2026-04-18T13:29:36.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T13:44:41.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T13:59:46.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T14:01:23.252 ProcessImageName: AcroCEF.exe, Pid: 2800, TotalTime: 3670, Count: 169, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-18T14:01:23.252 ProcessImageName: dllhost.exe, Pid: 8056, TotalTime: 2896, Count: 79, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\N7E3YERS_485\IV248B035L_30, EstimatedImpact: 44% 2026-04-18T14:01:23.252 ProcessImageName: AsPowerBar.exe, Pid: 12540, TotalTime: 2864, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 70% 2026-04-18T14:01:23.252 ProcessImageName: DipAwayMode.exe, Pid: 4940, TotalTime: 2588, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: MOM.exe, Pid: 11700, TotalTime: 1915, Count: 29, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 69% 2026-04-18T14:01:23.252 ProcessImageName: AISuite3.exe, Pid: 856, TotalTime: 1430, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-18T14:01:23.252 ProcessImageName: explorer.exe, Pid: 7056, TotalTime: 995, Count: 93, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\UltraVNC Launcher.lnk, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: websockify.exe, Pid: 11916, TotalTime: 959, Count: 18, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 49% 2026-04-18T14:01:23.252 ProcessImageName: WmiPrvSE.exe, Pid: 7312, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 93% 2026-04-18T14:01:23.252 ProcessImageName: TeamViewer.exe, Pid: 2904, TotalTime: 319, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 294, Count: 10, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 11% 2026-04-18T14:01:23.252 ProcessImageName: AdobeCollabSync.exe, Pid: 12680, TotalTime: 240, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\notificationsDB, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: svchost.exe, Pid: 3608, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RB79A19DA-2F86-4D37-B19D-B1CE43159D03\s640.cab, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: FileCoAuth.exe, Pid: 3080, TotalTime: 211, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: WhatsApp.Root.exe, Pid: 11128, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\session.db-shm, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 185, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 138, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 78% 2026-04-18T14:01:23.252 ProcessImageName: OfficeC2RClient.exe, Pid: 8676, TotalTime: 122, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 3% 2026-04-18T14:01:23.252 ProcessImageName: backgroundTaskHost.exe, Pid: 5480, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 24% 2026-04-18T14:01:23.252 ProcessImageName: SecurityHealthHost.exe, Pid: 10232, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 8% 2026-04-18T14:01:23.252 ProcessImageName: Acrobat.exe, Pid: 1600, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 6% 2026-04-18T14:01:23.252 ProcessImageName: PhoneExperienceHost.exe, Pid: 10584, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: AcroCEF.exe, Pid: 9164, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 23% 2026-04-18T14:01:23.252 ProcessImageName: OfficeC2RClient.exe, Pid: 10760, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1509a.log, EstimatedImpact: 3% 2026-04-18T14:01:23.252 ProcessImageName: taskhostw.exe, Pid: 3392, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 36% 2026-04-18T14:01:23.252 ProcessImageName: runonce.exe, Pid: 11784, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: OfficeClickToRun.exe, Pid: 8256, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: Acrobat.exe, Pid: 8124, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 6% 2026-04-18T14:01:23.252 ProcessImageName: svchost.exe, Pid: 1356, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-18T14:01:23.252 ProcessImageName: backgroundTaskHost.exe, Pid: 9928, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 26% 2026-04-18T14:01:23.252 ProcessImageName: SDXHelper.exe, Pid: 13116, TotalTime: 46, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 1% 2026-04-18T14:01:23.252 ProcessImageName: AcroCEF.exe, Pid: 13076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: TeamViewer_Service.exe, Pid: 4588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 1% 2026-04-18T14:01:23.252 ProcessImageName: RuntimeBroker.exe, Pid: 8956, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\assets\strings\de-DE.json, EstimatedImpact: 5% 2026-04-18T14:01:23.252 ProcessImageName: dllhost.exe, Pid: 8452, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 12% 2026-04-18T14:01:23.252 ProcessImageName: OpenWith.exe, Pid: 12132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisb.ttf, EstimatedImpact: 15% 2026-04-18T14:01:23.252 ProcessImageName: svchost.exe, Pid: 13104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7192_937770598\BITE339.tmp, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: OneDriveLauncher.exe, Pid: 8772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: winlogon.exe, Pid: 7028, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: backgroundTaskHost.exe, Pid: 4972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1776517549, EstimatedImpact: 12% 2026-04-18T14:01:23.252 ProcessImageName: SDXHelper.exe, Pid: 9712, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-04-18T14:01:23.252 ProcessImageName: svchost.exe, Pid: 5912, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 12260, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-18T14:01:23.252 ProcessImageName: AggregatorHost.exe, Pid: 5652, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-18T14:14:51.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T14:29:56.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T14:45:01.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T14:49:05.924 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24514, FileId: 0x1490000000006c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.924 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24516, FileId: 0x14b0000000006c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.924 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24513, FileId: 0xcc000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24519, FileId: 0x14c0000000006c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24520, FileId: 0xcf000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24518, FileId: 0xce000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24521, FileId: 0x14d0000000006c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24523, FileId: 0xd1000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.940 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24522, FileId: 0xd0000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24525, FileId: 0xd2000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24515, FileId: 0xcd000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24527, FileId: 0x95000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.971 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24528, FileId: 0xd6000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.971 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24529, FileId: 0x96000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.987 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24531, FileId: 0x97000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:05.987 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24524, FileId: 0x14e0000000006c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.424 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24581, FileId: 0x9b000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.424 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24583, FileId: 0xdd000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.424 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24579, FileId: 0xdb000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24584, FileId: 0x9c000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24585, FileId: 0xde000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24586, FileId: 0x9d000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24587, FileId: 0xdf000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24589, FileId: 0xe0000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T14:49:06.658 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24632, FileId: 0xea000000004b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T15:00:06.913 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T15:04:47.205 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-18T15:04:47.205 [RTP] 10 newly mounted volumes accumulated, forcing a config update ... 2026-04-18T15:04:47.205 [RTP] Duplicating the current plugin configuration object... 2026-04-18T15:04:47.205 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-18T15:04:47.205 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-18T15:04:47.205 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-18T15:04:47.205 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-18T15:15:11.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T15:30:16.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T15:45:21.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T16:00:26.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T16:01:23.253 ProcessImageName: AcroCEF.exe, Pid: 2800, TotalTime: 3670, Count: 169, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-18T16:01:23.253 ProcessImageName: dllhost.exe, Pid: 8056, TotalTime: 2896, Count: 79, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\N7E3YERS_485\IV248B035L_30, EstimatedImpact: 44% 2026-04-18T16:01:23.253 ProcessImageName: AsPowerBar.exe, Pid: 12540, TotalTime: 2864, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 70% 2026-04-18T16:01:23.253 ProcessImageName: DipAwayMode.exe, Pid: 4940, TotalTime: 2588, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: firefox.exe, Pid: 2452, TotalTime: 2266, Count: 236, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 63% 2026-04-18T16:01:23.253 ProcessImageName: MOM.exe, Pid: 11700, TotalTime: 1915, Count: 29, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 69% 2026-04-18T16:01:23.253 ProcessImageName: explorer.exe, Pid: 7056, TotalTime: 1780, Count: 121, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: AISuite3.exe, Pid: 856, TotalTime: 1430, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-18T16:01:23.253 ProcessImageName: httpd.exe, Pid: 12224, TotalTime: 1015, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_86.php, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: websockify.exe, Pid: 11916, TotalTime: 959, Count: 18, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 49% 2026-04-18T16:01:23.253 ProcessImageName: WmiPrvSE.exe, Pid: 7312, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 93% 2026-04-18T16:01:23.253 ProcessImageName: httpd.exe, Pid: 6204, TotalTime: 377, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 27% 2026-04-18T16:01:23.253 ProcessImageName: TeamViewer.exe, Pid: 2904, TotalTime: 319, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 2% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 305, Count: 14, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 294, Count: 10, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 11% 2026-04-18T16:01:23.253 ProcessImageName: AdobeCollabSync.exe, Pid: 12680, TotalTime: 240, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\notificationsDB, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 3608, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RB79A19DA-2F86-4D37-B19D-B1CE43159D03\s640.cab, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: FileCoAuth.exe, Pid: 3080, TotalTime: 211, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 2% 2026-04-18T16:01:23.253 ProcessImageName: WhatsApp.Root.exe, Pid: 11128, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\session.db-shm, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 138, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 78% 2026-04-18T16:01:23.253 ProcessImageName: OfficeC2RClient.exe, Pid: 8676, TotalTime: 122, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 3% 2026-04-18T16:01:23.253 ProcessImageName: backgroundTaskHost.exe, Pid: 5480, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 24% 2026-04-18T16:01:23.253 ProcessImageName: SecurityHealthHost.exe, Pid: 10232, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 8% 2026-04-18T16:01:23.253 ProcessImageName: Acrobat.exe, Pid: 1600, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 6% 2026-04-18T16:01:23.253 ProcessImageName: PhoneExperienceHost.exe, Pid: 10584, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: AcroCEF.exe, Pid: 9164, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 23% 2026-04-18T16:01:23.253 ProcessImageName: OfficeC2RClient.exe, Pid: 10760, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1509a.log, EstimatedImpact: 3% 2026-04-18T16:01:23.253 ProcessImageName: taskhostw.exe, Pid: 3392, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 36% 2026-04-18T16:01:23.253 ProcessImageName: runonce.exe, Pid: 11784, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-04-18T16:01:23.253 ProcessImageName: OfficeClickToRun.exe, Pid: 8256, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: Acrobat.exe, Pid: 8124, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 6% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 1356, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 2712, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 51% 2026-04-18T16:01:23.253 ProcessImageName: backgroundTaskHost.exe, Pid: 9928, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 26% 2026-04-18T16:01:23.253 ProcessImageName: SDXHelper.exe, Pid: 13116, TotalTime: 46, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 1% 2026-04-18T16:01:23.253 ProcessImageName: AcroCEF.exe, Pid: 13076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: TeamViewer_Service.exe, Pid: 4588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 1% 2026-04-18T16:01:23.253 ProcessImageName: pingsender.exe, Pid: 2700, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\2206847e-830b-47bb-91ff-a50a20a272c9, EstimatedImpact: 7% 2026-04-18T16:01:23.253 ProcessImageName: xampp-control.exe, Pid: 3596, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: RuntimeBroker.exe, Pid: 8956, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\assets\strings\de-DE.json, EstimatedImpact: 5% 2026-04-18T16:01:23.253 ProcessImageName: OfficeC2RClient.exe, Pid: 4932, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1723.log, EstimatedImpact: 1% 2026-04-18T16:01:23.253 ProcessImageName: dllhost.exe, Pid: 8452, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 12% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 13104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7192_937770598\BITE339.tmp, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: OneDriveLauncher.exe, Pid: 8772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc, EstimatedImpact: 2% 2026-04-18T16:01:23.253 ProcessImageName: pingsender.exe, Pid: 5516, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\6328855c-7c0c-47e9-a053-32e15350c64d, EstimatedImpact: 4% 2026-04-18T16:01:23.253 ProcessImageName: OpenWith.exe, Pid: 12132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisb.ttf, EstimatedImpact: 15% 2026-04-18T16:01:23.253 ProcessImageName: winlogon.exe, Pid: 7028, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: backgroundTaskHost.exe, Pid: 4972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1776517549, EstimatedImpact: 12% 2026-04-18T16:01:23.253 ProcessImageName: SDXHelper.exe, Pid: 9712, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-04-18T16:01:23.253 ProcessImageName: svchost.exe, Pid: 5912, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 12260, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-18T16:01:23.253 ProcessImageName: AggregatorHost.exe, Pid: 5652, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-18T16:15:31.923 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T16:30:36.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x8f3e43bf 2026-04-18T16:39:39.451 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T16:39:39.451 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T16:39:39.451 [Cloud] Queued cloud request. 2026-04-18T16:39:39.451 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T16:39:39.451 [Cloud] Dequeued cloud request. 2026-04-18T16:39:39.459 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T16:39:40.027 [Cloud] End of cloud request. 2026-04-18T16:39:40.027 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-04-18T16:39:40.549 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x09224982 2026-04-18T16:43:52.338 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T16:43:52.338 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T16:43:52.338 [Cloud] Queued cloud request. 2026-04-18T16:43:52.338 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T16:43:52.338 [Cloud] Dequeued cloud request. 2026-04-18T16:43:52.339 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T16:43:52.857 [Cloud] End of cloud request. 2026-04-18T16:43:52.857 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_0.php. status=0x40030000, statusex=0x200210, threatid=0x10001396, sigseq=0x64e730511cb7 2026-04-18T16:43:53.367 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T16:45:41.889 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T16:57:03.777 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\tsclient\N\OneDrive - SCIO Group\desktop.ini 2026-04-18T17:00:46.829 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T17:15:51.767 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T17:30:56.731 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T17:36:57.043 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #30826, FileId: 0x2d00000001c879, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{00DA76B7-17AE-FB76-C2D7-E00EE1152EE0} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:6204 ProcessCreationTime:134209982930337125 SessionID:2 CreationTime:04-18-2026 17:37:02 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-18T17:37:03.236 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T17:37:03.236 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T17:37:03.236 [Cloud] Queued cloud request. 2026-04-18T17:37:03.236 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T17:37:03.236 [Cloud] Dequeued cloud request. 2026-04-18T17:37:03.236 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T17:37:03.246 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-18T17:37:03.246 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T17:37:03.246 [Cloud] Queued cloud request. 2026-04-18T17:37:03.246 [Cloud] Dequeued cloud request. 2026-04-18T17:37:03.248 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T17:37:03.421 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-18T17:37:03.421 [Cloud] End of cloud request. 2026-04-18T17:37:03.537 [Cloud] End of cloud request. 2026-04-18T17:37:03.940 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T17:38:37.195 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31127, FileId: 0x2800000001c8ba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:40:16.079 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31212, FileId: 0x1700000001c697, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:41:56.162 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31424, FileId: 0x1900000001c958, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:43:36.274 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31490, FileId: 0x2000000001ca40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:45:17.444 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31582, FileId: 0x1d00000001cf03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:46:01.712 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T17:46:57.481 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31736, FileId: 0xe00000001d431, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:48:37.586 [RTP] [Mini-filter] Unsuccessful scan status(#190): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31803, FileId: 0x5f00000001d7f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:50:16.922 [RTP] [Mini-filter] Unsuccessful scan status(#200): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31869, FileId: 0xae00000001d8db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:51:57.795 [RTP] [Mini-filter] Unsuccessful scan status(#210): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #31939, FileId: 0x1a00000001da70, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:53:37.876 [RTP] [Mini-filter] Unsuccessful scan status(#220): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32113, FileId: 0x1a00000001db6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:55:16.872 [RTP] [Mini-filter] Unsuccessful scan status(#230): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32238, FileId: 0x2000000001c902, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:56:56.933 [RTP] [Mini-filter] Unsuccessful scan status(#240): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32314, FileId: 0x1400000001e7bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T17:58:38.123 [RTP] [Mini-filter] Unsuccessful scan status(#250): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32503, FileId: 0x56000000020b48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:00:18.178 [RTP] [Mini-filter] Unsuccessful scan status(#260): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32568, FileId: 0x1000000002327a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:01:06.698 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T18:01:23.031 ProcessImageName: explorer.exe, Pid: 7056, TotalTime: 5173, Count: 405, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: AcroCEF.exe, Pid: 2800, TotalTime: 3670, Count: 169, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-18T18:01:23.031 ProcessImageName: dllhost.exe, Pid: 8056, TotalTime: 2896, Count: 79, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\N7E3YERS_485\IV248B035L_30, EstimatedImpact: 44% 2026-04-18T18:01:23.031 ProcessImageName: AsPowerBar.exe, Pid: 12540, TotalTime: 2864, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 70% 2026-04-18T18:01:23.031 ProcessImageName: DipAwayMode.exe, Pid: 4940, TotalTime: 2588, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: httpd.exe, Pid: 12224, TotalTime: 2454, Count: 203, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: firefox.exe, Pid: 2452, TotalTime: 2266, Count: 236, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 63% 2026-04-18T18:01:23.031 ProcessImageName: MOM.exe, Pid: 11700, TotalTime: 1915, Count: 29, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 69% 2026-04-18T18:01:23.031 ProcessImageName: AISuite3.exe, Pid: 856, TotalTime: 1430, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-18T18:01:23.031 ProcessImageName: websockify.exe, Pid: 11916, TotalTime: 959, Count: 18, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 49% 2026-04-18T18:01:23.031 ProcessImageName: notepad++.exe, Pid: 12592, TotalTime: 661, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 17% 2026-04-18T18:01:23.031 ProcessImageName: WmiPrvSE.exe, Pid: 7312, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 93% 2026-04-18T18:01:23.031 ProcessImageName: httpd.exe, Pid: 6204, TotalTime: 377, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 27% 2026-04-18T18:01:23.031 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 320, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: TeamViewer.exe, Pid: 2904, TotalTime: 319, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 2% 2026-04-18T18:01:23.031 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 294, Count: 10, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 11% 2026-04-18T18:01:23.031 ProcessImageName: Notepad.exe, Pid: 6912, TotalTime: 274, Count: 27, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_89.php, EstimatedImpact: 16% 2026-04-18T18:01:23.031 ProcessImageName: AdobeCollabSync.exe, Pid: 12680, TotalTime: 240, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\notificationsDB, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: svchost.exe, Pid: 3608, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RB79A19DA-2F86-4D37-B19D-B1CE43159D03\s640.cab, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: PickerHost.exe, Pid: 12056, TotalTime: 211, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 3080, TotalTime: 211, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 2% 2026-04-18T18:01:23.031 ProcessImageName: WhatsApp.Root.exe, Pid: 11128, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\session.db-shm, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: PickerHost.exe, Pid: 1320, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 89% 2026-04-18T18:01:23.031 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 138, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 78% 2026-04-18T18:01:23.031 ProcessImageName: Photos.exe, Pid: 12336, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: OfficeC2RClient.exe, Pid: 8676, TotalTime: 122, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 3% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 7364, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.7364.1.aodl, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: backgroundTaskHost.exe, Pid: 5480, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 24% 2026-04-18T18:01:23.031 ProcessImageName: SecurityHealthHost.exe, Pid: 10232, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 8% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 3560, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1736.3560.1.aodl, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: Acrobat.exe, Pid: 1600, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 6% 2026-04-18T18:01:23.031 ProcessImageName: PhoneExperienceHost.exe, Pid: 10584, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: AcroCEF.exe, Pid: 9164, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 23% 2026-04-18T18:01:23.031 ProcessImageName: OfficeC2RClient.exe, Pid: 10760, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1509a.log, EstimatedImpact: 3% 2026-04-18T18:01:23.031 ProcessImageName: taskhostw.exe, Pid: 3392, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 36% 2026-04-18T18:01:23.031 ProcessImageName: runonce.exe, Pid: 11784, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 13076, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.13076.1.aodl, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 7144, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.7144.1.aodl, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: svchost.exe, Pid: 1808, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: OfficeClickToRun.exe, Pid: 8256, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: Acrobat.exe, Pid: 8124, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 6% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 2672, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1755.2672.2.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: RuntimeBroker.exe, Pid: 8956, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\assets\strings\de-DE.json, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: svchost.exe, Pid: 2712, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 51% 2026-04-18T18:01:23.031 ProcessImageName: svchost.exe, Pid: 1356, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 8332, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.8332.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: backgroundTaskHost.exe, Pid: 9928, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 26% 2026-04-18T18:01:23.031 ProcessImageName: SDXHelper.exe, Pid: 13116, TotalTime: 46, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: AcroCEF.exe, Pid: 13076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 12808, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.12808.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 8036, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.8036.2.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: OfficeC2RClient.exe, Pid: 3800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1926.log, EstimatedImpact: 2% 2026-04-18T18:01:23.031 ProcessImageName: TeamViewer_Service.exe, Pid: 4588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 1% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 13304, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.13304.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 3100, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.3100.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1755.13232.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.031 ProcessImageName: FileCoAuth.exe, Pid: 13152, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.13152.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 13136, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.13136.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 2860, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.2860.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 13008, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.13008.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: pingsender.exe, Pid: 2700, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\2206847e-830b-47bb-91ff-a50a20a272c9, EstimatedImpact: 7% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10692, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.10692.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 2520, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.2520.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 2452, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.2452.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10456, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.10456.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10448, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.10448.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 2348, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.2348.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 2040, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.2040.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 1880, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.1880.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 1724, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.1724.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 1276, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.1276.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10056, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.10056.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10004, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.10004.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9932, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.9932.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12572, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.12572.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9884, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.9884.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9884, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.9884.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9716, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.9716.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9692, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.9692.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12352, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.12352.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12284, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.12284.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9484, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.9484.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9308, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.9308.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9220, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.9220.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8688, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.8688.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8472, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.8472.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8280, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.8280.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8256, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.8256.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12284, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.12284.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8108, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.8108.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7864, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.7864.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7756, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.7756.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7628, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.7628.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 11540, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.11540.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7436, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.7436.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.6992.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 6784, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.6784.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 6536, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.6536.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 11204, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.11204.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 11164, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.11164.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 6360, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.6360.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5828, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.5828.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5768, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.5768.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5724, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.5724.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5428, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.5428.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 4248, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.4248.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 3564, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.3564.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 3448, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.3448.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 10780, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.10780.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: AggregatorHost.exe, Pid: 5652, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: backgroundTaskHost.exe, Pid: 3040, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1776531921->(UTF-16LE), EstimatedImpact: 6% 2026-04-18T18:01:23.032 ProcessImageName: xampp-control.exe, Pid: 3596, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 6888, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: OfficeC2RClient.exe, Pid: 4932, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1723.log, EstimatedImpact: 1% 2026-04-18T18:01:23.032 ProcessImageName: dllhost.exe, Pid: 8452, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 12% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 4692, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.4692.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: svchost.exe, Pid: 13104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7192_937770598\BITE339.tmp, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7560, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1736.7560.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5264, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12952, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: dllhost.exe, Pid: 5212, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12900, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.5044.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 4800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.12848.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12832, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12832, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.12832.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8908, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.8908.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12744, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 8920, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.8920.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 4440, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 4400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.4400.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12368, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.12368.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12364, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.12364.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7436, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.7436.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 5452, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.5452.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9156, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9156, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: OpenWith.exe, Pid: 12132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisb.ttf, EstimatedImpact: 15% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12096, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.12096.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 3556, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.3556.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 3448, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 12016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.12016.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 3140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 7340, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 11672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9444, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.9444.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 1664, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.1664.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 9508, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.9508.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.032 ProcessImageName: FileCoAuth.exe, Pid: 11248, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.11248.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 11100, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.11100.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 9632, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10948, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.10948.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 9704, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 7864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.7864.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10780, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.10780.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: pingsender.exe, Pid: 10760, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\d2896747-319c-46ba-91c2-f807e2039dc8, EstimatedImpact: 5% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10716, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.10716.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10632, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.10632.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1604, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.1604.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 9780, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.10288.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10244, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.10244.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10244, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.10244.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.10204.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 6920, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1508, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.1508.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 8400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.8400.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 488, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.488.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 8588, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.8588.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 8700, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.8700.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 6104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.6104.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5980, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.5896.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.5864.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 8448, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5732, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: pingsender.exe, Pid: 5516, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\6328855c-7c0c-47e9-a053-32e15350c64d, EstimatedImpact: 4% 2026-04-18T18:01:23.033 ProcessImageName: OneDriveLauncher.exe, Pid: 8772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc, EstimatedImpact: 2% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5452, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.5452.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: winlogon.exe, Pid: 7028, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: backgroundTaskHost.exe, Pid: 4972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1776517549, EstimatedImpact: 12% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 3552, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 13008, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 3824, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.3824.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 12964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 4440, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.4440.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 4160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.4160.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5208, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.5208.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 2860, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1240, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.1240.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 9624, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 12172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.12172.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1828, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.1828.2.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.6992.2.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 11344, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: SDXHelper.exe, Pid: 9712, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 4340, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.4340.2.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10780, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.10780.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: dllhost.exe, Pid: 8000, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B7808D8C.pf, EstimatedImpact: 3% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 1192, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.1192.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 10204, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: svchost.exe, Pid: 5912, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: dllhost.exe, Pid: 5480, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B93782C1.pf, EstimatedImpact: 3% 2026-04-18T18:01:23.033 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 12260, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: dllhost.exe, Pid: 7808, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-96E3AFF5.pf, EstimatedImpact: 0% 2026-04-18T18:01:23.033 ProcessImageName: FileCoAuth.exe, Pid: 5820, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.5820.1.aodl, EstimatedImpact: 0% 2026-04-18T18:01:58.207 [RTP] [Mini-filter] Unsuccessful scan status(#270): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32638, FileId: 0x26000000023902, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:03:38.319 [RTP] [Mini-filter] Unsuccessful scan status(#280): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #32706, FileId: 0x27000000024080, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:05:17.870 [RTP] [Mini-filter] Unsuccessful scan status(#290): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33003, FileId: 0x80000000024b5e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:06:57.443 [RTP] [Mini-filter] Unsuccessful scan status(#300): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33078, FileId: 0xa7000000024c38, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:08:38.611 [RTP] [Mini-filter] Unsuccessful scan status(#310): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33148, FileId: 0x4c000000024d33, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:10:18.861 [RTP] [Mini-filter] Unsuccessful scan status(#320): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33685, FileId: 0xe7000000004e6e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:11:58.835 [RTP] [Mini-filter] Unsuccessful scan status(#330): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33897, FileId: 0xf800000000fab9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:13:38.907 [RTP] [Mini-filter] Unsuccessful scan status(#340): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33971, FileId: 0x8000000000fbb2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:15:17.873 [RTP] [Mini-filter] Unsuccessful scan status(#350): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #34046, FileId: 0xa900000000fcb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:16:11.680 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T18:16:59.035 [RTP] [Mini-filter] Unsuccessful scan status(#360): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #34230, FileId: 0x7600000000ff0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:18:39.154 [RTP] [Mini-filter] Unsuccessful scan status(#370): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #34302, FileId: 0x78000000010028, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:20:19.267 [RTP] [Mini-filter] Unsuccessful scan status(#380): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #34381, FileId: 0x4f000000010140, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:21:59.372 [RTP] [Mini-filter] Unsuccessful scan status(#390): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #34588, FileId: 0xf1000000010288, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:23:49.668 [RTP] [Mini-filter] Unsuccessful scan status(#400): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35448, FileId: 0x210000000106cb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:25:29.529 [RTP] [Mini-filter] Unsuccessful scan status(#410): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35590, FileId: 0x78000000010a98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:27:09.572 [RTP] [Mini-filter] Unsuccessful scan status(#420): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35666, FileId: 0x47000000010b52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:28:49.677 [RTP] [Mini-filter] Unsuccessful scan status(#430): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35737, FileId: 0x32000000010bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:30:28.667 [RTP] [Mini-filter] Unsuccessful scan status(#440): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35805, FileId: 0x67000000010c58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:31:16.660 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T18:32:08.766 [RTP] [Mini-filter] Unsuccessful scan status(#450): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35883, FileId: 0x98000000010f65, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:33:48.878 [RTP] [Mini-filter] Unsuccessful scan status(#460): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #35956, FileId: 0x3a00000001104c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:35:30.034 [RTP] [Mini-filter] Unsuccessful scan status(#470): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36069, FileId: 0x55000000011141, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:37:10.098 [RTP] [Mini-filter] Unsuccessful scan status(#480): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36214, FileId: 0x1e0000000112d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:38:50.198 [RTP] [Mini-filter] Unsuccessful scan status(#490): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36353, FileId: 0x2f00000001133d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:40:29.626 [RTP] [Mini-filter] Unsuccessful scan status(#500): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36418, FileId: 0x38000000010a89, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:42:09.279 [RTP] [Mini-filter] Unsuccessful scan status(#510): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36484, FileId: 0x5f0000000118c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:43:39.338 [RTP] [Mini-filter] Unsuccessful scan status(#520): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36546, FileId: 0x53000000011909, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:45:20.524 [RTP] [Mini-filter] Unsuccessful scan status(#530): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36643, FileId: 0x2300000001194b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:46:21.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T18:47:00.680 [RTP] [Mini-filter] Unsuccessful scan status(#540): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36824, FileId: 0x8e0000000122d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:48:40.636 [RTP] [Mini-filter] Unsuccessful scan status(#550): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #36924, FileId: 0xd00000001e117, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:50:20.808 [RTP] [Mini-filter] Unsuccessful scan status(#560): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37008, FileId: 0x420000000295ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:51:59.880 [RTP] [Mini-filter] Unsuccessful scan status(#570): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37076, FileId: 0x1900000002978e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:53:41.047 [RTP] [Mini-filter] Unsuccessful scan status(#580): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37218, FileId: 0x1e0000000297d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:55:21.249 [RTP] [Mini-filter] Unsuccessful scan status(#590): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37288, FileId: 0x25000000011369, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:57:00.267 [RTP] [Mini-filter] Unsuccessful scan status(#600): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37365, FileId: 0x2e00000002985f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T18:58:41.502 [RTP] [Mini-filter] Unsuccessful scan status(#610): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37430, FileId: 0x23000000029882, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T19:00:21.535 [RTP] [Mini-filter] Unsuccessful scan status(#620): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37497, FileId: 0x400000000298ac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T19:01:26.659 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T19:06:52.620 Engine:Process 1760 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-18T19:16:31.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T19:31:36.640 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T19:43:04.022 [RTP] [Mini-filter] Unsuccessful scan status(#630): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php38A6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #39400, FileId: 0x9100000000e556, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T19:46:41.649 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T19:53:25.198 [RTP] [Mini-filter] Unsuccessful scan status(#640): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB33E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #39677, FileId: 0x7200000001112d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T19:54:40.706 [RTP] [Mini-filter] Unsuccessful scan status(#650): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39705, FileId: 0xbc000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T20:01:22.985 ProcessImageName: explorer.exe, Pid: 7056, TotalTime: 10524, Count: 723, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: AcroCEF.exe, Pid: 2800, TotalTime: 3670, Count: 169, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-18T20:01:22.985 ProcessImageName: httpd.exe, Pid: 12224, TotalTime: 3507, Count: 313, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: WINWORD.EXE, Pid: 13128, TotalTime: 3269, Count: 67, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSORES.DLL, EstimatedImpact: 18% 2026-04-18T20:01:22.985 ProcessImageName: dllhost.exe, Pid: 8056, TotalTime: 2896, Count: 79, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\N7E3YERS_485\IV248B035L_30, EstimatedImpact: 44% 2026-04-18T20:01:22.985 ProcessImageName: AsPowerBar.exe, Pid: 12540, TotalTime: 2864, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 70% 2026-04-18T20:01:22.985 ProcessImageName: setup.exe, Pid: 7372, TotalTime: 2859, Count: 340, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, EstimatedImpact: 25% 2026-04-18T20:01:22.985 ProcessImageName: DipAwayMode.exe, Pid: 4940, TotalTime: 2588, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: firefox.exe, Pid: 2452, TotalTime: 2266, Count: 236, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 63% 2026-04-18T20:01:22.985 ProcessImageName: MOM.exe, Pid: 11700, TotalTime: 1915, Count: 29, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 69% 2026-04-18T20:01:22.985 ProcessImageName: WINWORD.EXE, Pid: 6392, TotalTime: 1833, Count: 62, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 3% 2026-04-18T20:01:22.985 ProcessImageName: AISuite3.exe, Pid: 856, TotalTime: 1430, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-18T20:01:22.985 ProcessImageName: websockify.exe, Pid: 11916, TotalTime: 959, Count: 18, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 49% 2026-04-18T20:01:22.985 ProcessImageName: notepad++.exe, Pid: 12592, TotalTime: 661, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 17% 2026-04-18T20:01:22.985 ProcessImageName: WmiPrvSE.exe, Pid: 7312, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 93% 2026-04-18T20:01:22.985 ProcessImageName: firefox.exe, Pid: 5892, TotalTime: 450, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa06388, EstimatedImpact: 57% 2026-04-18T20:01:22.985 ProcessImageName: httpd.exe, Pid: 6204, TotalTime: 377, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 27% 2026-04-18T20:01:22.985 ProcessImageName: WINWORD.EXE, Pid: 7364, TotalTime: 350, Count: 27, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\mscss7cm_ge.dub, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 335, Count: 18, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: TeamViewer.exe, Pid: 2904, TotalTime: 319, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 2% 2026-04-18T20:01:22.985 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 294, Count: 10, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 11% 2026-04-18T20:01:22.985 ProcessImageName: Notepad.exe, Pid: 6912, TotalTime: 274, Count: 27, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_89.php, EstimatedImpact: 16% 2026-04-18T20:01:22.985 ProcessImageName: AdobeCollabSync.exe, Pid: 12680, TotalTime: 240, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\notificationsDB, EstimatedImpact: 0% 2026-04-18T20:01:22.985 ProcessImageName: svchost.exe, Pid: 3608, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RB79A19DA-2F86-4D37-B19D-B1CE43159D03\s640.cab, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: PickerHost.exe, Pid: 12056, TotalTime: 211, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 3080, TotalTime: 211, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 2% 2026-04-18T20:01:22.986 ProcessImageName: PickerHost.exe, Pid: 13504, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 83% 2026-04-18T20:01:22.986 ProcessImageName: WhatsApp.Root.exe, Pid: 11128, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\session.db-shm, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: PickerHost.exe, Pid: 1320, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 89% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 12348, TotalTime: 155, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1821.12348.1.aodl, EstimatedImpact: 2% 2026-04-18T20:01:22.986 ProcessImageName: MicrosoftEdge_X64_147.0.3912.72_147.0.3912.60.exe, Pid: 12284, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{201F1E02-C94C-44F1-896F-E2770EE6ABDB}\EDGEMITMP_47D19.tmp\setup.exe, EstimatedImpact: 62% 2026-04-18T20:01:22.986 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 138, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 78% 2026-04-18T20:01:22.986 ProcessImageName: Photos.exe, Pid: 12336, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: OfficeC2RClient.exe, Pid: 8676, TotalTime: 122, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 3% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13840, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.13840.1.aodl, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 7364, TotalTime: 107, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.7364.1.aodl, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: backgroundTaskHost.exe, Pid: 5480, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 24% 2026-04-18T20:01:22.986 ProcessImageName: SecurityHealthHost.exe, Pid: 10232, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 8% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 3560, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1736.3560.1.aodl, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: Acrobat.exe, Pid: 1600, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 6% 2026-04-18T20:01:22.986 ProcessImageName: PhoneExperienceHost.exe, Pid: 10584, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: RuntimeBroker.exe, Pid: 8956, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\assets\strings\de-DE.json, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: OfficeC2RClient.exe, Pid: 10760, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1509a.log, EstimatedImpact: 3% 2026-04-18T20:01:22.986 ProcessImageName: AcroCEF.exe, Pid: 9164, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 23% 2026-04-18T20:01:22.986 ProcessImageName: taskhostw.exe, Pid: 3392, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 36% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13076, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.13076.1.aodl, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 7144, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.7144.1.aodl, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: runonce.exe, Pid: 11784, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-04-18T20:01:22.986 ProcessImageName: svchost.exe, Pid: 1808, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: OfficeClickToRun.exe, Pid: 8256, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: SDXHelper.exe, Pid: 8612, TotalTime: 61, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F9D2D48-3204-440E-80D8-FDC87086026E, EstimatedImpact: 8% 2026-04-18T20:01:22.986 ProcessImageName: Acrobat.exe, Pid: 8124, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 6% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 6212, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.6212.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 5872, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1838.5872.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 14012, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.14012.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 2672, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1755.2672.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: AggregatorHost.exe, Pid: 5652, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: svchost.exe, Pid: 2712, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 51% 2026-04-18T20:01:22.986 ProcessImageName: svchost.exe, Pid: 1356, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 8332, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.8332.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: backgroundTaskHost.exe, Pid: 9928, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 26% 2026-04-18T20:01:22.986 ProcessImageName: SDXHelper.exe, Pid: 13116, TotalTime: 46, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: AcroCEF.exe, Pid: 13076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 4020, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1845.4020.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 10700, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1836.10700.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 8036, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.8036.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 12808, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.12808.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1926.log, EstimatedImpact: 2% 2026-04-18T20:01:22.986 ProcessImageName: dllhost.exe, Pid: 5212, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: TeamViewer_Service.exe, Pid: 4588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 1% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13564, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1845.13564.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 8256, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.8256.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13516, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1848.13516.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 8732, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.8732.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 4840, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1839.4840.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13468, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1900.13468.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13464, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1855.13464.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13432, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1856.13432.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13376, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1853.13376.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 10592, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1844.10592.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 8912, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1900.8912.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13304, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.13304.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13292, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1809.13292.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 10552, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.10552.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 10456, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.10456.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.13232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1821.13232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.986 ProcessImageName: FileCoAuth.exe, Pid: 10448, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.10448.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.13232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1755.13232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13212, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1811.13212.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3068, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1820.3068.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 4920, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1816.4920.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13152, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.13152.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13136, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1844.13136.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13136, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.13136.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13088, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1835.13088.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9484, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.9484.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5112, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.5112.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10368, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1850.10368.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13040, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1816.13040.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13008, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.13008.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5208, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1840.5208.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5428, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.5428.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5492, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1838.5492.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12952, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1855.12952.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10364, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1859.10364.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7436, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.7436.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8544, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1842.8544.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12880, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1813.12880.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5660, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1808.5660.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5724, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.5724.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12872, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1835.12872.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10276, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1809.10276.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9308, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.9308.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8796, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1854.8796.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12792, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1844.12792.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5768, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.5768.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7628, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.7628.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5828, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.5828.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12752, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1845.12752.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8280, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.8280.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7756, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.7756.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7864, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.7864.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12692, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1857.12692.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10144, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1821.10144.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12588, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1813.12588.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 5908, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1850.5908.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9220, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.9220.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12572, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1817.12572.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12572, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.12572.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10056, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.10056.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6088, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.6088.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6160, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.6160.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12392, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.12392.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10004, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.10004.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9168, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.9168.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12352, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.12352.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14300, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1823.14300.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12304, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1846.12304.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14296, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1928.14296.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12284, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.12284.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 12284, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.12284.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14280, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1828.14280.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14260, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1833.14260.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6360, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.6360.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14244, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1826.14244.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14240, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.14240.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14232, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1826.14232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6536, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.6536.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9932, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.9932.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 4020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1819.4020.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8168, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1826.8168.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14172, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1823.14172.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9716, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.9716.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6656, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1822.6656.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9884, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.9884.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9884, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1746.9884.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9120, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1812.9120.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6784, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.6784.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6784, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1839.6784.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7064, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1802.7064.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1927.14124.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8176, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1824.8176.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6888, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1806.6888.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14056, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1844.14056.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8108, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.8108.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11540, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.11540.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9692, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.9692.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9848, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1829.9848.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6888, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1812.6888.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11032, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1816.11032.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8688, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.8688.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.8124.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8568, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.8568.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.6992.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11340, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1832.11340.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11312, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.11312.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 14012, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1845.14012.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10892, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.10892.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11204, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.11204.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 11164, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.11164.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 4248, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.4248.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13932, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.13932.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8160, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1824.8160.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 9716, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1840.9716.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7316, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1825.7316.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3728, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1849.3728.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3720, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1803.3720.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 7324, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1828.7324.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3564, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.3564.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 4348, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.4348.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3456, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.3456.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3448, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.3448.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10780, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.10780.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3368, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1825.3368.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3188, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1829.3188.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 3100, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1742.3100.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8928, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1836.8928.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2908, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.2908.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13836, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.13836.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2860, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1805.2860.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2860, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.2860.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 10776, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1828.10776.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2768, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1806.2768.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8248, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1806.8248.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: pingsender.exe, Pid: 2700, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\2206847e-830b-47bb-91ff-a50a20a272c9, EstimatedImpact: 7% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 13776, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1830.13776.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 8472, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.8472.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2520, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.2520.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2512, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1815.2512.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2452, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.2452.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 2452, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.2452.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.987 ProcessImageName: FileCoAuth.exe, Pid: 4364, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1851.4364.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10692, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1738.10692.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2348, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.2348.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2144, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1820.2144.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2104, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1816.2104.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2072, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.2072.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2040, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1743.2040.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1880, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1825.1880.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1880, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.1880.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 13636, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.13636.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1784, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1830.1784.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1724, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.1724.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9612, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.9612.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1900.1444.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.1444.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 13636, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1833.13636.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 13632, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.13632.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7336, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1841.7336.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1276, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.1276.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 1240, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1828.1240.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 960, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1855.960.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 960, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1809.960.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 13624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1848.13624.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 2644, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1805.2644.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 600, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: backgroundTaskHost.exe, Pid: 3040, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1776531921->(UTF-16LE), EstimatedImpact: 6% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 6888, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 4852, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1823.4852.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: xampp-control.exe, Pid: 3596, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: dllhost.exe, Pid: 8452, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 12% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 4136, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1823.4136.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: OfficeC2RClient.exe, Pid: 4932, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-1723.log, EstimatedImpact: 1% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12560, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1817.12560.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12524, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1832.12524.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12368, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.12368.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12364, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.12364.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12188, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12180, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1856.12180.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12164, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: OpenWith.exe, Pid: 12132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisb.ttf, EstimatedImpact: 15% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12096, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.12096.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12056, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1821.12056.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 12016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.12016.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11472, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11468, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1802.11468.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1851.11432.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.11432.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1832.11432.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11248, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.11248.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.11140.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11100, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1827.11100.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11100, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.11100.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11084, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1833.11084.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11084, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1824.11084.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11072, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1803.11072.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1845.11064.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1808.11064.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 11036, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10948, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.10948.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10892, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10780, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.10780.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: pingsender.exe, Pid: 10760, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\d2896747-319c-46ba-91c2-f807e2039dc8, EstimatedImpact: 5% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10716, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.10716.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10648, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10632, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.10632.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10600, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1827.10600.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10572, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1805.10572.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.10400.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.10288.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10244, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1747.10244.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10244, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1740.10244.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1800.10204.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8536, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1821.8536.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10168, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1819.10168.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 10136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1814.10136.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9880, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9856, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9836, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1820.9836.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9780, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9704, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.9672.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9632, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1839.9632.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9632, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1835.9552.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9508, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.9508.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9444, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.9444.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1838.9400.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9352, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1824.9352.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9156, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9156, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9052, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1841.9052.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 9012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1835.9012.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8920, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.8920.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8908, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1802.8908.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8908, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.8908.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8792, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: OneDriveLauncher.exe, Pid: 8772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc, EstimatedImpact: 2% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8736, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8700, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1900.8700.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8700, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1749.8700.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1807.8672.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8616, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1803.8616.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8600, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1806.8600.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8588, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.8588.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 14324, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1825.14324.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8448, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1804.8416.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: OfficeC2RClient.exe, Pid: 8400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-2042.log, EstimatedImpact: 1% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1757.8400.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1806.8328.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8256, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8236, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1807.8204.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8200, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1808.8200.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8180, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8168, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1848.8168.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8028, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1807.8028.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 8000, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.8000.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7996, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1827.7996.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7888, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.7888.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.7864.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.7864.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7600, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7560, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1736.7560.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7556, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1825.7556.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7488, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7436, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.7436.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.988 ProcessImageName: FileCoAuth.exe, Pid: 7396, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1842.7372.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7364, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1802.7364.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7360, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1815.7360.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7340, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1804.7340.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7340, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7332, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.7328.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1803.7328.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 7160, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.7160.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1822.6992.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6932, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6920, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6876, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1807.6876.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1838.6748.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6360, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1808.6360.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6232, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.6232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6108, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.6108.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1753.6104.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: OfficeC2RClient.exe, Pid: 6100, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260418-2155.log, EstimatedImpact: 1% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5980, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5908, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.5896.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5864, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1752.5864.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1827.5844.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5816, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1844.5816.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5816, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5812, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1859.5812.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5812, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1857.5812.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1812.5768.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1809.5768.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5732, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5676, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5624, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.5624.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5620, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1815.5620.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5600, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1817.5600.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1815.5528.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: pingsender.exe, Pid: 5516, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\6328855c-7c0c-47e9-a053-32e15350c64d, EstimatedImpact: 4% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5452, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.5452.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5452, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1748.5452.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1839.5428.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5424, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1826.5424.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5264, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1819.5220.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5208, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 5044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.5044.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4692, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1737.4692.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4440, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1839.4428.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4400, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1756.4400.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4084, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1813.4084.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4084, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1811.4084.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 4048, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14180, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3780, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3736, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1857.3736.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14164, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.14164.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14152, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1829.14136.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14116, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3572, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1854.3572.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14096, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1853.14096.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14040, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3556, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1758.3556.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3480, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1805.3480.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3472, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1851.3472.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3472, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1846.3472.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3472, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.3472.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14032, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1829.14032.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3448, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1842.3448.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3448, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 14032, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1824.14032.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13984, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.13984.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13976, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1904.13976.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3352, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3240, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1822.3240.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.13944.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 3140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1853.13936.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13928, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1823.13928.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1815.6992.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13868, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1854.13868.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13852, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1856.13852.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13852, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1826.13852.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13808, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13792, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1853.13748.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1842.13740.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13720, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13680, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 2672, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1804.2672.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1837.13636.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1836.13636.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13628, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1858.13628.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13516, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1856.13516.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 2508, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.2508.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1834.13492.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13356, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1836.13356.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13336, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1851.13336.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13304, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1816.13304.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13284, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 2260, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1813.2260.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13284, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 2132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13252, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13236, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1809.13236.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13232, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 2012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1846.2012.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13212, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: svchost.exe, Pid: 13104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7192_937770598\BITE339.tmp, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13072, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 13040, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1819.13040.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12952, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1720, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1838.1720.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1664, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.1664.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1604, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.1604.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12900, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1508, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.1508.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1496, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12880, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1853.12880.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1854.12848.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12848, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1739.12848.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1859.12840.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12832, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 1276, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.989 ProcessImageName: FileCoAuth.exe, Pid: 12832, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1744.12832.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12820, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1840.12820.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1240, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1811.1240.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1830.1124.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1841.12800.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1020, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1855.1020.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12756, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1842.12756.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12752, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1833.12752.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12744, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12604, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12600, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1805.12600.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 488, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.488.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12572, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1847.12572.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 240, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1850.240.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: winlogon.exe, Pid: 7028, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: backgroundTaskHost.exe, Pid: 4972, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1776517549, EstimatedImpact: 12% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13056, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1801.13056.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 6100, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1852.6100.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 6092, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1818.6092.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13148, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13164, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4852, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1855.4852.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 2860, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13488, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.13488.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 5980, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1901.5980.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 2732, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13504, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1857.13504.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 9624, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12588, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1811.12588.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1859.13568.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 2524, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1810.2524.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12636, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1814.12636.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4440, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1754.4440.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 10232, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.10232.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 5208, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1751.5208.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13748, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1827.13748.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4356, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1830.4356.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 7604, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4340, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.4340.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1848.13936.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13960, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1848.13960.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1832.4224.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 13980, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 12752, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1900.12752.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4160, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1741.4160.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 14028, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 14088, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1831.14088.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 2016, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1820.2016.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 10204, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 4048, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 6992, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1750.6992.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 14172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1851.14172.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 14204, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1850.14204.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 3824, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1759.3824.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 11344, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 1828, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1745.1828.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: dllhost.exe, Pid: 8000, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B7808D8C.pf, EstimatedImpact: 3% 2026-04-18T20:01:22.990 ProcessImageName: SDXHelper.exe, Pid: 9712, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 7996, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1830.7996.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 5664, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1808.5664.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 5664, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1828.9716.1.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 3636, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1833.3636.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 10552, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1813.10552.2.aodl, EstimatedImpact: 0% 2026-04-18T20:01:22.990 ProcessImageName: FileCoAuth.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-18.1843.9716.1.aodl, EstimatedImpact: 0% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-18-2026 21:18:03 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/18/2026 21:18:03.26504500 UTC (13750 ms since boot) 2026-04-18T21:18:03.085 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-18T21:18:03.090 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-18T21:18:03.090 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-18T21:18:03.189 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260418-211803-00000003-fffffffeffffffff.bin ... 2026-04-18T21:18:03.274 [WPP] Trace session started - MpWppTracing-20260418-211803-00000003-fffffffeffffffff.bin 2026-04-18T21:18:03.279 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-18T21:18:03.279 [RbM] Rollback manager succesfully initialized. 2026-04-18T21:18:03.279 [RbM] Rollback manager EnableRollbackManager called. 2026-04-18T21:18:03.287 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-18T21:18:03.287 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-18T21:18:03.287 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-18T21:18:03.287 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-18T21:18:03.287 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-18T21:18:03.294 MdCoreSvc is supported in this platform and OS 2026-04-18T21:18:03.294 MdCoreSvc is supported in this platform and OS 2026-04-18T21:18:03.294 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-18T21:18:03.294 [PlatUpd] Starting MdCoreSvc service 2026-04-18T21:18:03.329 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-18T21:18:07.030 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-18T21:18:07.030 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-18T21:18:07.030 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-18T21:18:07.030 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-18T21:18:07.030 [PlatUpd] CSP platform update started 2026-04-18T21:18:07.030 [PlatUpd] Defender MDM CSP platform update not required 2026-04-18T21:18:07.030 [PlatUpd] WMI/PS provider platform update started 2026-04-18T21:18:07.030 [PlatUpd] WMI/PS provider platform update not required 2026-04-18T21:18:07.030 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-18T21:18:07.030 MdCoreSvc is supported in this platform and OS 2026-04-18T21:18:07.030 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-18T21:18:07.030 [PlatUpd] Starting MdCoreSvc service 2026-04-18T21:18:07.030 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-18T21:18:07.030 [TS] Troublshooting mode is not available! 2026-04-18T21:18:07.030 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-18T21:18:07.030 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-18T21:18:07.061 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-18T21:18:07.061 [Service] Enabling AutoLoggers ... 2026-04-18T21:18:07.061 [Service] Enabling AMSI registration ... 2026-04-18T21:18:07.061 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-18T21:18:07.077 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 51954 Number of invalid entries is 0 Number of inserts issued is 1571449 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6328 Number of lookups is 106538428 Number of lookup misses is 5106210 Number of fast lookup misses is 54438451 Number of false fast lookups is 5106205 Number of invalidations is 727799 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-18T21:18:07.077 Verifying license file... 2026-04-18T21:18:07.077 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-18T21:18:07.092 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-18T21:18:07.092 Loaded module#0 MpComServer. 2026-04-18T21:18:07.092 Loaded module#1 StartupPolicies. 2026-04-18T21:18:07.092 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-18T21:18:07.092 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-18T21:18:07.092 COM server initialized successfully. 2026-04-18T21:18:07.108 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-18T21:18:07.123 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-18T21:18:07.123 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-18T21:18:07.123 [RTP] [RTP] FilterCommunicator object 0x0000016123A9DDA0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-18T21:18:07.139 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-18T21:18:07.139 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-18T21:18:07.139 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-18T21:18:07.139 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-18T21:18:07.139 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-18T21:18:07.139 [RTP] [RTP] FilterCommunicator object 0x0000016123A9DFB0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-18T21:18:07.139 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-18T21:18:07.139 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-18T21:18:07.139 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-18T21:18:07.139 [RTP] [RTP] StartCommunication 0x0000016123A9DDA0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-18T21:18:07.139 [init][RTP] RTPPlugin initialization completed 2026-04-18T21:18:07.139 OS boot count = 2 2026-04-18T21:18:07.139 OS Install = 0 2026-04-18T21:18:07.139 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-18T21:18:07.139 [KSL] Entering CKSLEngine::Initialize. 2026-04-18T21:18:07.139 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-18T21:18:07.139 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-18T21:18:07.155 [KSL] MpInstallKslD: hr=0x1 2026-04-18T21:18:07.155 [KSL] MpRegisterKslD: hr=0 2026-04-18T21:18:07.155 [KSL] MpStartKslD: hr=0 2026-04-18T21:18:07.155 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-18T21:18:07.155 Loading engine... 2026-04-18T21:18:07.170 Verifying engine and signature files (source: 1) ... 2026-04-18T21:18:07.170 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpengine.dll] due to PPL. 2026-04-18T21:18:07.170 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpasbase.vdm] (file in cache) 2026-04-18T21:18:07.170 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpasdlta.vdm] (file in cache) 2026-04-18T21:18:07.170 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpavbase.vdm] (file in cache) 2026-04-18T21:18:07.170 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpavdlta.vdm] (file in cache) 2026-04-18T21:18:07.217 [Engine] IsHybridMode: 0 2026-04-18T21:18:07.217 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-18T21:18:07.248 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-31B1EE0D9714D4720223713FAB746866113C3665.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-18T21:18:16.225 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-18T21:18:16.226 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-18T21:18:16.230 [Engine] New active engine 00007FFEE0438020 (no old engine). Number of active engines: 1 2026-04-18T21:18:16.242 EngineInit:Global ASOC is enabled 2026-04-18T21:18:16.242 EngineInit:ASOO is enabled for developer volumes 2026-04-18T21:18:16.347 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-18T21:18:16.347 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.347 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-18T21:18:16.348 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-18T21:18:16.348 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-18T21:18:16.348 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.348 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.348 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.349 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-18T21:18:16.349 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.350 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:18:16.381 MpWriteUupSignatureVersion 1.449.170.0, hr = 0 2026-04-18T21:18:16.383 [SigStatUpd] CSignatureStatus: back to good 2026-04-18T21:18:16.383 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-18T21:18:16.406 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-18T21:18:16.407 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-18T21:18:16.407 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-18T21:18:16.407 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-18T21:18:16.408 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-18T21:18:16.425 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-18T21:18:16.425 [Plugin] Initializing RTP plugin state... 2026-04-18T21:18:16.425 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-18T21:18:16.425 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,1,0 Proc:0,1,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2298 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2791 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14330 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2934 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-18T21:18:16.426 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A} 2026-04-18T21:18:16.426 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:18:16.427 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:18:16.427 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:18:16.427 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-18T21:18:16.427 MdCoreSvc is supported in this platform and OS 2026-04-18T21:18:16.428 Engine loaded! 2026-04-18T21:18:16.428 [DLP] Create FeatureControlState instance 2026-04-18T21:18:16.434 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-18T21:18:16.434 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-18T21:18:16.436 RegisterSModeChangeListener: hr = 0x1 2026-04-18T21:18:16.436 RegisterHybridModeChangeListener: hr = 0 2026-04-18T21:18:16.451 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-18T21:18:16.452 [SigReleaseHb] Initialized with Stage 0 2026-04-18T21:18:16.452 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-18T21:18:16.453 [SCC][CID=27171_5368] Initializing ... 2026-04-18T21:18:16.453 [SCC][CID=27171_5368] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-18T21:18:16.456 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-18T21:18:16.456 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-18T21:18:16.459 [NRI] Stopping NIS service ... 2026-04-18T21:18:16.460 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-18T21:18:16.460 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.170.0 AV Signature Version: 1.449.170.0 ************************************************************ 2026-04-18T21:18:16.461 Resource usage Monitoring is enabled 2026-04-18T21:18:16.463 Job Notification: New process added to job (4528) 2026-04-18T21:18:16.464 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-18T21:18:16.464 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-18T21:18:16.530 Job Notification: New process added to job (9180) 2026-04-18T21:18:16.536 Job Notification: New process added to job (9188) 2026-04-18T21:18:16.543 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:9180] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:9188]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-18T21:18:16.579 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-18T21:18:16.581 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-18T21:18:16.587 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-18T21:18:16.587 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-18T21:18:16.587 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-18T21:18:16.587 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-18T21:18:16.587 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-18T21:18:16.587 [RTP] Generating the base plugin configuration ... 2026-04-18T21:18:16.587 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-18T21:18:16.588 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-18T21:18:16.588 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-18T21:18:16.590 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-18T21:18:16.590 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-18T21:18:16.590 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-18T21:18:16.594 [RTP] [RTP] StartCommunication 0x0000016123A9DFB0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-18T21:18:16.600 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-18T21:18:16.617 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-18T21:18:16.684 Job Notification: Process exited from job (9180) 2026-04-18T21:18:16.688 Job Notification: Process exited from job (9188) 2026-04-18T21:18:16.688 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-18T21:18:16.957 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-18T21:18:16.957 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-18T21:18:16.957 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-18T21:18:16.979 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T21:18:19.663 [RTP] Duplicating the current plugin configuration object... 2026-04-18T21:18:19.663 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-18T21:18:19.663 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-18T21:18:19.664 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-18T21:18:19.665 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-18T21:18:23.379 Bm signature throttled:0x00002db31bed458f 2026-04-18T21:18:36.503 Engine:Triggered SMS scan for filename: explorer.exe, pid: 8684, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-04-18T21:18:49.144 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2915, FileId: 0xb200000000f342, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000DD784C325B52, sigsha=f9299e3658eb20c1c433de2ba018176931b361be, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x000024617D0EB055, sigsha=b4c361a7dac40d2a28447d17d87f02bc4b3cca68, cached=false, source=0, resourceid=0xe1824bfa 2026-04-18T21:19:07.097 Process scan (poststartupscan) started. 2026-04-18T21:19:07.097 Process scan (poststartupscan) completed. 2026-04-18T21:19:07.612 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-18T21:19:07.628 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-18T21:19:10.206 [RTP] Duplicating the current plugin configuration object... 2026-04-18T21:19:10.206 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-18T21:19:10.206 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-18T21:19:10.206 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-18T21:19:10.206 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-18T21:19:13.550 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-18T21:19:13.550 [RTP] Duplicating the current plugin configuration object... 2026-04-18T21:19:13.550 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-18T21:19:13.550 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-18T21:19:13.550 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-18T21:19:13.550 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\htdocs\0_\08_PHP - Verknüpfung.lnk 2026-04-18T21:19:13.550 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-04-18T21:20:06.316 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-18T21:20:06.316 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-18T21:20:06.331 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-18T21:23:16.296 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-18T21:23:16.457 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T21:23:16.577 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5942, FileId: 0x1c00000005a4f3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:28:16.465 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-18T21:28:16.465 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-18T21:28:16.523 Job Notification: New process added to job (1496) 2026-04-18T21:28:16.541 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-18T21:28:16.549 Job Notification: New process added to job (8744) 2026-04-18T21:28:16.568 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:1496] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8744]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-18T21:28:16.616 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 19044426(ms) from now at 04:45 (02:45 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-18T21:28:16.664 Job Notification: New process added to job (11080) 2026-04-18T21:28:16.669 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-18T21:28:16.673 Job Notification: New process added to job (976) 2026-04-18T21:28:16.683 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11080] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:976]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-18T21:28:32.486 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\4A7D36D7-0EA6-4248-994C-3E3C0D87577E334c.1dccf7a4d5b45fd 2026-04-18T21:28:32.582 Verifying engine and signature files (source: 0) ... 2026-04-18T21:28:32.582 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpengine.dll] due to PPL. 2026-04-18T21:28:32.582 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpasbase.vdm] (file in cache) 2026-04-18T21:28:32.582 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-18T21:28:32.596 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpasdlta.vdm] 2026-04-18T21:28:32.596 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpavbase.vdm] (file in cache) 2026-04-18T21:28:32.596 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-18T21:28:32.611 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpavdlta.vdm] 2026-04-18T21:28:32.772 [Engine] IsHybridMode: 0 2026-04-18T21:28:32.772 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-18T21:28:32.778 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5E3BDBF89F8F7C02556344802E7B6EAF92EF03B6.bin): 0x00000002 2026-04-18T21:28:32.787 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5E3BDBF89F8F7C02556344802E7B6EAF92EF03B6.bin) 2026-04-18T21:28:32.787 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-18T21:28:32.787 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-18T21:28:32.787 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-18T21:28:32.787 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-18T21:28:46.167 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-18T21:28:46.167 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-18T21:28:46.186 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFEE0438020, lRefCount: 5, hr=0 2026-04-18T21:28:46.186 [Engine] New active engine 00007FFEAFC68020 replacing engine 00007FFEE0438020. Number of active engines: 2 2026-04-18T21:28:46.192 EngineInit:Global ASOC is enabled 2026-04-18T21:28:46.192 EngineInit:ASOO is enabled for developer volumes 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-18T21:28:46.262 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.263 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-18T21:28:46.268 MpWriteUupSignatureVersion 1.449.176.0, hr = 0 2026-04-18T21:28:46.270 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-18T21:28:46.288 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-18T21:28:46.290 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-18T21:28:46.290 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-18T21:28:46.290 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-18T21:28:46.290 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-18T21:28:46.315 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-18T21:28:46.316 [Plugin] Initializing RTP plugin state... 2026-04-18T21:28:46.316 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎18‎-‎2026 23:18:16 Last Perf:‎04‎-‎18‎-‎2026 23:18:16 First RTP Scan:‎04‎-‎18‎-‎2026 23:18:16 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2467 Misses:3944 BM Queue:0,383,0 Proc:0,188,0 File:0,375,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:6688 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:21691424 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:9704 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:33091 TotalHits:23701 InstanceCacheInserts:363 InstanceCacheUpdates:0 InstanceCacheDeletes:239 InstanceCacheHits:3 InstanceCacheMisses:11269 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (774/244) Success: 244, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-18T21:28:46.316 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-18T21:28:46.317 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF} 2026-04-18T21:28:46.317 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A}\mpasbase.vdm in use, hr=0x80070020 2026-04-18T21:28:46.319 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-18T21:28:46.319 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D359230B-81D2-46DA-884C-C1F95C567D29} removed 2026-04-18T21:28:46.320 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.320 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.321 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.321 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.321 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-18-2026 21:28:46 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-18-2026 21:28:46 2026-04-18T21:28:46.327 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-18T21:28:46.327 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-18T21:28:46.328 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-18T21:28:46.328 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-18T21:28:46.330 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T21:28:46.331 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.331 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.331 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.331 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-18T21:28:46.332 MdCoreSvc is supported in this platform and OS Signature updated on 04-18-2026 21:28:46 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.176.0 AV Signature Version: 1.449.176.0 ************************************************************ 2026-04-18T21:28:46.334 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-18T21:28:46.334 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\4A7D36D7-0EA6-4248-994C-3E3C0D87577E334c.1dccf7a4d5b45fd 2026-04-18T21:28:46.425 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-18T21:28:46.427 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-18-2026 21:28:46 ************************************************************ 2026-04-18T21:28:46.539 Job Notification: Process exited from job (11080) 2026-04-18T21:28:46.550 Job Notification: Process exited from job (976) 2026-04-18T21:28:46.571 Job Notification: Process exited from job (1496) 2026-04-18T21:28:46.575 Job Notification: Process exited from job (8744) 2026-04-18T21:28:46.789 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-18T21:28:46.789 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-18T21:28:46.789 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-18T21:28:46.797 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-18T21:28:46.797 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-18T21:28:46.797 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-18T21:28:46.797 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-18T21:28:46.798 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-18T21:28:46.799 [Engine] Engine 00007FFEE0438020 no longer in use. Number of active engines: 1 2026-04-18T21:28:46.799 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-18T21:28:46.799 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-18T21:28:46.924 ProcessImageName: AsPowerBar.exe, Pid: 13920, TotalTime: 3006, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 49% 2026-04-18T21:28:46.924 ProcessImageName: explorer.exe, Pid: 8684, TotalTime: 2677, Count: 196, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\contextMenu\NppShell.dll, EstimatedImpact: 0% 2026-04-18T21:28:46.924 ProcessImageName: DipAwayMode.exe, Pid: 7948, TotalTime: 2457, Count: 30, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 25% 2026-04-18T21:28:46.924 ProcessImageName: dllhost.exe, Pid: 11100, TotalTime: 2236, Count: 65, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LEQ0NS2CRU_88, EstimatedImpact: 45% 2026-04-18T21:28:46.924 ProcessImageName: MOM.exe, Pid: 13924, TotalTime: 1912, Count: 29, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 63% 2026-04-18T21:28:46.924 ProcessImageName: AISuite3.exe, Pid: 6704, TotalTime: 1429, Count: 23, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-18T21:28:46.924 ProcessImageName: websockify.exe, Pid: 13972, TotalTime: 865, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 59% 2026-04-18T21:28:46.924 ProcessImageName: Notepad.exe, Pid: 10208, TotalTime: 350, Count: 36, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 1% 2026-04-18T21:28:46.924 ProcessImageName: WhatsApp.Root.exe, Pid: 8556, TotalTime: 211, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\session.db-wal, EstimatedImpact: 0% 2026-04-18T21:28:46.924 ProcessImageName: PickerHost.exe, Pid: 4588, TotalTime: 166, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 1), EstimatedImpact: 76% 2026-04-18T21:28:46.924 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 155, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T21:28:46.924 ProcessImageName: TabTip.exe, Pid: 7664, TotalTime: 154, Count: 5, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-18T21:28:46.924 ProcessImageName: TeamViewer.exe, Pid: 8108, TotalTime: 153, Count: 10, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 2% 2026-04-18T21:28:46.924 ProcessImageName: PhoneExperienceHost.exe, Pid: 1008, TotalTime: 150, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-18T21:28:46.961 [Engine] RSIG_UNLOADENGINE, 00007FFEE0438020, err=0x0 2026-04-18T21:28:46.972 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{225E6F61-5A49-4857-9333-3F655FC7561A} removed 2026-04-18T21:28:48.356 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-18T21:28:48.361 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-18T21:28:48.362 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-18T21:29:07.106 Process scan (postsignatureupdatescan) started. 2026-04-18T21:29:26.889 Process scan (postsignatureupdatescan) completed. 2026-04-18T21:29:29.781 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-18T21:29:29.782 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-18T21:29:29.823 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-18T21:29:29.861 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-18T21:29:29.891 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-18T21:30:17.072 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7276CD90D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7804, FileId: 0x3200000000d3f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.121 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8063CE927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7810, FileId: 0xea0000000067ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.172 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA641519EF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7809, FileId: 0x3400000000d3f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.174 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj371665945. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7813, FileId: 0x176000000002cbb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.210 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE320DE9F7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7817, FileId: 0xec0000000067ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.390 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9CB8DC931. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7835, FileId: 0x17e000000002cbb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.443 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6002E39B1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7851, FileId: 0xee0000000067ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.522 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFB2DAD90E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7855, FileId: 0x2b0000000110e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.563 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0C9A68982. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7856, FileId: 0x9000000001c641, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:17.584 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDC2A569A0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7857, FileId: 0x9100000001c641, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:18.266 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8BFC390C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7881, FileId: 0x7c000000004bdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:31.518 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8057, FileId: 0x1f000000003127, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:31.688 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8061, FileId: 0xae00000000416f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:30:31.798 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8065, FileId: 0x880000000041bc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:31:32.107 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8451, FileId: 0x1ac000000001074, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:33:16.928 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #8522, FileId: 0xe4000000004b2b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:33:46.229 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-18T21:37:56.008 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-18T21:37:56.999 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #9631, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:38:21.459 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T21:40:31.962 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9850, FileId: 0x1700000001c64e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:40:31.980 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9852, FileId: 0x45c000000035126, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:45:00.040 [RTP] [Mini-filter] OpenWithoutRead notification (1162, 10013, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-04-18T21:49:05.497 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11299, FileId: 0x70000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.498 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11301, FileId: 0xc2000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.500 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11302, FileId: 0x72000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.502 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11300, FileId: 0xc1000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.515 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11305, FileId: 0x74000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.516 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11307, FileId: 0x75000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.529 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11310, FileId: 0xc7000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.530 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11306, FileId: 0xc4000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.531 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11311, FileId: 0x78000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.543 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11314, FileId: 0xca000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.545 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11317, FileId: 0xcb000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.556 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11315, FileId: 0x7a000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.906 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11347, FileId: 0xcd000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:49:05.918 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13f9ee6c-0937-4ffb-a21b-a7e5f5fb803b. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #11349, FileId: 0x270000000038de, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T21:53:26.466 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T22:07:49.480 Bm signature throttled:0x00002db31bed458f 2026-04-18T22:08:31.467 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T22:18:16.467 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-18T22:23:36.467 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ddda7d7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4451ed10 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x33e6bc34 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5fbb863a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x964adc32 2026-04-18T22:30:13.167 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.167 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.167 [Cloud] Queued cloud request. 2026-04-18T22:30:13.167 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.169 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.176 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.176 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.176 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.176 [Cloud] Queued cloud request. 2026-04-18T22:30:13.176 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.176 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.176 [Cloud] Queued cloud request. 2026-04-18T22:30:13.176 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.177 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.177 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.177 [Cloud] Queued cloud request. 2026-04-18T22:30:13.177 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.179 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.179 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.180 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.180 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.180 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.182 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.182 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.182 [Cloud] Queued cloud request. 2026-04-18T22:30:13.182 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.182 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.182 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.182 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.184 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.574 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d85011e6cf683d0d7999ae4d04e4e77b1084c8e7 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a84107a452bb96c9cf6d591005753f5c7bd3859 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.574 Dynamic signature received 2026-04-18T22:30:13.575 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:30:13.575 [Cloud] End of cloud request. 2026-04-18T22:30:13.575 [Cloud] End of cloud request. 2026-04-18T22:30:13.575 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:30:13.580 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ab5c3a07fe160d584c762ce17dd691017b1a535c Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.581 [Cloud] End of cloud request. 2026-04-18T22:30:13.581 RTSD:RTSD recieved, rescanning impacted resources Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2508d7a2588d7edbe0a263b3fd7837b3e4c9c433 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.589 Dynamic signature received 2026-04-18T22:30:13.590 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:30:13.590 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x183071d3 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2a8211f476deca5d6fc03814e403bcf1012dbfa1 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.621 Dynamic signature received 2026-04-18T22:30:13.626 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6e0e739e 2026-04-18T22:30:13.640 [Cloud] End of cloud request. 2026-04-18T22:30:13.658 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.659 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.659 [Cloud] Queued cloud request. 2026-04-18T22:30:13.659 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.659 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.659 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.678 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.678 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.678 [Cloud] Queued cloud request. 2026-04-18T22:30:13.678 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.679 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.679 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:13.834 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\61800682a94d00c47adb66133e955adb2fdfac18 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.835 [Cloud] End of cloud request. 2026-04-18T22:30:13.835 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:30:13.854 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cf2778fe357efdbe2e426c87cba41a061baccc87 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:13.855 [Cloud] End of cloud request. 2026-04-18T22:30:13.855 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6e0fd71e 2026-04-18T22:30:13.919 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:30:13.919 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:30:13.919 [Cloud] Queued cloud request. 2026-04-18T22:30:13.919 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:30:13.920 [Cloud] Dequeued cloud request. 2026-04-18T22:30:13.920 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:30:14.087 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\32649ccda90b58c40ce31f292945a4fe03988f41 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:15 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:30:14.179 Dynamic signature received 2026-04-18T22:30:14.180 [Cloud] End of cloud request. 2026-04-18T22:30:14.180 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:30:14.695 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000005550CC00373, sigsha=e78b10a67caa30620208d7d5968dda6c5655bb87, cached=false, source=0, resourceid=0xabf26e4b Internal signature match:subtype=Lowfi, sigseq=0x00003D960C97DB92, sigsha=dc3c741ae9701e0978f1add4813777628b70b09c, cached=false, source=0, resourceid=0xabf26e4b Internal signature match:subtype=Lowfi, sigseq=0x00000555498DA744, sigsha=f9fe7263cd98e932bfa7989bfe514ab1a1359a57, cached=false, source=0, resourceid=0xabf26e4b 2026-04-18T22:36:19.107 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:36:19.107 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:36:19.107 [Cloud] Queued cloud request. 2026-04-18T22:36:19.107 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:36:19.108 [Cloud] Dequeued cloud request. 2026-04-18T22:36:19.115 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-18T22:36:19.638 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b543d929a24da961038626fd151e6824bb556d2e Dynamic Signature Compilation Timestamp:04-18-2026 22:36:20 Persistence Type:Duration Time remaining:1728000000 2026-04-18T22:36:19.640 [Cloud] End of cloud request. 2026-04-18T22:36:19.640 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:36:20.163 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T22:36:20.180 ExpensiveFile:Scan time for `\\?\C:\Users\ITHAN\Downloads\xampp-windows-x64-8.2.12-0-VS16-installer.exe` is 12921 units 2026-04-18T22:38:41.465 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000082E732B51972, sigsha=e1231b80e9db16c4b6e19abd5b7d261392c7cb37, cached=false, source=0, resourceid=0x0e16a3ae Internal signature match:subtype=Lowfi, sigseq=0x000082E7F0901A0A, sigsha=7902eb5d39888eb083c7611e8a99d25d9c960c3b, cached=false, source=0, resourceid=0x0e16a3ae 2026-04-18T22:41:18.008 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:41:18.009 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:41:18.009 [Cloud] Queued cloud request. 2026-04-18T22:41:18.009 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:41:18.009 [Cloud] Dequeued cloud request. 2026-04-18T22:41:18.009 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\589c52fa70d1a8ff5c09c3a8d5ec3cf0c88d1639 Dynamic Signature Compilation Timestamp:04-18-2026 22:41:19 Persistence Type:Duration Time remaining:864000000 2026-04-18T22:41:18.787 Dynamic signature received 2026-04-18T22:41:18.787 [Cloud] End of cloud request. 2026-04-18T22:41:18.788 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:41:19.309 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-18T22:41:19.660 ExpensiveFile:Scan time for `\\?\C:\Users\ITHAN\Downloads\xampp-portable-windows-x64-8.1.4-1-VS16.zip` is 11468 units Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=5, resourceid=0xf858e3a3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=5, resourceid=0x2904aa3f 2026-04-18T22:53:35.650 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.650 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.772 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.772 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.834 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.834 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.894 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.895 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.957 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:35.957 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.072 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.072 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.084 Engine:EMS scan for process: pid_8684 pid: 8684, sigseq: 0x0, sendMemoryScanReport: 0, source: 8 2026-04-18T22:53:36.132 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.132 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.195 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.195 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.370 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.370 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.662 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.662 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.780 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.780 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.849 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.849 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.910 mp.TriggerScanResource(0x00000008, process, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:36.910 mp.TriggerScanResource(0x00000008, ems, pid:8684), delay = 0 from 0x002010bd9cc67d2f 2026-04-18T22:53:46.479 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000157EFD8B7E43, sigsha=f9d791e5b14cac67df410448a761971c425ea871, cached=false, source=5, resourceid=0x1cdc1770 2026-04-18T22:55:20.025 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-18T22:55:20.025 [Cloud] Start of cloud request. Passive mode: 0 2026-04-18T22:55:20.025 [Cloud] Queued cloud request. 2026-04-18T22:55:20.025 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-18T22:55:20.025 [Cloud] Dequeued cloud request. 2026-04-18T22:55:20.026 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5b40b1a60b3671e1f5d44f82a3d5fb78283368ad Dynamic Signature Compilation Timestamp:04-18-2026 22:55:21 Persistence Type:Duration Time remaining:50065408 2026-04-18T22:55:20.323 Dynamic signature received 2026-04-18T22:55:20.324 RTSD:RTSD recieved, rescanning impacted resources 2026-04-18T22:55:20.324 [Cloud] End of cloud request. 2026-04-18T22:55:20.855 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xeff34e02 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x6f084cf3 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xb6c5876a Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xd91fff18 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x3b20f67a Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xe7a6344e Internal signature match:subtype=Lowfi, sigseq=0x00001A2985E55790, sigsha=88cbf2a3b3bf6b6a86b3ca3d8c024e1f4a6f32b9, cached=false, source=2, resourceid=0xdbd69cf5 2026-04-18T23:08:51.455 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T23:09:50.225 Bm signature throttled:0x00002db31bed458f 2026-04-18T23:15:13.075 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7A58.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65337, FileId: 0xc80000000048f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:15:23.754 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA42B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65343, FileId: 0x3b00000008f59b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:15:32.619 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC6C8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65347, FileId: 0x3c00000008f537, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:15:52.368 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1400.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65349, FileId: 0x4e000000035127, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:16:00.917 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3564.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65352, FileId: 0x50000000035127, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:16:03.536 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3FA7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65354, FileId: 0x52000000035127, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:23:56.458 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T23:28:11.905 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5CD1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65738, FileId: 0xba00000000416b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:28:46.193 ProcessImageName: explorer.exe, Pid: 8684, TotalTime: 340481, Count: 50511, MaxTime: 1796, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 4% 2026-04-18T23:28:46.193 ProcessImageName: AcroCEF.exe, Pid: 5176, TotalTime: 4107, Count: 175, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-04-18T23:28:46.193 ProcessImageName: dllhost.exe, Pid: 11100, TotalTime: 3884, Count: 82, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\ONNKX1GX_487\1GLDF21M3X_11, EstimatedImpact: 19% 2026-04-18T23:28:46.193 ProcessImageName: notepad++.exe, Pid: 6388, TotalTime: 1282, Count: 90, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-18T23:28:46.193 ProcessImageName: svchost.exe, Pid: 10048, TotalTime: 609, Count: 3, MaxTime: 609, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-18T23:28:46.193 ProcessImageName: firefox.exe, Pid: 14004, TotalTime: 555, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 68% 2026-04-18T23:28:46.193 ProcessImageName: httpd.exe, Pid: 9736, TotalTime: 453, Count: 37, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_95.php, EstimatedImpact: 0% 2026-04-18T23:28:46.193 ProcessImageName: notepad++.exe, Pid: 13952, TotalTime: 382, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\httpd.conf@2026-04-19_002333, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: AdobeCollabSync.exe, Pid: 6724, TotalTime: 243, Count: 23, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 8988, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 100% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 708, TotalTime: 226, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 100% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 1432, TotalTime: 211, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 78% 2026-04-18T23:28:46.194 ProcessImageName: backgroundTaskHost.exe, Pid: 12292, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 12964, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 76% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 7404, TotalTime: 181, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 89% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 10452, TotalTime: 180, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 90% 2026-04-18T23:28:46.194 ProcessImageName: mmc.exe, Pid: 9756, TotalTime: 168, Count: 18, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 13% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 2960, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\22162cc2-55f1-46e7-8c5c-2c71237e0afa.1.bin, EstimatedImpact: 22% 2026-04-18T23:28:46.194 ProcessImageName: PickerHost.exe, Pid: 1340, TotalTime: 165, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 73% 2026-04-18T23:28:46.194 ProcessImageName: TabTip.exe, Pid: 3504, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 90% 2026-04-18T23:28:46.194 ProcessImageName: svchost.exe, Pid: 1436, TotalTime: 139, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: httpd.exe, Pid: 4508, TotalTime: 136, Count: 21, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 25% 2026-04-18T23:28:46.194 ProcessImageName: Acrobat.exe, Pid: 4232, TotalTime: 136, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 8% 2026-04-18T23:28:46.194 ProcessImageName: RuntimeBroker.exe, Pid: 10724, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{503D7C5E-D909-407C-9A9E-B716F8180ED6}.json, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 3376, TotalTime: 122, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 4% 2026-04-18T23:28:46.194 ProcessImageName: OpenConsole.exe, Pid: 4720, TotalTime: 121, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\desktop.ini->(UTF-16LE), EstimatedImpact: 39% 2026-04-18T23:28:46.194 ProcessImageName: svchost.exe, Pid: 1512, TotalTime: 108, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: httpd.exe, Pid: 8184, TotalTime: 106, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 12% 2026-04-18T23:28:46.194 ProcessImageName: SDXHelper.exe, Pid: 13160, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F9D2D48-3204-440E-80D8-FDC87086026E, EstimatedImpact: 7% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 5732, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\logs\access.log, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: httpd.exe, Pid: 1392, TotalTime: 91, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 44% 2026-04-18T23:28:46.194 ProcessImageName: AcroCEF.exe, Pid: 13120, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 8% 2026-04-18T23:28:46.194 ProcessImageName: xampp-control.exe, Pid: 13908, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: notepad++.exe, Pid: 2012, TotalTime: 60, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: SDXHelper.exe, Pid: 5176, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 1% 2026-04-18T23:28:46.194 ProcessImageName: xampp-control.exe, Pid: 4344, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\StaticCache.dat, EstimatedImpact: 1% 2026-04-18T23:28:46.194 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: firefox.exe, Pid: 2996, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 8% 2026-04-18T23:28:46.194 ProcessImageName: xampp-control.exe, Pid: 7876, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 10516, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\8dcd5345-611a-4ea1-ade1-6aefe3f024fd.0.bin, EstimatedImpact: 1% 2026-04-18T23:28:46.194 ProcessImageName: cmd.exe, Pid: 2416, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\WF.msc, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: Acrobat.exe, Pid: 7880, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 3% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 1944, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\22162cc2-55f1-46e7-8c5c-2c71237e0afa.0.bin, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: Notepad.exe, Pid: 5140, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\43c3c20f-6e98-4dc5-8e8e-b23187cd4ada.0.bin, EstimatedImpact: 2% 2026-04-18T23:28:46.194 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-18T23:28:46.194 ProcessImageName: svchost.exe, Pid: 2136, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-18T23:32:33.590 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5B0A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #65762, FileId: 0xce00000000139b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:33:03.402 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #66614, FileId: 0x1e00000008f626, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:39:01.453 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T23:44:30.523 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4B86.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67477, FileId: 0x5100000003515e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:44:43.135 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7CCA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67479, FileId: 0xd500000000139b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:44:50.880 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9B21.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67482, FileId: 0x5d000000003ed7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:44:53.632 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA5D2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67484, FileId: 0x142000000004204, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:45:57.428 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9F08.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67494, FileId: 0x3000000003549c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:45:59.612 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA7A6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67496, FileId: 0x3200000003549c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:46:01.883 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB072.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67498, FileId: 0x3400000003549c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:47:06.150 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAB8D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67505, FileId: 0x2700000008f518, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:48:03.452 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8B60.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67535, FileId: 0xe0000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:50:00.767 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php55A2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67588, FileId: 0x94000000004129, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:50:16.880 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php94A1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67591, FileId: 0x1a00000008f7b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:50:33.942 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD73A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67602, FileId: 0x148000000004204, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:50:55.361 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2AEA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67605, FileId: 0xe4000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:51:15.653 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7A36.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67609, FileId: 0xe6000000004ba8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:54:06.466 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-18T23:55:43.523 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php908B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67792, FileId: 0x4600000003549c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:55:50.653 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAC72.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67794, FileId: 0x3b000000066404, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:56:00.893 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD45F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67796, FileId: 0x3d000000066404, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:57:16.935 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFD81.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67808, FileId: 0x2900000008f5ff, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:58:50.295 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6A23.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67820, FileId: 0x2c00000008f5ff, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-18T23:58:53.675 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7735.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #67823, FileId: 0x2f00000008f5ff, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:09:06.198 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD009.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68271, FileId: 0x3000000008f5a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:09:11.459 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T00:09:19.018 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php274.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68273, FileId: 0x3100000008f5a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:09:27.203 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2261.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68276, FileId: 0xc000000001c641, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:09:34.237 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3DD9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68277, FileId: 0x2100000001c510, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:11:03.335 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php99F0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68281, FileId: 0x8d00000001c50f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:11:06.142 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA4ED.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68282, FileId: 0x159000000004204, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:11:09.772 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB308.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68283, FileId: 0x15a000000004204, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:11:23.961 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEA84.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68284, FileId: 0x2600000001c510, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:15:49.670 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF86C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #68415, FileId: 0x1800000008f85f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:24:16.458 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T00:25:53.386 [AutoPurge] Verification Routine tasks have started. 2026-04-19T00:25:53.386 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-19T00:25:53.428 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-19T00:25:53.429 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-19T00:25:53.429 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-19T00:25:53.429 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-19T00:25:53.429 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-19T00:25:53.429 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-19T00:25:53.435 [AutoPurge] Cleanup Routine tasks have started. 2026-04-19T00:25:53.443 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:FBC0BFB6-22D6-4AF9-A12E-0D7D2B3B948E, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-19T00:25:53.443 Scheduled scan with Id FBC0BFB6-22D6-4AF9-A12E-0D7D2B3B948E configured CPU priority: normal (LowCpuPriority: 0) 2026-04-19T00:25:53.445 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-19T00:25:53.445 [SFC] System file cache build is not needed (already completed) 2026-04-19T00:25:53.451 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-19T00:25:53.455 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-19T00:25:53.456 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-19-2026 00:25:53 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-19-2026 00:25:53 2026-04-19T00:25:53.478 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-19T00:25:53.478 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-19T00:25:53.478 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-19T00:25:53.479 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-19T00:25:53.484 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-19T00:25:53.669 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-19T00:25:53.673 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-19T00:25:53.708 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-19T00:25:53.719 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-19T00:25:53.721 [AutoPurge] Verification Routine tasks have ended. 2026-04-19T00:25:54.665 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #68568, FileId: 0x2400000008f7d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:25:55.464 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T00:25:55.476 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T00:25:55.478 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x000005553D684D6B, sigsha=cb34e8cfd7c7921b11326795eba505924831f9e3, cached=false, source=0, resourceid=0x6126c044 2026-04-19T00:26:36.705 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\469E3DEE-F9F7-4039-9B50-92E07F2239B71574.1dccf932ddb5b41 2026-04-19T00:26:36.897 Verifying engine and signature files (source: 0) ... 2026-04-19T00:26:36.897 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpengine.dll] due to PPL. 2026-04-19T00:26:36.897 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasbase.vdm] (file in cache) 2026-04-19T00:26:36.897 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-19T00:26:36.912 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasdlta.vdm] 2026-04-19T00:26:36.912 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpavbase.vdm] (file in cache) 2026-04-19T00:26:36.912 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-19T00:26:36.926 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpavdlta.vdm] 2026-04-19T00:26:37.197 [Engine] IsHybridMode: 0 2026-04-19T00:26:37.198 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-19T00:26:37.204 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-793868F7243870C577C71514658050AB7633B68C.bin): 0x00000002 2026-04-19T00:26:37.215 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-793868F7243870C577C71514658050AB7633B68C.bin) 2026-04-19T00:26:37.215 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-19T00:26:37.215 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-19T00:26:37.215 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-19T00:26:37.215 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-04-19T00:26:38.646 Engine:Triggered AR EMS scan 2026-04-19T00:26:38.651 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.673 Engine:EMS scan for process: svchost pid: 964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.688 Engine:EMS scan for process: svchost pid: 672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.692 Engine:EMS scan for process: svchost pid: 1032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.697 Engine:EMS scan for process: svchost pid: 1220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.710 Engine:EMS scan for process: svchost pid: 1244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.715 Engine:EMS scan for process: svchost pid: 1360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.725 Engine:EMS scan for process: svchost pid: 1376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.732 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.734 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.740 Engine:EMS scan for process: svchost pid: 1472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.743 Engine:EMS scan for process: svchost pid: 1532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.747 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.752 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.756 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.758 Engine:EMS scan for process: svchost pid: 1692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.766 Engine:EMS scan for process: svchost pid: 1884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.771 Engine:EMS scan for process: svchost pid: 2000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.777 Engine:EMS scan for process: svchost pid: 1512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.780 Engine:EMS scan for process: svchost pid: 1892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.784 Engine:EMS scan for process: svchost pid: 2080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.788 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.791 Engine:EMS scan for process: svchost pid: 2332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.798 Engine:EMS scan for process: svchost pid: 2372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.800 Engine:EMS scan for process: svchost pid: 2380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.803 Engine:EMS scan for process: svchost pid: 2420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.805 Engine:EMS scan for process: svchost pid: 2548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.808 Engine:EMS scan for process: svchost pid: 2580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.810 Engine:EMS scan for process: svchost pid: 2648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.817 Engine:EMS scan for process: svchost pid: 2664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.820 Engine:EMS scan for process: svchost pid: 2900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.825 Engine:EMS scan for process: svchost pid: 3008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.832 Engine:EMS scan for process: svchost pid: 3032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.836 Engine:EMS scan for process: svchost pid: 3108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.843 Engine:EMS scan for process: svchost pid: 3440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.847 Engine:EMS scan for process: svchost pid: 3444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.849 Engine:EMS scan for process: svchost pid: 3556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.855 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.863 Engine:EMS scan for process: svchost pid: 3756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.871 Engine:EMS scan for process: svchost pid: 4068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.875 Engine:EMS scan for process: svchost pid: 3372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.879 Engine:EMS scan for process: svchost pid: 4136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.884 Engine:EMS scan for process: svchost pid: 4188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.891 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.898 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.903 Engine:EMS scan for process: svchost pid: 4420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.912 Engine:EMS scan for process: svchost pid: 4472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.914 Engine:EMS scan for process: svchost pid: 4552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.919 Engine:EMS scan for process: svchost pid: 4660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.923 Engine:EMS scan for process: svchost pid: 5936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.926 Engine:EMS scan for process: svchost pid: 1872, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.928 Engine:EMS scan for process: dllhost pid: 6104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.932 Engine:EMS scan for process: svchost pid: 6880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.939 Engine:EMS scan for process: svchost pid: 6888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.946 Engine:EMS scan for process: svchost pid: 6952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.955 Engine:EMS scan for process: svchost pid: 7600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.957 Engine:EMS scan for process: svchost pid: 7812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.962 Engine:EMS scan for process: svchost pid: 6848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.967 Engine:EMS scan for process: svchost pid: 1324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.985 Engine:EMS scan for process: svchost pid: 7916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.987 Bm signature throttled:0x00002db31bed458f 2026-04-19T00:26:38.995 Engine:EMS scan for process: svchost pid: 7980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:38.999 Engine:EMS scan for process: svchost pid: 8336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.006 Engine:EMS scan for process: explorer pid: 8684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.075 Engine:EMS scan for process: svchost pid: 8876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.079 Engine:EMS scan for process: svchost pid: 9904, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.083 Engine:EMS scan for process: svchost pid: 10048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.092 Engine:EMS scan for process: svchost pid: 10804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.099 Engine:EMS scan for process: dllhost pid: 11100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.103 Engine:EMS scan for process: svchost pid: 11304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.107 Engine:EMS scan for process: svchost pid: 1004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.112 Engine:EMS scan for process: svchost pid: 7108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.116 Engine:EMS scan for process: svchost pid: 7652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.119 Engine:EMS scan for process: svchost pid: 2136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.138 Engine:EMS scan for process: dllhost pid: 12048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.141 Engine:EMS scan for process: svchost pid: 8420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.148 Engine:EMS scan for process: svchost pid: 3608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.155 Engine:EMS scan for process: svchost pid: 14264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.158 Engine:EMS scan for process: svchost pid: 13028, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.165 Engine:EMS scan for process: svchost pid: 8036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.172 Engine:EMS scan for process: svchost pid: 6596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.176 Engine:EMS scan for process: svchost pid: 9744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.188 Engine:EMS scan for process: svchost pid: 6624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.196 Engine:EMS scan for process: svchost pid: 936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.202 Engine:EMS scan for process: svchost pid: 6228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.205 Engine:EMS scan for process: svchost pid: 15236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.209 Engine:EMS scan for process: svchost pid: 14944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-19T00:26:39.224 Engine:EMS scan for process: wuauclt pid: 476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-19T00:26:51.928 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-19T00:26:51.929 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-19T00:26:51.957 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFEAFC68020, lRefCount: 9, hr=0 2026-04-19T00:26:51.957 [Engine] New active engine 00007FFE73D58020 replacing engine 00007FFEAFC68020. Number of active engines: 2 2026-04-19T00:26:51.964 EngineInit:Global ASOC is enabled 2026-04-19T00:26:51.964 EngineInit:ASOO is enabled for developer volumes 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T00:26:52.039 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.040 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T00:26:52.049 MpWriteUupSignatureVersion 1.449.177.0, hr = 0 2026-04-19T00:26:52.053 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-19T00:26:52.073 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-19T00:26:52.075 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T00:26:52.075 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-19T00:26:52.075 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-19T00:26:52.075 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-19T00:26:52.101 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-19T00:26:52.101 [Plugin] Initializing RTP plugin state... 2026-04-19T00:26:52.101 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎18‎-‎2026 23:28:46 Last Perf:‎04‎-‎18‎-‎2026 23:28:46 First RTP Scan:‎04‎-‎18‎-‎2026 23:28:46 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1541 Misses:19175 BM Queue:0,492,0 Proc:0,182,0 File:0,310,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:68906 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:212776314 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:48041 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:117461 TotalHits:743386 InstanceCacheInserts:1975 InstanceCacheUpdates:0 InstanceCacheDeletes:361 InstanceCacheHits:156 InstanceCacheMisses:38213 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (2331/1019) Success: 1019, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-19T00:26:52.101 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-19T00:26:52.102 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA} 2026-04-19T00:26:52.102 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF}\mpasbase.vdm in use, hr=0x80070020 2026-04-19T00:26:52.104 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DD5F4FE0-6AC3-4E7A-BC2E-C03499CF4379} removed 2026-04-19T00:26:52.104 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-19T00:26:52.105 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.105 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.106 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.106 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.106 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-19-2026 00:26:52 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-19-2026 00:26:52 2026-04-19T00:26:52.111 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-19T00:26:52.111 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-19T00:26:52.114 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T00:26:52.114 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-19T00:26:52.117 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.118 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.118 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.118 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.118 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T00:26:52.118 MdCoreSvc is supported in this platform and OS Signature updated on 04-19-2026 00:26:52 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.177.0 AV Signature Version: 1.449.177.0 ************************************************************ 2026-04-19T00:26:52.121 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-19T00:26:52.121 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\469E3DEE-F9F7-4039-9B50-92E07F2239B71574.1dccf932ddb5b41 2026-04-19T00:26:52.135 Process scan (postsignatureupdatescan) started. 2026-04-19T00:26:52.217 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-19T00:26:52.219 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-19T00:26:52.587 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-19T00:26:52.599 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-19T00:26:52.599 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-19T00:26:52.599 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-19T00:26:52.611 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-19T00:26:52.612 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-19T00:26:52.613 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-19T00:26:52.613 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-19T00:26:52.613 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T00:26:52.613 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T00:26:52.614 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-19T00:26:52.614 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-19T00:26:52.614 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-19T00:26:52.615 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.620 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.624 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.628 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T00:26:52.665 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-19T00:26:52.665 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-19T00:26:52.665 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-19T00:26:52.665 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T00:26:52.665 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T00:26:52.669 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T00:26:52.669 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-19T00:26:52.694 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 5978609(ms) from now at 04:06 (02:06 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-19T00:26:54.135 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T00:26:54.142 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T00:26:54.143 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T00:26:55.202 [RTP] Duplicating the current plugin configuration object... 2026-04-19T00:26:55.202 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T00:26:55.202 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-04-19T00:26:55.202 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T00:26:55.202 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-19T00:26:55.203 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-19T00:27:12.217 Process scan (postsignatureupdatescan) completed. Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 2026-04-19T00:30:40.973 QuickScan:ScanID:FBC0BFB6-22D6-4AF9-A12E-0D7D2B3B948E: Quick scan finished with error 0 2026-04-19T00:30:40.983 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x70548d8c7ffffffe 2026-04-19T00:30:40.987 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x70548d8c7ffffffe 2026-04-19T00:30:41.001 [Engine] Engine 00007FFEAFC68020 no longer in use. Number of active engines: 1 2026-04-19T00:30:41.001 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 5 resources, RtpIoavOnly: FALSE 2026-04-19T00:30:41.210 ProcessImageName: explorer.exe, Pid: 8684, TotalTime: 341241, Count: 50568, MaxTime: 1796, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 3% 2026-04-19T00:30:41.210 ProcessImageName: AcroCEF.exe, Pid: 5176, TotalTime: 4107, Count: 175, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-04-19T00:30:41.210 ProcessImageName: dllhost.exe, Pid: 11100, TotalTime: 3884, Count: 82, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\ONNKX1GX_487\1GLDF21M3X_11, EstimatedImpact: 19% 2026-04-19T00:30:41.210 ProcessImageName: notepad++.exe, Pid: 6388, TotalTime: 1282, Count: 90, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-19T00:30:41.210 ProcessImageName: httpd.exe, Pid: 9736, TotalTime: 997, Count: 90, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_95.php, EstimatedImpact: 0% 2026-04-19T00:30:41.210 ProcessImageName: WmiPrvSE.exe, Pid: 5692, TotalTime: 693, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\refs.sys, EstimatedImpact: 89% 2026-04-19T00:30:41.210 ProcessImageName: svchost.exe, Pid: 10048, TotalTime: 609, Count: 3, MaxTime: 609, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-19T00:30:41.210 ProcessImageName: firefox.exe, Pid: 14004, TotalTime: 555, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 68% 2026-04-19T00:30:41.210 ProcessImageName: notepad++.exe, Pid: 13952, TotalTime: 382, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\httpd.conf@2026-04-19_002333, EstimatedImpact: 0% 2026-04-19T00:30:41.210 ProcessImageName: Notepad.exe, Pid: 6440, TotalTime: 289, Count: 25, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_98.php, EstimatedImpact: 35% 2026-04-19T00:30:41.210 ProcessImageName: AdobeCollabSync.exe, Pid: 6724, TotalTime: 243, Count: 23, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal, EstimatedImpact: 0% 2026-04-19T00:30:41.210 ProcessImageName: PickerHost.exe, Pid: 8988, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 100% 2026-04-19T00:30:41.210 ProcessImageName: PickerHost.exe, Pid: 708, TotalTime: 226, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 100% 2026-04-19T00:30:41.210 ProcessImageName: PickerHost.exe, Pid: 1432, TotalTime: 211, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 78% 2026-04-19T00:30:41.210 ProcessImageName: backgroundTaskHost.exe, Pid: 12292, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-04-19T00:30:41.290 [Engine] RSIG_UNLOADENGINE, 00007FFEAFC68020, err=0x0 2026-04-19T00:30:41.304 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{58BD5798-D45B-4D1B-9EC3-2738AEE6F6CF} removed 2026-04-19T00:30:41.498 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-19T00:30:41.498 [RTP] Duplicating the current plugin configuration object... 2026-04-19T00:30:41.498 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T00:30:41.498 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-19T00:30:41.498 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T00:30:41.498 [RTP] No config change detected. Not updating plugin configuration. 2026-04-19T00:30:41.498 [RTP] No config changes found. No configuration switch. 2026-04-19T00:30:41.498 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-19T00:30:42.995 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T00:30:43.000 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T00:30:43.002 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T00:30:44.551 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-19T00:30:44.551 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:44.551 [RTP] Duplicating the current plugin configuration object... 2026-04-19T00:30:44.551 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T00:30:44.551 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-19T00:30:44.551 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-19T00:30:44.551 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-19T00:30:44.646 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy8\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.196 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.383 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.568 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.772 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.945 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-04-19T00:30:45.948 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2 2026-04-19T00:31:51.999 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-19T00:32:22.424 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #70622, FileId: 0x81000000002524, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:39:21.453 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T00:39:34.510 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB5FB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #70997, FileId: 0x1800000001ab87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:40:12.531 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A5E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71002, FileId: 0xfa000000003f13, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:40:17.961 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5FAD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71004, FileId: 0xfc000000003f13, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:40:22.845 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php72C9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71006, FileId: 0x12700000000bf14, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:47:04.267 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php92D9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71907, FileId: 0x1a9000000004b56, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:47:09.576 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA79C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71909, FileId: 0x5900000003544b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:47:12.013 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB114.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71911, FileId: 0x5b00000003544b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:47:24.492 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE1EA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71914, FileId: 0x1ac000000004b56, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:47:34.445 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php89E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #71921, FileId: 0x5f00000003544b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:53:47.154 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB89E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #72253, FileId: 0xfc00000000c0a0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:53:51.886 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCB3E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #72255, FileId: 0xa600000000c251, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:53:56.595 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDD8F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #72260, FileId: 0xa800000000c251, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:54:26.453 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T00:56:09.218 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE393.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #72314, FileId: 0x137000000002b57, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T00:56:13.351 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF3C1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #72316, FileId: 0x139000000002b57, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-19-2026 09:10:11 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/19/2026 09:10:11.433374100 UTC (14156 ms since boot) 2026-04-19T09:10:11.457 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-19T09:10:11.462 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T09:10:11.462 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T09:10:11.496 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260419-091011-00000003-fffffffeffffffff.bin ... 2026-04-19T09:10:11.655 [WPP] Trace session started - MpWppTracing-20260419-091011-00000003-fffffffeffffffff.bin 2026-04-19T09:10:11.662 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-19T09:10:11.662 [RbM] Rollback manager succesfully initialized. 2026-04-19T09:10:11.662 [RbM] Rollback manager EnableRollbackManager called. 2026-04-19T09:10:11.671 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-19T09:10:11.672 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-19T09:10:11.672 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-19T09:10:11.672 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-19T09:10:11.672 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-19T09:10:11.677 MdCoreSvc is supported in this platform and OS 2026-04-19T09:10:11.677 MdCoreSvc is supported in this platform and OS 2026-04-19T09:10:11.677 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-19T09:10:11.677 [PlatUpd] Starting MdCoreSvc service 2026-04-19T09:10:11.722 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-19T09:10:15.302 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-19T09:10:15.302 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-19T09:10:15.302 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-19T09:10:15.302 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-19T09:10:15.302 [PlatUpd] CSP platform update started 2026-04-19T09:10:15.302 [PlatUpd] Defender MDM CSP platform update not required 2026-04-19T09:10:15.302 [PlatUpd] WMI/PS provider platform update started 2026-04-19T09:10:15.302 [PlatUpd] WMI/PS provider platform update not required 2026-04-19T09:10:15.302 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-19T09:10:15.302 MdCoreSvc is supported in this platform and OS 2026-04-19T09:10:15.302 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-19T09:10:15.318 [PlatUpd] Starting MdCoreSvc service 2026-04-19T09:10:15.318 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-19T09:10:15.318 [TS] Troublshooting mode is not available! 2026-04-19T09:10:15.318 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-19T09:10:15.318 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-19T09:10:15.333 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-19T09:10:15.333 [Service] Enabling AutoLoggers ... 2026-04-19T09:10:15.333 [Service] Enabling AMSI registration ... 2026-04-19T09:10:15.333 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-19T09:10:15.349 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 51978 Number of invalid entries is 0 Number of inserts issued is 1571733 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6342 Number of lookups is 106620571 Number of lookup misses is 5109083 Number of fast lookup misses is 54460815 Number of false fast lookups is 5109078 Number of invalidations is 728059 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-19T09:10:15.349 Verifying license file... 2026-04-19T09:10:15.349 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-19T09:10:15.365 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-19T09:10:15.365 Loaded module#0 MpComServer. 2026-04-19T09:10:15.365 Loaded module#1 StartupPolicies. 2026-04-19T09:10:15.365 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-19T09:10:15.365 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-19T09:10:15.365 COM server initialized successfully. 2026-04-19T09:10:15.380 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-19T09:10:15.396 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-19T09:10:15.396 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-19T09:10:15.412 [RTP] [RTP] FilterCommunicator object 0x000001F1B7E9D7F0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-19T09:10:15.412 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-19T09:10:15.412 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T09:10:15.412 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T09:10:15.412 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-19T09:10:15.412 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-19T09:10:15.412 [RTP] [RTP] FilterCommunicator object 0x000001F1B7E9DA00 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-19T09:10:15.412 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-19T09:10:15.412 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-19T09:10:15.412 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-19T09:10:15.412 [RTP] [RTP] StartCommunication 0x000001F1B7E9D7F0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-19T09:10:15.412 [init][RTP] RTPPlugin initialization completed 2026-04-19T09:10:15.412 OS boot count = 2 2026-04-19T09:10:15.412 OS Install = 0 2026-04-19T09:10:15.427 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-19T09:10:15.427 [KSL] Entering CKSLEngine::Initialize. 2026-04-19T09:10:15.427 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-19T09:10:15.427 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-19T09:10:15.427 [KSL] MpInstallKslD: hr=0x1 2026-04-19T09:10:15.427 [KSL] MpRegisterKslD: hr=0 2026-04-19T09:10:15.427 [KSL] MpStartKslD: hr=0 2026-04-19T09:10:15.427 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-19T09:10:15.427 Loading engine... 2026-04-19T09:10:15.443 Verifying engine and signature files (source: 1) ... 2026-04-19T09:10:15.443 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpengine.dll] due to PPL. 2026-04-19T09:10:15.443 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasbase.vdm] (file in cache) 2026-04-19T09:10:15.443 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasdlta.vdm] (file in cache) 2026-04-19T09:10:15.443 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpavbase.vdm] (file in cache) 2026-04-19T09:10:15.443 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpavdlta.vdm] (file in cache) 2026-04-19T09:10:15.490 [Engine] IsHybridMode: 0 2026-04-19T09:10:15.490 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-19T09:10:15.521 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-793868F7243870C577C71514658050AB7633B68C.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-19T09:10:22.052 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-19T09:10:22.052 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-19T09:10:22.052 [Engine] New active engine 00007FFF10EF8020 (no old engine). Number of active engines: 1 2026-04-19T09:10:22.068 EngineInit:Global ASOC is enabled 2026-04-19T09:10:22.068 EngineInit:ASOO is enabled for developer volumes 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.146 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:10:22.162 MpWriteUupSignatureVersion 1.449.177.0, hr = 0 2026-04-19T09:10:22.162 [SigStatUpd] CSignatureStatus: back to good 2026-04-19T09:10:22.162 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-19T09:10:22.193 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-19T09:10:22.193 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T09:10:22.193 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-19T09:10:22.193 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-19T09:10:22.193 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-19T09:10:22.193 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-19T09:10:22.193 [Plugin] Initializing RTP plugin state... 2026-04-19T09:10:22.193 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-19T09:10:22.193 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2207 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12495 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2449 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-19T09:10:22.193 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA} 2026-04-19T09:10:22.193 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:10:22.193 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:10:22.193 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:10:22.193 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T09:10:22.193 MdCoreSvc is supported in this platform and OS 2026-04-19T09:10:22.193 Engine loaded! 2026-04-19T09:10:22.193 [DLP] Create FeatureControlState instance 2026-04-19T09:10:22.208 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-19T09:10:22.208 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-19T09:10:22.208 RegisterSModeChangeListener: hr = 0x1 2026-04-19T09:10:22.208 RegisterHybridModeChangeListener: hr = 0 2026-04-19T09:10:22.224 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-19T09:10:22.224 [SigReleaseHb] Initialized with Stage 0 2026-04-19T09:10:22.224 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-19T09:10:22.224 [SCC][CID=24937_5392] Initializing ... 2026-04-19T09:10:22.224 [SCC][CID=24937_5392] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-19T09:10:22.224 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-19T09:10:22.224 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-19T09:10:22.224 [NRI] Stopping NIS service ... 2026-04-19T09:10:22.224 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-19T09:10:22.224 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.177.0 AV Signature Version: 1.449.177.0 ************************************************************ 2026-04-19T09:10:22.224 Resource usage Monitoring is enabled 2026-04-19T09:10:22.224 Job Notification: New process added to job (4648) 2026-04-19T09:10:22.224 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-19T09:10:22.224 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-19T09:10:22.240 Job Notification: New process added to job (7432) 2026-04-19T09:10:22.240 Job Notification: New process added to job (7440) 2026-04-19T09:10:22.240 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7432] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7440]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-19T09:10:22.302 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-19T09:10:22.302 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-19T09:10:22.318 Job Notification: Process exited from job (7432) 2026-04-19T09:10:22.318 Job Notification: Process exited from job (7440) 2026-04-19T09:10:22.318 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-19T09:10:22.318 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-19T09:10:22.318 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-19T09:10:22.318 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-19T09:10:22.318 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T09:10:22.318 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T09:10:22.318 [RTP] Generating the base plugin configuration ... 2026-04-19T09:10:22.318 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-19T09:10:22.318 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T09:10:22.318 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-19T09:10:22.318 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-19T09:10:22.318 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T09:10:22.318 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-19T09:10:22.318 [RTP] [RTP] StartCommunication 0x000001F1B7E9DA00 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-19T09:10:22.318 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-19T09:10:22.318 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-19T09:10:22.646 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T09:10:22.662 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-19T09:10:22.662 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-19T09:10:22.662 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-19T09:10:25.224 [RTP] Duplicating the current plugin configuration object... 2026-04-19T09:10:25.224 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T09:10:25.224 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-19T09:10:25.224 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-19T09:10:25.224 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-19T09:11:15.349 Process scan (poststartupscan) started. 2026-04-19T09:11:15.349 Process scan (poststartupscan) completed. 2026-04-19T09:11:15.849 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-19T09:11:15.849 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-19T09:11:18.427 [RTP] Duplicating the current plugin configuration object... 2026-04-19T09:11:18.427 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T09:11:18.427 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-19T09:11:18.427 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-19T09:11:18.427 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-19T09:12:14.724 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T09:12:14.724 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T09:12:14.724 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T09:15:12.177 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #594, FileId: 0xd0000000004bec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:15:22.083 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-19T09:15:22.224 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T09:20:11.005 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #1725, FileId: 0x65000000000d6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:20:22.208 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-19T09:20:22.224 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-19T09:20:22.240 Job Notification: New process added to job (5464) 2026-04-19T09:20:22.240 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-19T09:20:22.240 Aggressive catchup quick scan threshold: 320688016109 / 25920000000000 2026-04-19T09:20:22.240 Job Notification: New process added to job (5460) 2026-04-19T09:20:22.255 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:5464] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5460]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-19T09:20:22.287 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 62629421(ms) from now at 04:44 (02:44 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-19T09:20:22.333 Job Notification: New process added to job (4820) 2026-04-19T09:20:22.349 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-19T09:20:22.349 Job Notification: New process added to job (8008) 2026-04-19T09:20:22.349 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:4820] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8008]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-19T09:20:22.521 Job Notification: New process added to job (5268) 2026-04-19T09:20:22.537 Task(GetDeviceTicket -AccessKey 5AABBAD9-475E-6104-CEB9-682BF2030DFC ) launched as network service 2026-04-19T09:20:22.740 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-19T09:20:22.740 [RTP] Duplicating the current plugin configuration object... 2026-04-19T09:20:22.740 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T09:20:22.740 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-19T09:20:22.740 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T09:20:22.740 [RTP] No config change detected. Not updating plugin configuration. 2026-04-19T09:20:22.740 [RTP] No config changes found. No configuration switch. 2026-04-19T09:20:22.740 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-19T09:20:22.958 Job Notification: Process exited from job (5268) 2026-04-19T09:20:23.021 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-19T09:20:23.021 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T09:20:23.021 [Cloud] Queued cloud request. 2026-04-19T09:20:23.021 [Cloud] Dequeued cloud request. 2026-04-19T09:20:23.021 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T09:20:23.224 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-19T09:20:23.224 [Cloud] End of cloud request. 2026-04-19T09:20:23.521 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T09:20:50.693 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\8CD07615-3D76-42D7-A0B4-DAFCCB1C1F7712b8.1dccfddcf81bcb7 2026-04-19T09:20:50.787 Verifying engine and signature files (source: 0) ... 2026-04-19T09:20:50.787 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpengine.dll] due to PPL. 2026-04-19T09:20:50.787 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpasbase.vdm] (file in cache) 2026-04-19T09:20:50.787 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-19T09:20:50.802 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpasdlta.vdm] 2026-04-19T09:20:50.802 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpavbase.vdm] (file in cache) 2026-04-19T09:20:50.802 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-19T09:20:50.818 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpavdlta.vdm] 2026-04-19T09:20:50.974 [Engine] IsHybridMode: 0 2026-04-19T09:20:50.974 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-19T09:20:50.974 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-15D9C2058550D960B200823621720478DE8C75F7.bin): 0x00000002 2026-04-19T09:20:50.990 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-15D9C2058550D960B200823621720478DE8C75F7.bin) 2026-04-19T09:20:50.990 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-19T09:20:50.990 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-19T09:20:50.990 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-19T09:20:50.990 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-19T09:21:02.677 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-19T09:21:02.677 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-19T09:21:02.693 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFF10EF8020, lRefCount: 5, hr=0 2026-04-19T09:21:02.693 [Engine] New active engine 00007FFF0AD68020 replacing engine 00007FFF10EF8020. Number of active engines: 2 2026-04-19T09:21:02.693 EngineInit:Global ASOC is enabled 2026-04-19T09:21:02.693 EngineInit:ASOO is enabled for developer volumes 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T09:21:02.755 MpWriteUupSignatureVersion 1.449.184.0, hr = 0 2026-04-19T09:21:02.771 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-19T09:21:02.787 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-19T09:21:02.787 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T09:21:02.787 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-19T09:21:02.787 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-19T09:21:02.787 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-19T09:21:02.787 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-19T09:21:02.802 [Plugin] Initializing RTP plugin state... 2026-04-19T09:21:02.802 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-19T09:21:02.802 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎19‎-‎2026 11:10:22 Last Perf:‎04‎-‎19‎-‎2026 11:10:22 First RTP Scan:‎04‎-‎19‎-‎2026 11:10:22 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:691 Misses:1130 BM Queue:0,16,0 Proc:0,16,0 File:0,2,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:1915 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:5576580 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:5167 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:28247 TotalHits:9147 InstanceCacheInserts:25 InstanceCacheUpdates:0 InstanceCacheDeletes:16 InstanceCacheHits:0 InstanceCacheMisses:5774 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (209/79) Success: 79, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-19T09:21:02.802 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B} 2026-04-19T09:21:02.802 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2D7DEBE0-6EB3-4C18-951C-023462DE3693} removed 2026-04-19T09:21:02.802 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-19T09:21:02.802 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA}\mpasbase.vdm in use, hr=0x80070020 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-19-2026 09:21:02 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-19-2026 09:21:02 2026-04-19T09:21:02.802 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-19T09:21:02.802 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-19T09:21:02.802 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T09:21:02.802 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-19T09:21:02.802 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T09:21:02.802 MdCoreSvc is supported in this platform and OS Signature updated on 04-19-2026 09:21:02 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.184.0 AV Signature Version: 1.449.184.0 ************************************************************ 2026-04-19T09:21:02.818 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-19T09:21:02.818 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\8CD07615-3D76-42D7-A0B4-DAFCCB1C1F7712b8.1dccfddcf81bcb7 2026-04-19T09:21:02.880 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-19T09:21:02.880 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-19-2026 09:21:02 ************************************************************ 2026-04-19T09:21:02.912 Job Notification: Process exited from job (4820) 2026-04-19T09:21:02.912 Job Notification: Process exited from job (8008) 2026-04-19T09:21:02.990 Job Notification: Process exited from job (5464) 2026-04-19T09:21:02.990 Job Notification: Process exited from job (5460) 2026-04-19T09:21:03.162 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-19T09:21:03.162 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-19T09:21:03.162 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-19T09:21:03.162 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T09:21:03.162 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T09:21:03.162 [Engine] Engine 00007FFF10EF8020 no longer in use. Number of active engines: 1 2026-04-19T09:21:03.162 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T09:21:03.162 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-19T09:21:03.240 ProcessImageName: DeviceCensus.exe, Pid: 3052, TotalTime: 1358, Count: 6, MaxTime: 750, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-04-19T09:21:03.240 ProcessImageName: WmiPrvSE.exe, Pid: 1500, TotalTime: 585, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 78% 2026-04-19T09:21:03.240 ProcessImageName: powershell.exe, Pid: 4552, TotalTime: 384, Count: 30, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 22% 2026-04-19T09:21:03.240 ProcessImageName: svchost.exe, Pid: 2492, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 0% 2026-04-19T09:21:03.240 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\PushToInstall\Registration->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T09:21:03.240 ProcessImageName: OfficeC2RClient.exe, Pid: 7332, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1120.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-19T09:21:03.240 ProcessImageName: OfficeC2RClient.exe, Pid: 3824, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 2% 2026-04-19T09:21:03.240 ProcessImageName: RUXIMICS.exe, Pid: 5316, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 22% 2026-04-19T09:21:03.271 [Engine] RSIG_UNLOADENGINE, 00007FFF10EF8020, err=0x0 2026-04-19T09:21:03.271 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-19T09:21:03.271 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-19T09:21:03.271 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-19T09:21:03.271 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8DB6645C-FF5E-4DC2-827E-FCDAEBF27FCA} removed 2026-04-19T09:21:04.818 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T09:21:04.818 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T09:21:04.818 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T09:21:15.349 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-19T09:21:31.396 Process scan (postsignatureupdatescan) completed. 2026-04-19T09:26:02.708 [RbM] Setting Last known good engine candidate. hr = 0 BEGIN BM telemetry GUID:{056F6047-16E0-50A1-5022-329B81CFC8C8} SignatureID:48049478956430 SigSha:73cc283bde9843fca73b0f93351b76c5d52529db ThreatLevel:0 ProcessID:3680 ProcessCreationTime:134210646093219072 SessionID:0 CreationTime:04-19-2026 09:30:09 ImagePath:C:\Windows\System32\svchost.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\System32\services.exe:756:1, Operations:None END BM telemetry 2026-04-19T09:30:09.849 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T09:30:09.849 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T09:30:09.849 [Cloud] Queued cloud request. 2026-04-19T09:30:09.849 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T09:30:09.849 [Cloud] Dequeued cloud request. 2026-04-19T09:30:09.849 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T09:30:09.865 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-19T09:30:09.865 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T09:30:09.865 [Cloud] Queued cloud request. 2026-04-19T09:30:09.865 [Cloud] Dequeued cloud request. 2026-04-19T09:30:09.865 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T09:30:09.974 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-19T09:30:09.974 [Cloud] End of cloud request. 2026-04-19T09:30:10.005 [Cloud] End of cloud request. 2026-04-19T09:30:10.490 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T09:30:27.224 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T09:43:18.333 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T09:43:18.333 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T09:43:18.333 [Cloud] Queued cloud request. 2026-04-19T09:43:18.333 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T09:43:18.333 [Cloud] Dequeued cloud request. 2026-04-19T09:43:18.333 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T09:43:18.583 [Cloud] End of cloud request. 2026-04-19T09:43:19.099 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T09:43:19.989 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:43:22.768 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #3295, FileId: 0x38b000000000a32, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:43:22.877 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:43:22.987 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:43:23.362 Bm signature throttled:0x00002bb3641ff58e BEGIN BM telemetry GUID:{E741E78A-DA66-5472-6EBA-D5FFD6274238} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:5456 ProcessCreationTime:134210654067972604 SessionID:2 CreationTime:04-19-2026 09:43:26 ImagePath:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\147.0.3912.72\msedgewebview2.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Program Files\TeamViewer\TeamViewer.exe:3864:1, Operations:None END BM telemetry 2026-04-19T09:43:26.871 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:27.745 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:28.034 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:28.127 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:28.455 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:29.829 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:43:40.016 Engine:Triggered SMS scan for filename: explorer.exe, pid: 6636, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-04-19T09:43:51.366 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-04-19T09:43:51.366 [RTP] Duplicating the current plugin configuration object... 2026-04-19T09:43:51.366 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T09:43:51.366 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-19T09:43:51.366 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-19T09:43:51.366 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-19T09:43:51.475 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe BEGIN BM telemetry GUID:{BA7FC870-DDD3-19A0-F3EC-22F137EA8895} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:10668 ProcessCreationTime:134210654332070636 SessionID:2 CreationTime:04-19-2026 09:43:53 ImagePath:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\explorer.exe:6636:1, Operations:None END BM telemetry 2026-04-19T09:43:54.001 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:54.161 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:54.161 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:54.265 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:54.485 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:54.535 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:56.293 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:56.860 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #6061, FileId: 0x16000000085d8f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:43:57.815 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:57.815 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:57.817 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:57.825 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:43:57.828 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:01.782 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:01.895 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:02.155 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:02.384 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:02.401 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:03.927 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:04.039 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:04.674 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:04.774 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:04.782 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:04.791 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:12.433 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:12.657 Bm signature throttled:0x0000adb3669e2e33 BEGIN BM telemetry GUID:{35D72B60-487F-2DBE-356E-BA1B78676D37} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:9280 ProcessCreationTime:134210654526488302 SessionID:2 CreationTime:04-19-2026 09:44:12 ImagePath:C:\Windows\System32\rundll32.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\System32\svchost.exe:2188:1, Operations:None END BM telemetry 2026-04-19T09:44:19.678 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:44:19.888 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:21.996 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:22.846 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:44:24.140 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:26.084 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:44:38.629 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-19T09:44:38.629 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-04-19T09:44:38.629 [RTP] Duplicating the current plugin configuration object... 2026-04-19T09:44:38.629 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-19T09:44:38.629 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-19T09:44:38.629 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-19T09:44:38.644 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-19T09:45:27.695 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:45:32.227 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T09:45:54.111 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:46:02.099 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:46:04.334 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:46:56.997 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:47:56.713 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:48:03.280 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:48:05.530 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7754, FileId: 0x2000000008f7b2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:48:25.555 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7765, FileId: 0x5c00000003676c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:51:27.504 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:52:54.915 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:52:57.259 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7816, FileId: 0x6500000003676c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:11.371 Bm signature throttled:0x0000adb3669e2e33 BEGIN BM telemetry GUID:{6EE4C942-2043-6AAE-6059-2E7967D30982} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:12144 ProcessCreationTime:134210660798116541 SessionID:2 CreationTime:04-19-2026 09:54:39 ImagePath:C:\Program Files\Firefox Developer Edition\firefox.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\System32\svchost.exe:1468:1, Operations:None END BM telemetry 2026-04-19T09:54:39.853 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:54:40.759 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7873, FileId: 0x4d000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.759 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7876, FileId: 0x81000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.775 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7877, FileId: 0x50000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.775 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7878, FileId: 0x82000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.775 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7879, FileId: 0x83000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.775 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7880, FileId: 0x51000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.775 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7874, FileId: 0x80000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.791 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7884, FileId: 0x86000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.791 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7882, FileId: 0x52000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.791 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7887, FileId: 0x55000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.791 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7885, FileId: 0x87000000004bf2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.806 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7890, FileId: 0x57000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.806 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7888, FileId: 0x56000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:40.806 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7892, FileId: 0x58000000035298, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:41.181 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13f9ee6c-0937-4ffb-a21b-a7e5f5fb803b. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #7922, FileId: 0x270000000038de, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:54:58.311 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:55:24.641 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:55:24.954 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj443D25945. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8223, FileId: 0x2100000008f994, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.032 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBA469B9C8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8230, FileId: 0xcd000000003cab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.048 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj500DD293B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8229, FileId: 0x2500000008f98f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.048 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj772D849F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8234, FileId: 0x2300000008f994, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.079 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj84EA779E4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8239, FileId: 0x1e00000008f99c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.276 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAABD72955. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8277, FileId: 0xed000000004ba5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.323 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCF7A17909. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8282, FileId: 0x2000000008f9a6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.354 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB4514E922. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8286, FileId: 0x2100000008f99c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.385 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5A5020906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8288, FileId: 0x2500000008f99d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:25.401 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E9E80979. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8289, FileId: 0x2600000008f99d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:26.047 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0D0BDF97D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8299, FileId: 0x2800000008f994, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:39.611 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8439, FileId: 0x2200000008f973, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:39.689 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8441, FileId: 0x2400000008f984, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:55:39.814 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8447, FileId: 0x2300000008f98b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:56:39.949 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8449, FileId: 0xf0000000004ba5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:58:23.379 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:58:25.957 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #8487, FileId: 0xe5000000004b2b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T09:58:28.978 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T09:58:49.784 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T09:59:35.603 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:00:37.224 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T10:01:59.801 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:03:28.682 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:04:24.190 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:05:30.593 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:05:39.895 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8570, FileId: 0x2900000008f973, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T10:05:39.911 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8572, FileId: 0x2800000008f984, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T10:09:01.777 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:09:02.819 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:10:22.235 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-19T10:12:32.522 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:13:23.661 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:13:23.661 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:13:49.862 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:14:12.692 [RTP] [Mini-filter] OpenWithoutRead notification (2447, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-04-19T10:14:44.528 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:15:42.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T10:16:03.339 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:19:33.985 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:19:36.969 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:19:40.454 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:23:04.790 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:24:24.217 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:25:24.635 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:26:35.407 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:28:49.937 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:30:06.017 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:30:47.238 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T10:33:36.630 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:35:22.919 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:35:22.981 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:37:07.385 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:40:38.100 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:43:49.999 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:43:54.327 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:43:55.894 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:44:09.246 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:44:24.188 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:44:43.068 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:45:52.238 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T10:47:39.953 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:51:10.729 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:54:41.553 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:55:07.390 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T10:55:24.633 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:58:12.357 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T10:58:50.058 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:00:57.230 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T11:01:42.987 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:04:24.188 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:05:13.617 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.797 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.819 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.828 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.914 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.920 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.925 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.931 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.932 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.945 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:06.952 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:08:07.902 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:08:08.283 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:08.402 Engine:Process 912 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-19T11:08:09.456 Bm signature throttled:0x000015b367acd5a5 2026-04-19T11:08:12.478 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:12.485 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:08:33.876 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16564, FileId: 0x7e00000000421d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:08:44.242 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:10:08.994 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:10:09.369 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:10:11.139 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:11:30.467 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:11:30.702 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:12:06.220 Bm signature throttled:0x00002fb3d48c1e28 2026-04-19T11:12:14.256 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:13:50.125 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:14:12.241 Bm signature throttled:0x000075b3d68c353f 2026-04-19T11:14:26.139 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:14:26.404 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:15:44.854 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:16:02.233 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T11:17:03.287 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:17:21.085 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:17:38.487 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:19:15.475 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:21:02.534 Bm signature throttled:0x00002fb3d48c1e28 2026-04-19T11:21:02.706 ProcessImageName: AcroCEF.exe, Pid: 10848, TotalTime: 3666, Count: 168, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-19T11:21:02.706 ProcessImageName: dllhost.exe, Pid: 8932, TotalTime: 2825, Count: 77, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LEQ0NS2CRU_88, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: AsPowerBar.exe, Pid: 9860, TotalTime: 2819, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 14% 2026-04-19T11:21:02.706 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 2805, Count: 123, MaxTime: 765, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: DipAwayMode.exe, Pid: 7612, TotalTime: 2727, Count: 16, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: MOM.exe, Pid: 12944, TotalTime: 1961, Count: 29, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-04-19T11:21:02.706 ProcessImageName: AISuite3.exe, Pid: 1096, TotalTime: 1242, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-19T11:21:02.706 ProcessImageName: websockify.exe, Pid: 12996, TotalTime: 849, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 69% 2026-04-19T11:21:02.706 ProcessImageName: WmiPrvSE.exe, Pid: 7600, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-04-19T11:21:02.706 ProcessImageName: firefox.exe, Pid: 3432, TotalTime: 585, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 44% 2026-04-19T11:21:02.706 ProcessImageName: TeamViewer.exe, Pid: 3864, TotalTime: 288, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 3% 2026-04-19T11:21:02.706 ProcessImageName: TabTip.exe, Pid: 6424, TotalTime: 247, Count: 10, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 46% 2026-04-19T11:21:02.706 ProcessImageName: backgroundTaskHost.exe, Pid: 14308, TotalTime: 210, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1776496858, EstimatedImpact: 20% 2026-04-19T11:21:02.706 ProcessImageName: AdobeCollabSync.exe, Pid: 1784, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-19.log, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: FileCoAuth.exe, Pid: 9492, TotalTime: 136, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-19T11:21:02.706 ProcessImageName: WhatsApp.Root.exe, Pid: 10280, TotalTime: 135, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: SDXHelper.exe, Pid: 13880, TotalTime: 135, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 10% 2026-04-19T11:21:02.706 ProcessImageName: Acrobat.exe, Pid: 576, TotalTime: 121, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 10% 2026-04-19T11:21:02.706 ProcessImageName: backgroundTaskHost.exe, Pid: 4212, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 23% 2026-04-19T11:21:02.706 ProcessImageName: OfficeC2RClient.exe, Pid: 13912, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 3% 2026-04-19T11:21:02.706 ProcessImageName: PhoneExperienceHost.exe, Pid: 2512, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: runonce.exe, Pid: 12768, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-04-19T11:21:02.706 ProcessImageName: AcroCEF.exe, Pid: 3140, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 21% 2026-04-19T11:21:02.706 ProcessImageName: taskhostw.exe, Pid: 5352, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 37% 2026-04-19T11:21:02.706 ProcessImageName: svchost.exe, Pid: 788, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-19T11:21:02.706 ProcessImageName: Acrobat.exe, Pid: 13644, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 8% 2026-04-19T11:21:02.706 ProcessImageName: SDXHelper.exe, Pid: 8796, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 9% 2026-04-19T11:21:02.706 ProcessImageName: OpenWith.exe, Pid: 12888, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisb.ttf, EstimatedImpact: 5% 2026-04-19T11:21:02.706 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: svchost.exe, Pid: 3656, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1b22f6bc141e8f5efca9e524a43bbb948a733dfe\content.phf, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: dllhost.exe, Pid: 4020, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 7% 2026-04-19T11:21:02.706 ProcessImageName: backgroundTaskHost.exe, Pid: 9752, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 30% 2026-04-19T11:21:02.706 ProcessImageName: OfficeC2RClient.exe, Pid: 12316, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1308.log, EstimatedImpact: 1% 2026-04-19T11:21:02.706 ProcessImageName: winlogon.exe, Pid: 6780, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 1% 2026-04-19T11:21:02.706 ProcessImageName: OfficeC2RClient.exe, Pid: 5268, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1152.log, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: TeamViewer_Service.exe, Pid: 4564, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: OfficeC2RClient.exe, Pid: 13108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1148a.log, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: OneDriveLauncher.exe, Pid: 14104, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: AggregatorHost.exe, Pid: 5432, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-19T11:21:02.706 ProcessImageName: svchost.exe, Pid: 14164, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-19T11:21:48.049 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18801, FileId: 0x5000000000870c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:22:46.165 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:23:08.909 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:24:24.197 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:25:24.659 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:25:40.972 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:25:41.221 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:26:16.049 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #18976, FileId: 0xae00000000866b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:26:16.978 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:27:58.757 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:29:47.615 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:31:07.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{099B9027-9561-5E63-AE73-2C0B6D29ACB1} SignatureID:48049478956430 SigSha:73cc283bde9843fca73b0f93351b76c5d52529db ThreatLevel:0 ProcessID:13568 ProcessCreationTime:134210719327619159 SessionID:0 CreationTime:04-19-2026 11:32:12 ImagePath:C:\Windows\System32\svchost.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\Windows\System32\services.exe:756:1, Operations:None END BM telemetry 2026-04-19T11:32:13.284 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T11:32:13.284 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T11:32:13.284 [Cloud] Queued cloud request. 2026-04-19T11:32:13.284 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T11:32:13.284 [Cloud] Dequeued cloud request. 2026-04-19T11:32:13.284 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T11:32:13.487 [Cloud] End of cloud request. 2026-04-19T11:32:13.987 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T11:33:18.293 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:36:42.942 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:36:49.004 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:37:06.581 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:37:24.465 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:40:00.146 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:40:03.647 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19307, FileId: 0x410000000075ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:40:19.989 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:42:06.533 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:43:23.339 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:43:50.213 Bm signature throttled:0x00002bb3641ff58e BEGIN BM telemetry GUID:{60FB8602-88CE-B716-44DE-C5CA9273367F} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:10144 ProcessCreationTime:134210726307089641 SessionID:2 CreationTime:04-19-2026 11:43:50 ImagePath:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\147.0.3912.72\msedgewebview2.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: C:\program files (x86)\microsoft\edgewebview\application\147.0.3912.72\msedgewebview2.exe:11448:1, Operations:None END BM telemetry BEGIN BM telemetry GUID:{5B3DB278-3460-E01F-AA86-4841FCAE4C27} SignatureID:190986032393779 SigSha:a40b18c67b4e14db0a9701cfaaa95a98f4f81e97 ThreatLevel:0 ProcessID:10668 ProcessCreationTime:134210654332070636 SessionID:2 CreationTime:04-19-2026 11:43:54 ImagePath:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-19T11:43:55.978 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:44:11.019 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:44:11.535 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:44:12.457 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:44:24.200 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:44:47.381 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:46:12.235 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T11:47:21.360 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.704 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:48:04.798 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.896 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.898 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.903 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.908 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.909 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:04.981 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:48:08.942 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:49:04.740 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:49:04.756 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19718, FileId: 0x4600000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19720, FileId: 0xc000000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19721, FileId: 0x4800000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19723, FileId: 0xc200000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19722, FileId: 0x4a00000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.131 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19724, FileId: 0x4b00000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.146 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19727, FileId: 0x4d00000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.146 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19726, FileId: 0x4c00000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.146 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19730, FileId: 0xc600000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.146 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19728, FileId: 0xc400000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.146 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19732, FileId: 0xc700000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.162 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19729, FileId: 0x4f00000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.162 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19736, FileId: 0xc900000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.162 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19734, FileId: 0xc800000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.600 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19770, FileId: 0x5400000000e065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:49:05.600 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\34467ee2-9ff1-42e0-af76-be7caecc5017. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #19772, FileId: 0xe100000000232e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:50:51.971 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:51:24.487 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:52:00.597 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:54:22.799 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:55:07.423 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T11:55:24.650 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:57:54.301 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T11:58:41.069 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19977, FileId: 0x5f00000000e0d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T11:58:50.276 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:01:17.226 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T12:01:24.903 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:03:45.554 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:04:10.070 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20074, FileId: 0x6200000000e0d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:04:24.199 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:04:42.996 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:04:55.532 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:08:26.197 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:11:57.400 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:13:50.338 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:15:28.059 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:16:22.226 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T12:18:58.759 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:20:05.831 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:22:29.637 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:24:24.191 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:25:07.377 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:25:07.440 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:25:24.644 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:26:00.731 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:28:50.400 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:29:31.610 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:31:27.235 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T12:33:02.378 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:33:03.409 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:36:33.084 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:40:03.862 Bm signature throttled:0x0000adb3669e2e33 2026-04-19T12:40:07.331 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:40:07.394 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:42:02.518 Bm signature throttled:0x00002bb3641ff58e 2026-04-19T12:42:11.174 Bm signature throttled:0x00002bb3641ff58e BEGIN BM telemetry GUID:{85AD9193-7F94-0202-CA31-2C80F585E1E3} SignatureID:147007337517939 SigSha:a4944b7579f586c96692e5fd334c916b7cce3fa2 ThreatLevel:0 ProcessID:9644 ProcessCreationTime:134210761378891413 SessionID:2 CreationTime:04-19-2026 12:42:19 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: D:\xampp\apache\bin\libapr-1.dll:25,D:\xampp\apache\bin\libaprutil-1.dll:25,D:\xampp\apache\bin\libhttpd.dll:25,D:\xampp\apache\bin\libapriconv-1.dll:25,D:\xampp\apache\bin\pcre2-8.dll:25,D:\xampp\apache\modules\mod_access_compat.so:25,D:\xampp\apache\modules\mod_actions.so:25,D:\xampp\apache\modules\mod_alias.so:25,D:\xampp\apache\modules\mod_allowmethods.so:25,D:\xampp\apache\modules\mod_asis.so:25,D:\xampp\apache\modules\mod_auth_basic.so:25,D:\xampp\apache\modules\mod_authn_core.so:25,D:\xampp\apache\modules\mod_authn_file.so:25,D:\xampp\apache\modules\mod_authz_core.so:25,D:\xampp\apache\modules\mod_authz_groupfile.so:25,D:\xampp\apache\modules\mod_authz_host.so:25,D:\xampp\apache\modules\mod_authz_user.so:25,D:\xampp\apache\modules\mod_autoindex.so:25,D:\xampp\apache\modules\mod_cgi.so:25,D:\xampp\apache\modules\mod_dav_lock.so:25,; Parents: D:\xampp\xampp-control.exe:2092:3,C:\Windows\System32\svchost.exe:8096:2,C:\Windows\System32\csrss.exe:912:2,C:\Windows\explorer.exe:6636:2,C:\Windows\System32\csrss.exe:588:2,C:\Windows\System32\svchost.exe:988:2, Operations:None END BM telemetry 2026-04-19T12:42:21.049 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T12:42:21.049 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T12:42:21.049 [Cloud] Queued cloud request. 2026-04-19T12:42:21.049 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T12:42:21.049 [Cloud] Dequeued cloud request. 2026-04-19T12:42:21.049 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T12:42:21.065 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-19T12:42:21.065 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T12:42:21.065 [Cloud] Queued cloud request. 2026-04-19T12:42:21.065 [Cloud] Dequeued cloud request. 2026-04-19T12:42:21.065 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T12:42:21.346 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-19T12:42:21.346 [Cloud] End of cloud request. 2026-04-19T12:42:21.440 [Cloud] End of cloud request. 2026-04-19T12:42:21.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T12:42:21.909 Engine:Triggered SMS scan for filename: httpd.exe, pid: 9644, sigseq: 0x85B3D021D373, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0x148a175b 2026-04-19T12:42:38.815 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\35D07548-9636-4876-8652-F9753BC587011600.1dccffa0057b85e 2026-04-19T12:42:38.924 Verifying engine and signature files (source: 0) ... 2026-04-19T12:42:38.924 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpengine.dll] due to PPL. 2026-04-19T12:42:38.924 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasbase.vdm] (file in cache) 2026-04-19T12:42:38.924 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-19T12:42:38.940 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasdlta.vdm] 2026-04-19T12:42:38.940 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpavbase.vdm] (file in cache) 2026-04-19T12:42:38.940 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-19T12:42:38.956 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpavdlta.vdm] 2026-04-19T12:42:39.112 [Engine] IsHybridMode: 0 2026-04-19T12:42:39.112 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-19T12:42:39.127 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A54686C517E07C39DE3ED9C188E9D51C32350A55.bin): 0x00000002 2026-04-19T12:42:39.127 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A54686C517E07C39DE3ED9C188E9D51C32350A55.bin) 2026-04-19T12:42:39.127 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-19T12:42:39.127 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-19T12:42:39.127 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-19T12:42:39.127 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-19T12:42:51.216 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-19T12:42:51.216 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-19T12:42:51.248 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFF0AD68020, lRefCount: 5, hr=0 2026-04-19T12:42:51.248 [Engine] New active engine 00007FFEB5D98020 replacing engine 00007FFF0AD68020. Number of active engines: 2 2026-04-19T12:42:51.248 EngineInit:Global ASOC is enabled 2026-04-19T12:42:51.248 EngineInit:ASOO is enabled for developer volumes 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.310 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-19T12:42:51.326 MpWriteUupSignatureVersion 1.449.186.0, hr = 0 2026-04-19T12:42:51.326 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-19T12:42:51.341 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-19T12:42:51.341 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-19T12:42:51.341 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-19T12:42:51.341 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-19T12:42:51.341 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-19T12:42:51.373 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-19T12:42:51.373 [Plugin] Initializing RTP plugin state... 2026-04-19T12:42:51.373 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎19‎-‎2026 11:21:03 Last Perf:‎04‎-‎19‎-‎2026 11:21:02 First RTP Scan:‎04‎-‎19‎-‎2026 11:21:03 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2433 Misses:12918 BM Queue:0,252,0 Proc:0,225,0 File:0,168,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,2,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:21047 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:115447998 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:15600 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:61001 TotalHits:152125 InstanceCacheInserts:2207 InstanceCacheUpdates:0 InstanceCacheDeletes:26 InstanceCacheHits:429 InstanceCacheMisses:24551 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:5ms (3082/569) Success: 569, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-19T12:42:51.373 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-19T12:42:51.373 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA} 2026-04-19T12:42:51.373 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6241B9B6-E035-4850-91F8-523ED687CE87} removed 2026-04-19T12:42:51.373 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B}\mpasbase.vdm in use, hr=0x80070020 2026-04-19T12:42:51.373 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-19-2026 12:42:51 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-19-2026 12:42:51 2026-04-19T12:42:51.373 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-19T12:42:51.373 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-19T12:42:51.373 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T12:42:51.373 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-19T12:42:51.373 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-19T12:42:51.373 MdCoreSvc is supported in this platform and OS Signature updated on 04-19-2026 12:42:51 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.186.0 AV Signature Version: 1.449.186.0 ************************************************************ 2026-04-19T12:42:51.388 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-19T12:42:51.388 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\35D07548-9636-4876-8652-F9753BC587011600.1dccffa0057b85e 2026-04-19T12:42:51.404 Process scan (postsignatureupdatescan) started. 2026-04-19T12:42:51.466 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-19T12:42:51.482 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-19T12:42:51.826 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-19T12:42:51.826 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-19T12:42:51.826 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-19T12:42:51.826 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-19T12:42:51.826 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-19T12:42:51.826 [Engine] Engine 00007FFF0AD68020 no longer in use. Number of active engines: 1 2026-04-19T12:42:51.826 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-19T12:42:51.826 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-19T12:42:51.857 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-19T12:42:51.857 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-19T12:42:51.857 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-19T12:42:52.013 ProcessImageName: AcroCEF.exe, Pid: 10848, TotalTime: 3666, Count: 168, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-19T12:42:52.013 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 3282, Count: 144, MaxTime: 765, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 0% 2026-04-19T12:42:52.013 ProcessImageName: dllhost.exe, Pid: 8932, TotalTime: 2825, Count: 77, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LEQ0NS2CRU_88, EstimatedImpact: 0% 2026-04-19T12:42:52.013 ProcessImageName: AsPowerBar.exe, Pid: 9860, TotalTime: 2819, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 14% 2026-04-19T12:42:52.013 ProcessImageName: DipAwayMode.exe, Pid: 7612, TotalTime: 2727, Count: 16, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-19T12:42:52.013 ProcessImageName: MOM.exe, Pid: 12944, TotalTime: 1961, Count: 29, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-04-19T12:42:52.013 ProcessImageName: AISuite3.exe, Pid: 1096, TotalTime: 1242, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-19T12:42:52.013 ProcessImageName: websockify.exe, Pid: 12996, TotalTime: 849, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 69% 2026-04-19T12:42:52.013 ProcessImageName: WmiPrvSE.exe, Pid: 7600, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-04-19T12:42:52.013 ProcessImageName: firefox.exe, Pid: 3432, TotalTime: 585, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 44% 2026-04-19T12:42:52.013 ProcessImageName: firefox.exe, Pid: 2700, TotalTime: 465, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09728, EstimatedImpact: 60% 2026-04-19T12:42:52.013 ProcessImageName: httpd.exe, Pid: 9644, TotalTime: 378, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 23% 2026-04-19T12:42:52.013 ProcessImageName: TeamViewer.exe, Pid: 3864, TotalTime: 303, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-04-19T12:42:52.013 ProcessImageName: TabTip.exe, Pid: 6424, TotalTime: 247, Count: 10, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 46% 2026-04-19T12:42:52.076 [Engine] RSIG_UNLOADENGINE, 00007FFF0AD68020, err=0x0 2026-04-19T12:42:52.091 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8EF9F21C-E230-4ABE-9BB5-5C8B8CB9233B} removed 2026-04-19T12:42:53.394 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T12:42:53.409 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-19T12:42:53.409 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-19T12:43:09.430 Process scan (postsignatureupdatescan) completed. 2026-04-19T12:45:34.036 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php65D1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #21229, FileId: 0xb000000000e45b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:45:40.369 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7E9B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #21231, FileId: 0xb200000000e45b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:45:53.581 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB230.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #21233, FileId: 0xb400000000e45b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:46:32.226 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T12:47:51.302 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-19T12:53:53.894 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php66A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #22801, FileId: 0x3c00000003e25d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:53:56.305 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFD2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #22803, FileId: 0x3e00000003e25d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:54:05.729 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php34B2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #22807, FileId: 0x4b000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:54:14.392 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5684.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #22809, FileId: 0x1900000008a57c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:55:24.026 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php667F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #22989, FileId: 0x2000000008a579, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:55:35.277 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9273.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23004, FileId: 0x52000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:59:42.763 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5941.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23305, FileId: 0x17000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T12:59:50.491 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php777A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23307, FileId: 0x34000000032882, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:03.894 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpABCA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23312, FileId: 0x140000000338e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:11.601 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC9E3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23315, FileId: 0x58000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:17.983 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE2CC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23317, FileId: 0x5a000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:34.398 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1410.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23319, FileId: 0x5c000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:36.640 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2BC0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23321, FileId: 0x5e000000065d93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:43.596 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php46EB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23324, FileId: 0x37000000032882, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:00:52.328 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php691B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23327, FileId: 0x39000000032882, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:08.044 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA53C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23329, FileId: 0x2500000008a579, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:13.214 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBAAA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23331, FileId: 0x180000000338e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:26.265 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEDB3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23335, FileId: 0x1a0000000338e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:28.635 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF6FC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23337, FileId: 0x1c0000000338e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:32.978 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7D6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23339, FileId: 0x1e0000000338e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:37.229 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T13:01:47.016 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3EB7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23341, FileId: 0x4200000003e25d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:01:55.197 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5D7C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23343, FileId: 0x1e000000062524, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:01.016 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php753C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23345, FileId: 0x36000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:08.587 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9307.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23349, FileId: 0x1b000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:11.746 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9F4E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23351, FileId: 0x1d000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:15.211 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpACDD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23353, FileId: 0x1f000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:17.675 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB683.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23355, FileId: 0x21000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:26.451 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD76B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23357, FileId: 0x24000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:38.287 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6CA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23359, FileId: 0x4600000003e25d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:40.641 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1033.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23361, FileId: 0x4800000003e25d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:50.416 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3541.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23363, FileId: 0xa8000000004143, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:02:53.198 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php410B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23365, FileId: 0xaa000000004143, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:03:10.946 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php86A1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23369, FileId: 0x27000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:03:14.657 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php951A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23371, FileId: 0x29000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:03:19.057 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA652.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23373, FileId: 0x2b000000032e26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:03:24.800 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBCDA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23396, FileId: 0x21000000062524, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:03:25.728 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23398, FileId: 0x1f000000061e27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:04:56.693 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php23BF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23577, FileId: 0x1e000000061f58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:09.972 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5560.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23579, FileId: 0x5500000004b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:18.645 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7984.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23581, FileId: 0x5700000004b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:25.393 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php93F4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23583, FileId: 0x5900000004b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:34.450 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB74D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23586, FileId: 0x3b000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:46.447 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE62F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23589, FileId: 0xd400000000d298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:51.581 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFA36.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23591, FileId: 0x3e000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:05:59.177 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php17E1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23593, FileId: 0x5d00000004b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:06:44.773 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC9FD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23666, FileId: 0x41000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:06:49.663 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDD39.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23668, FileId: 0x43000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:06:51.984 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE634.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23670, FileId: 0x45000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:07:23.076 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5FAD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23676, FileId: 0x48000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:07:40.953 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA582.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23678, FileId: 0x4b000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:07:50.668 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCB7A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23680, FileId: 0x4d000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:00.210 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF0B8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23682, FileId: 0x4f000000032e1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:07.727 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE15.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23686, FileId: 0xd900000000d298, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:12.869 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php223C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23688, FileId: 0x180000000360d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:15.210 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2B56.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23690, FileId: 0x1a0000000360d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:25.070 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php51FA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23695, FileId: 0x8f000000003fd7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:08:27.318 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5AB7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23697, FileId: 0x92000000003fd7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:10:24.266 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23758, FileId: 0x211000000004b17, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:14:35.271 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF7FA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23884, FileId: 0x7300000000d9f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.595 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj954366968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23906, FileId: 0x1700000008ac4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.611 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE981F79EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23907, FileId: 0x1800000008ac4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.619 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj528A99926. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23908, FileId: 0x1900000008ac4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.630 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1A65199A9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23909, FileId: 0x1a00000008ac4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.648 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7F4EE299A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23911, FileId: 0x1c00000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.654 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj462F169E8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23912, FileId: 0x1a00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.914 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF0471195E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23913, FileId: 0x1600000008b232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.928 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6D470D92E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23914, FileId: 0x1e00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.942 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj03F1629AB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23915, FileId: 0x1f00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.955 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2B78CC905. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23916, FileId: 0x2000000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.968 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj09C11192A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23917, FileId: 0x2100000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.982 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD48259974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23918, FileId: 0x2200000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:00.997 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA380BC955. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23919, FileId: 0x2300000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.010 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEAC333927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23920, FileId: 0x2400000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.023 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70E32299D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23921, FileId: 0x2500000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.037 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAE2464929. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23922, FileId: 0x2600000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.050 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC82C47956. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23923, FileId: 0x2700000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.082 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8609C97D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23924, FileId: 0x2800000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.098 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCC66059AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23925, FileId: 0x2900000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.106 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj04B16D9D4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23926, FileId: 0x2a00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.114 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB8C6B49F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23927, FileId: 0x2b00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.131 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj39E05F960. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23928, FileId: 0x3300000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.137 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D95A39CC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23929, FileId: 0x3400000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.256 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC3A8CF900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23930, FileId: 0x3900000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.268 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD0B11B923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23931, FileId: 0x2d00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.282 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj657D2B916. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23932, FileId: 0x2e00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.295 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEDBAF59B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23933, FileId: 0x2f00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.309 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAE9BA6936. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23934, FileId: 0x3000000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.333 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7A20F29AC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23935, FileId: 0x3100000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.350 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C1A38946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23936, FileId: 0x3200000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.399 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8C437B923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23937, FileId: 0x3300000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.416 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1AECA5947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23938, FileId: 0x3400000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.425 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD8CCE8938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23939, FileId: 0x3500000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.433 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj00F56D9DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23940, FileId: 0x3600000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.452 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3E291E9AA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23941, FileId: 0x4800000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.457 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC9E580994. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23942, FileId: 0x4900000008ac4d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.589 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDD335297A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23943, FileId: 0x1800000008b232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.602 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj022053927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23944, FileId: 0x3a00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.747 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA4E88A977. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23954, FileId: 0x4400000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:01.961 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj44484893E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23964, FileId: 0x4d00000008adca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:16:42.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x09224982 2026-04-19T13:29:21.064 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T13:29:21.064 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T13:29:21.064 [Cloud] Queued cloud request. 2026-04-19T13:29:21.064 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T13:29:21.064 [Cloud] Dequeued cloud request. 2026-04-19T13:29:21.073 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x84aab460 2026-04-19T13:29:21.104 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T13:29:21.105 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T13:29:21.105 [Cloud] Queued cloud request. 2026-04-19T13:29:21.105 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T13:29:21.106 [Cloud] Dequeued cloud request. 2026-04-19T13:29:21.107 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T13:29:21.602 [Cloud] End of cloud request. 2026-04-19T13:29:21.602 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_0.php. status=0x40030000, statusex=0x200210, threatid=0x10001396, sigseq=0x64e730511cb7 2026-04-19T13:29:21.849 [Cloud] End of cloud request. 2026-04-19T13:29:21.849 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_1.php. status=0x40030000, statusex=0x200210, threatid=0x10001396, sigseq=0x64e730511cb7 2026-04-19T13:29:22.116 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T13:31:47.238 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T13:42:25.649 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php74E7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #25811, FileId: 0xeb000000004abd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:46:52.234 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T13:55:09.911 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1E66.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #26249, FileId: 0x16b000000000c02, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:55:51.163 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBF9C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #26275, FileId: 0x1d0000000bbed6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T13:59:57.926 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php839D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #26593, FileId: 0x130000000bbee3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:01:57.232 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T14:08:25.871 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php43E2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #27505, FileId: 0x6f00000004b038, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x6754f83f 2026-04-19T14:09:54.371 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T14:09:54.371 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T14:09:54.371 [Cloud] Queued cloud request. 2026-04-19T14:09:54.371 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T14:09:54.371 [Cloud] Dequeued cloud request. 2026-04-19T14:09:54.371 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T14:09:54.944 [Cloud] End of cloud request. 2026-04-19T14:09:54.944 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_51.php. status=0x40030000, statusex=0x200210, threatid=0x10001396, sigseq=0x64e730511cb7 2026-04-19T14:09:55.463 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T14:15:00.044 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php47C1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #28268, FileId: 0x160000000bbf01, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:16:47.777 [RTP] [Mini-filter] Unsuccessful scan status(#190): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEC9C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #28311, FileId: 0x9100000000dc0f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:17:02.233 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T14:30:47.688 [RTP] [Mini-filter] Unsuccessful scan status(#200): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBD8F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29238, FileId: 0x120000000bbee9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:32:07.228 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T14:33:35.320 [RTP] [Mini-filter] Unsuccessful scan status(#210): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4C7C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29286, FileId: 0x11a000000004077, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:35:12.927 [RTP] [Mini-filter] Unsuccessful scan status(#220): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC9BB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29385, FileId: 0x1e800000000209d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:36:37.171 [RTP] [Mini-filter] Unsuccessful scan status(#230): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php12F8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29420, FileId: 0x3a00000008f933, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:37:31.992 [RTP] [Mini-filter] Unsuccessful scan status(#240): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE929.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29451, FileId: 0x1b0000000bbeed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:38:33.031 [RTP] [Mini-filter] Unsuccessful scan status(#250): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD7B0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29486, FileId: 0x4c000000099ef4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:39:17.944 [RTP] [Mini-filter] Unsuccessful scan status(#260): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php872E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29515, FileId: 0x170000000bbee5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:40:08.504 [RTP] [Mini-filter] Unsuccessful scan status(#270): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4CD4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29556, FileId: 0x2b00000008cf38, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:42:09.299 [RTP] [Mini-filter] Unsuccessful scan status(#280): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php24B5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29604, FileId: 0x280000000bbeed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:42:51.261 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 4850, Count: 360, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: httpd.exe, Pid: 7676, TotalTime: 4644, Count: 474, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_101.php, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: EXCEL.EXE, Pid: 12752, TotalTime: 1885, Count: 135, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\Library\SOLVER\SOLVER.XLAM->xl/vbaProject.bin, EstimatedImpact: 9% 2026-04-19T14:42:51.261 ProcessImageName: notepad++.exe, Pid: 9892, TotalTime: 785, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 13732, TotalTime: 701, Count: 70, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: svchost.exe, Pid: 6176, TotalTime: 671, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 12% 2026-04-19T14:42:51.261 ProcessImageName: Notepad.exe, Pid: 2848, TotalTime: 334, Count: 31, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 22% 2026-04-19T14:42:51.261 ProcessImageName: Photos.exe, Pid: 7748, TotalTime: 211, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 7% 2026-04-19T14:42:51.261 ProcessImageName: PickerHost.exe, Pid: 576, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 92% 2026-04-19T14:42:51.261 ProcessImageName: PickerHost.exe, Pid: 5776, TotalTime: 181, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 90% 2026-04-19T14:42:51.261 ProcessImageName: SDXHelper.exe, Pid: 12236, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 12% 2026-04-19T14:42:51.261 ProcessImageName: FileCoAuth.exe, Pid: 9968, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-19T14:42:51.261 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: dllhost.exe, Pid: 3148, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 4% 2026-04-19T14:42:51.261 ProcessImageName: prevhost.exe, Pid: 13844, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\wbk4074.tmp, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: OfficeC2RClient.exe, Pid: 13848, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 2% 2026-04-19T14:42:51.261 ProcessImageName: OfficeC2RClient.exe, Pid: 480, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 1% 2026-04-19T14:42:51.261 ProcessImageName: dllhost.exe, Pid: 2540, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 2% 2026-04-19T14:42:51.261 ProcessImageName: AdobeCollabSync.exe, Pid: 1784, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: OfficeC2RClient.exe, Pid: 5444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1603.log, EstimatedImpact: 2% 2026-04-19T14:42:51.261 ProcessImageName: dllhost.exe, Pid: 4920, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: AggregatorHost.exe, Pid: 5432, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: RuntimeBroker.exe, Pid: 8552, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{26E30DD2-E9D0-427F-9760-ACF2B18CDDCD}.json, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: OfficeC2RClient.exe, Pid: 10392, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1638.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: FileCoAuth.exe, Pid: 13384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-19.1430.13384.2.aodl, EstimatedImpact: 0% 2026-04-19T14:42:51.261 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10200, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-19T14:42:51.262 ProcessImageName: dllhost.exe, Pid: 10464, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B93782C1.pf, EstimatedImpact: 0% 2026-04-19T14:44:35.956 [RTP] [Mini-filter] Unsuccessful scan status(#290): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php61AB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29648, FileId: 0xe0000000bbf67, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:46:05.705 [RTP] [Mini-filter] Unsuccessful scan status(#300): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC064.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29672, FileId: 0x3c0000000360d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:47:12.227 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T14:58:23.160 [RTP] [Mini-filter] Unsuccessful scan status(#310): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php116.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29759, FileId: 0x210000000bbf4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T14:59:40.461 [RTP] [Mini-filter] Unsuccessful scan status(#320): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2F1B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29873, FileId: 0xef000000010601, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:02:04.109 [RTP] [Mini-filter] Unsuccessful scan status(#330): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6057.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #30158, FileId: 0xc0000000bbf0b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:02:17.231 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0xc060b555 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x4de848b7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x9bd0481e Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x8d88b532 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x000048d0 2026-04-19T15:17:22.231 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T15:21:29.684 [RTP] [Mini-filter] Unsuccessful scan status(#340): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2975.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #30762, FileId: 0xdc000000004c35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:31:48.439 [RTP] [Mini-filter] Unsuccessful scan status(#350): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9A88.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #31221, FileId: 0x100000000bbfce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:32:27.227 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T15:32:43.202 [RTP] [Mini-filter] Unsuccessful scan status(#360): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7099.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #31260, FileId: 0x8a0000000039f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:47:32.235 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T15:51:48.886 [RTP] [Mini-filter] Unsuccessful scan status(#370): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEBE4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #31918, FileId: 0x1f000000039ecd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:52:33.828 [RTP] [Mini-filter] Unsuccessful scan status(#380): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9B81.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #31948, FileId: 0x26000000039ecd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:56:57.533 [RTP] [Mini-filter] Unsuccessful scan status(#390): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA191.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #31998, FileId: 0x34000000039f42, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:58:07.836 [RTP] [Mini-filter] Unsuccessful scan status(#400): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB47A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32035, FileId: 0x790000000050c4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:59:19.465 [RTP] [Mini-filter] Unsuccessful scan status(#410): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCC48.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32068, FileId: 0x1f000000039e7c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T15:59:58.682 [RTP] [Mini-filter] Unsuccessful scan status(#420): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php659E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32093, FileId: 0x1460000000050a0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:00:54.668 [RTP] [Mini-filter] Unsuccessful scan status(#430): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4062.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32124, FileId: 0x14f0000000050a0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:01:40.738 [RTP] [Mini-filter] Unsuccessful scan status(#440): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF465.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32153, FileId: 0x1630000000050a0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:02:37.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T16:02:51.044 [RTP] [Mini-filter] Unsuccessful scan status(#450): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php702.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32183, FileId: 0x2a000000039e90, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:17:42.227 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T16:21:19.088 [RTP] [Mini-filter] Unsuccessful scan status(#460): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEF75.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32552, FileId: 0x1c6000000004e99, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:32:47.235 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T16:37:10.304 [RTP] [Mini-filter] Unsuccessful scan status(#470): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7019.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32779, FileId: 0x21000000039fa5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:42:51.277 ProcessImageName: httpd.exe, Pid: 7676, TotalTime: 8847, Count: 916, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_101.php, EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 6591, Count: 501, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: EXCEL.EXE, Pid: 12752, TotalTime: 1885, Count: 135, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\Library\SOLVER\SOLVER.XLAM->xl/vbaProject.bin, EstimatedImpact: 9% 2026-04-19T16:42:51.277 ProcessImageName: notepad++.exe, Pid: 9892, TotalTime: 785, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 13732, TotalTime: 701, Count: 70, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: svchost.exe, Pid: 6176, TotalTime: 671, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 12% 2026-04-19T16:42:51.277 ProcessImageName: Notepad.exe, Pid: 2848, TotalTime: 334, Count: 31, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 22% 2026-04-19T16:42:51.277 ProcessImageName: httpd.exe, Pid: 388, TotalTime: 317, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-04-19T16:42:51.277 ProcessImageName: httpd.exe, Pid: 10492, TotalTime: 315, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\sess_6jr2ku35f2nb41ad6102dgaeo7, EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: Photos.exe, Pid: 7748, TotalTime: 211, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 7% 2026-04-19T16:42:51.277 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 196, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T16:42:51.277 ProcessImageName: PickerHost.exe, Pid: 576, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 92% 2026-04-19T16:42:51.277 ProcessImageName: PickerHost.exe, Pid: 5776, TotalTime: 181, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 90% 2026-04-19T16:42:51.277 ProcessImageName: backgroundTaskHost.exe, Pid: 2604, TotalTime: 180, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 30% 2026-04-19T16:42:51.277 ProcessImageName: SDXHelper.exe, Pid: 12236, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 12% 2026-04-19T16:42:51.277 ProcessImageName: FileCoAuth.exe, Pid: 9968, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-19T16:42:51.277 ProcessImageName: dllhost.exe, Pid: 3148, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 4% 2026-04-19T16:42:51.278 ProcessImageName: prevhost.exe, Pid: 13844, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\wbk4074.tmp, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: dllhost.exe, Pid: 4920, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 13848, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 2% 2026-04-19T16:42:51.278 ProcessImageName: AggregatorHost.exe, Pid: 5432, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 480, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 1% 2026-04-19T16:42:51.278 ProcessImageName: dllhost.exe, Pid: 2540, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 2% 2026-04-19T16:42:51.278 ProcessImageName: AdobeCollabSync.exe, Pid: 1784, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 2588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1757.log, EstimatedImpact: 2% 2026-04-19T16:42:51.278 ProcessImageName: FileCoAuth.exe, Pid: 14212, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-19.1543.14212.1.aodl, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1603.log, EstimatedImpact: 2% 2026-04-19T16:42:51.278 ProcessImageName: SDXHelper.exe, Pid: 13492, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5836, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1654.log, EstimatedImpact: 1% 2026-04-19T16:42:51.278 ProcessImageName: RuntimeBroker.exe, Pid: 8552, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{26E30DD2-E9D0-427F-9760-ACF2B18CDDCD}.json, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10392, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1638.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: FileCoAuth.exe, Pid: 13384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-19.1430.13384.2.aodl, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10200, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-19T16:42:51.278 ProcessImageName: dllhost.exe, Pid: 10464, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B93782C1.pf, EstimatedImpact: 0% 2026-04-19T16:47:52.231 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T16:54:40.475 [RTP] [Mini-filter] Unsuccessful scan status(#480): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33468, FileId: 0xce00000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:54:40.522 [RTP] [Mini-filter] Unsuccessful scan status(#490): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33482, FileId: 0xd900000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:54:41.065 [RTP] [Mini-filter] Unsuccessful scan status(#500): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33543, FileId: 0x3d00000000de6b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T16:54:41.776 [RTP] [Mini-filter] Unsuccessful scan status(#510): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33638, FileId: 0xed00000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T17:02:57.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x1b8edd91 2026-04-19T17:17:00.994 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-19T17:17:00.994 [Cloud] Start of cloud request. Passive mode: 0 2026-04-19T17:17:00.994 [Cloud] Queued cloud request. 2026-04-19T17:17:00.994 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-19T17:17:00.994 [Cloud] Dequeued cloud request. 2026-04-19T17:17:00.994 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-19T17:17:02.874 [Cloud] End of cloud request. 2026-04-19T17:17:02.874 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\html\fileflowweb\index.php. status=0x40030000, statusex=0x200210, threatid=0x10001396, sigseq=0x64e730511cb7 2026-04-19T17:17:03.401 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-19T17:18:02.224 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T17:30:33.429 [RTP] [Mini-filter] Unsuccessful scan status(#520): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php503E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #34995, FileId: 0x3300000003c20e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T17:33:07.238 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T17:33:34.879 [RTP] [Mini-filter] Unsuccessful scan status(#530): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php153D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #35059, FileId: 0x3f00000001c537, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T17:36:58.076 [RTP] [Mini-filter] Unsuccessful scan status(#540): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2F02.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #35088, FileId: 0x14b000000004077, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T17:48:12.235 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T17:55:03.028 [RTP] [Mini-filter] Unsuccessful scan status(#550): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBD2F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #35693, FileId: 0x5b0000000356a6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T18:03:17.232 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T18:06:57.962 [RTP] [Mini-filter] Unsuccessful scan status(#560): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA5FD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #35774, FileId: 0x2300000003d4c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T18:18:22.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T18:33:27.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T18:42:51.385 ProcessImageName: httpd.exe, Pid: 7676, TotalTime: 8847, Count: 916, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_101.php, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 7668, Count: 583, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: firefox.exe, Pid: 12260, TotalTime: 2206, Count: 214, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 74% 2026-04-19T18:42:51.385 ProcessImageName: EXCEL.EXE, Pid: 12752, TotalTime: 1885, Count: 135, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\Library\SOLVER\SOLVER.XLAM->xl/vbaProject.bin, EstimatedImpact: 9% 2026-04-19T18:42:51.385 ProcessImageName: httpd.exe, Pid: 5648, TotalTime: 1143, Count: 136, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_85.php, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: notepad++.exe, Pid: 9892, TotalTime: 785, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: notepad++.exe, Pid: 12880, TotalTime: 769, Count: 87, MaxTime: 46, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\html\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 13732, TotalTime: 716, Count: 72, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: svchost.exe, Pid: 6176, TotalTime: 671, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 12% 2026-04-19T18:42:51.385 ProcessImageName: httpd.exe, Pid: 10492, TotalTime: 420, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\sess_6jr2ku35f2nb41ad6102dgaeo7, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: notepad++.exe, Pid: 13380, TotalTime: 380, Count: 48, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\index.php@2026-04-19_192040, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: Notepad.exe, Pid: 2848, TotalTime: 334, Count: 31, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 22% 2026-04-19T18:42:51.385 ProcessImageName: httpd.exe, Pid: 388, TotalTime: 317, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-04-19T18:42:51.385 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 256, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: Photos.exe, Pid: 7748, TotalTime: 211, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 7% 2026-04-19T18:42:51.385 ProcessImageName: PickerHost.exe, Pid: 576, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 92% 2026-04-19T18:42:51.385 ProcessImageName: PickerHost.exe, Pid: 5776, TotalTime: 181, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 90% 2026-04-19T18:42:51.385 ProcessImageName: backgroundTaskHost.exe, Pid: 2604, TotalTime: 180, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 30% 2026-04-19T18:42:51.385 ProcessImageName: SDXHelper.exe, Pid: 12236, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 12% 2026-04-19T18:42:51.385 ProcessImageName: FileCoAuth.exe, Pid: 9968, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: AggregatorHost.exe, Pid: 5432, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: dllhost.exe, Pid: 3148, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 4% 2026-04-19T18:42:51.385 ProcessImageName: prevhost.exe, Pid: 13844, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\wbk4074.tmp, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: dllhost.exe, Pid: 4920, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: OfficeC2RClient.exe, Pid: 13848, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: OfficeC2RClient.exe, Pid: 480, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 1% 2026-04-19T18:42:51.385 ProcessImageName: dllhost.exe, Pid: 2540, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: AdobeCollabSync.exe, Pid: 1784, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-04-19T18:42:51.385 ProcessImageName: OfficeC2RClient.exe, Pid: 8680, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1925.log, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: OfficeC2RClient.exe, Pid: 2588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1757.log, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: OfficeC2RClient.exe, Pid: 5444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1603.log, EstimatedImpact: 2% 2026-04-19T18:42:51.385 ProcessImageName: FileCoAuth.exe, Pid: 14212, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-19.1543.14212.1.aodl, EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: notepad++.exe, Pid: 9660, TotalTime: 30, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 19% 2026-04-19T18:42:51.386 ProcessImageName: SDXHelper.exe, Pid: 13492, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 11744, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-2006.log, EstimatedImpact: 1% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 13076, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-2026.log, EstimatedImpact: 1% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 13432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1849.log, EstimatedImpact: 1% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 5836, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1654.log, EstimatedImpact: 1% 2026-04-19T18:42:51.386 ProcessImageName: RuntimeBroker.exe, Pid: 8552, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{26E30DD2-E9D0-427F-9760-ACF2B18CDDCD}.json, EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 10392, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1638.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: FileCoAuth.exe, Pid: 13384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-19.1430.13384.2.aodl, EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: OfficeC2RClient.exe, Pid: 1348, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1936.log, EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10200, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.220.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-04-19T18:42:51.386 ProcessImageName: dllhost.exe, Pid: 10464, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-B93782C1.pf, EstimatedImpact: 0% 2026-04-19T18:45:33.954 [RTP] [Mini-filter] Unsuccessful scan status(#570): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFC61.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #37062, FileId: 0x2d00000003c3bc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T18:48:32.415 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T18:49:05.381 [RTP] [Mini-filter] Unsuccessful scan status(#580): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37100, FileId: 0xfa00000000df4b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T19:03:37.577 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T19:04:17.660 [RTP] [Mini-filter] Unsuccessful scan status(#590): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2108.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #37337, FileId: 0x3400000003d9c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T19:18:42.707 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T19:32:12.771 [RTP] [Mini-filter] Unsuccessful scan status(#600): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAFB5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #37772, FileId: 0x4500000003d1c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T19:33:47.806 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T19:48:52.873 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T20:03:57.923 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T20:19:02.961 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T20:26:03.298 [RTP] [Mini-filter] Unsuccessful scan status(#610): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFA3C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #38419, FileId: 0x3900000003519d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-19T20:34:07.987 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-19T20:42:52.065 ProcessImageName: httpd.exe, Pid: 7676, TotalTime: 8847, Count: 916, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_101.php, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: explorer.exe, Pid: 6636, TotalTime: 8845, Count: 671, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: firefox.exe, Pid: 12260, TotalTime: 2206, Count: 214, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 74% 2026-04-19T20:42:52.065 ProcessImageName: EXCEL.EXE, Pid: 12752, TotalTime: 1885, Count: 135, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\Library\SOLVER\SOLVER.XLAM->xl/vbaProject.bin, EstimatedImpact: 9% 2026-04-19T20:42:52.065 ProcessImageName: httpd.exe, Pid: 5648, TotalTime: 1848, Count: 206, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_85.php, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: notepad++.exe, Pid: 9892, TotalTime: 785, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: notepad++.exe, Pid: 12880, TotalTime: 769, Count: 87, MaxTime: 46, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\html\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 13732, TotalTime: 716, Count: 72, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: svchost.exe, Pid: 6176, TotalTime: 671, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 12% 2026-04-19T20:42:52.065 ProcessImageName: httpd.exe, Pid: 10492, TotalTime: 420, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\sess_6jr2ku35f2nb41ad6102dgaeo7, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: notepad++.exe, Pid: 13380, TotalTime: 380, Count: 48, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\index.php@2026-04-19_192040, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: firefox.exe, Pid: 12208, TotalTime: 360, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa02708, EstimatedImpact: 46% 2026-04-19T20:42:52.065 ProcessImageName: Notepad.exe, Pid: 2848, TotalTime: 334, Count: 31, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 22% 2026-04-19T20:42:52.065 ProcessImageName: httpd.exe, Pid: 388, TotalTime: 317, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-04-19T20:42:52.065 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 286, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: Photos.exe, Pid: 7748, TotalTime: 211, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 7% 2026-04-19T20:42:52.065 ProcessImageName: PickerHost.exe, Pid: 576, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 92% 2026-04-19T20:42:52.065 ProcessImageName: PickerHost.exe, Pid: 5776, TotalTime: 181, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 90% 2026-04-19T20:42:52.065 ProcessImageName: backgroundTaskHost.exe, Pid: 2604, TotalTime: 180, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 30% 2026-04-19T20:42:52.065 ProcessImageName: SDXHelper.exe, Pid: 12236, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 12% 2026-04-19T20:42:52.065 ProcessImageName: FileCoAuth.exe, Pid: 9968, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-19T20:42:52.065 ProcessImageName: AggregatorHost.exe, Pid: 5432, TotalTime: 121, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: dllhost.exe, Pid: 3148, TotalTime: 105, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 4% 2026-04-19T20:42:52.065 ProcessImageName: prevhost.exe, Pid: 13844, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\wbk4074.tmp, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: dllhost.exe, Pid: 4920, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 8268, TotalTime: 77, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-2150.log, EstimatedImpact: 3% 2026-04-19T20:42:52.065 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 13848, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EA3AAC77-9050-4D4F-9E4C-C62C6B7E4A58, EstimatedImpact: 2% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 480, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 1% 2026-04-19T20:42:52.065 ProcessImageName: dllhost.exe, Pid: 2540, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 2% 2026-04-19T20:42:52.065 ProcessImageName: AdobeCollabSync.exe, Pid: 1784, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 8680, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1925.log, EstimatedImpact: 2% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 2588, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1757.log, EstimatedImpact: 2% 2026-04-19T20:42:52.065 ProcessImageName: OfficeC2RClient.exe, Pid: 5444, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260419-1603.log, EstimatedImpact: 2% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-20-2026 06:24:14 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/20/2026 06:24:14.763357200 UTC (13484 ms since boot) 2026-04-20T06:24:14.779 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-20T06:24:14.784 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T06:24:14.784 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T06:24:14.829 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260420-062414-00000003-fffffffeffffffff.bin ... 2026-04-20T06:24:14.904 [WPP] Trace session started - MpWppTracing-20260420-062414-00000003-fffffffeffffffff.bin 2026-04-20T06:24:14.909 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-20T06:24:14.909 [RbM] Rollback manager succesfully initialized. 2026-04-20T06:24:14.914 [RbM] Rollback manager EnableRollbackManager called. 2026-04-20T06:24:14.920 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-20T06:24:14.929 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-20T06:24:14.936 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-20T06:24:14.936 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-20T06:24:14.936 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-20T06:24:14.979 MdCoreSvc is supported in this platform and OS 2026-04-20T06:24:14.979 MdCoreSvc is supported in this platform and OS 2026-04-20T06:24:14.979 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T06:24:14.979 [PlatUpd] Starting MdCoreSvc service 2026-04-20T06:24:15.019 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-20T06:24:18.761 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-20T06:24:18.761 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-20T06:24:18.761 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-20T06:24:18.761 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-20T06:24:18.761 [PlatUpd] CSP platform update started 2026-04-20T06:24:18.761 [PlatUpd] Defender MDM CSP platform update not required 2026-04-20T06:24:18.761 [PlatUpd] WMI/PS provider platform update started 2026-04-20T06:24:18.761 [PlatUpd] WMI/PS provider platform update not required 2026-04-20T06:24:18.761 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-20T06:24:18.761 MdCoreSvc is supported in this platform and OS 2026-04-20T06:24:18.761 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T06:24:18.761 [PlatUpd] Starting MdCoreSvc service 2026-04-20T06:24:18.761 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-20T06:24:18.761 [TS] Troublshooting mode is not available! 2026-04-20T06:24:18.761 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T06:24:18.761 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-20T06:24:18.777 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-20T06:24:18.777 [Service] Enabling AutoLoggers ... 2026-04-20T06:24:18.777 [Service] Enabling AMSI registration ... 2026-04-20T06:24:18.777 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-20T06:24:18.792 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52135 Number of invalid entries is 0 Number of inserts issued is 1572175 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6356 Number of lookups is 106727995 Number of lookup misses is 5112729 Number of fast lookup misses is 54489221 Number of false fast lookups is 5112724 Number of invalidations is 728343 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-20T06:24:18.792 Verifying license file... 2026-04-20T06:24:18.792 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-20T06:24:18.808 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-20T06:24:18.808 Loaded module#0 MpComServer. 2026-04-20T06:24:18.808 Loaded module#1 StartupPolicies. 2026-04-20T06:24:18.808 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T06:24:18.808 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T06:24:18.808 COM server initialized successfully. 2026-04-20T06:24:18.824 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-20T06:24:18.839 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-20T06:24:18.839 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-20T06:24:18.839 [RTP] [RTP] FilterCommunicator object 0x00000186A78953C0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T06:24:18.855 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-20T06:24:18.855 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T06:24:18.855 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T06:24:18.855 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-20T06:24:18.855 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-20T06:24:18.855 [RTP] [RTP] FilterCommunicator object 0x00000186A78955D0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T06:24:18.855 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-20T06:24:18.855 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-20T06:24:18.855 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-20T06:24:18.855 [RTP] [RTP] StartCommunication 0x00000186A78953C0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T06:24:18.855 [init][RTP] RTPPlugin initialization completed 2026-04-20T06:24:18.855 OS boot count = 2 2026-04-20T06:24:18.855 OS Install = 0 2026-04-20T06:24:18.855 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-20T06:24:18.855 [KSL] Entering CKSLEngine::Initialize. 2026-04-20T06:24:18.855 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-20T06:24:18.855 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-20T06:24:18.871 [KSL] MpInstallKslD: hr=0x1 2026-04-20T06:24:18.871 [KSL] MpRegisterKslD: hr=0 2026-04-20T06:24:18.871 [KSL] MpStartKslD: hr=0 2026-04-20T06:24:18.871 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T06:24:18.871 Loading engine... 2026-04-20T06:24:18.886 Verifying engine and signature files (source: 1) ... 2026-04-20T06:24:18.886 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpengine.dll] due to PPL. 2026-04-20T06:24:18.886 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasbase.vdm] (file in cache) 2026-04-20T06:24:18.886 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasdlta.vdm] (file in cache) 2026-04-20T06:24:18.886 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpavbase.vdm] (file in cache) 2026-04-20T06:24:18.886 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpavdlta.vdm] (file in cache) 2026-04-20T06:24:18.933 [Engine] IsHybridMode: 0 2026-04-20T06:24:18.933 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T06:24:18.964 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A54686C517E07C39DE3ED9C188E9D51C32350A55.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T06:24:25.074 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T06:24:25.074 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T06:24:25.074 [Engine] New active engine 00007FFB6A2B8020 (no old engine). Number of active engines: 1 2026-04-20T06:24:25.089 EngineInit:Global ASOC is enabled 2026-04-20T06:24:25.089 EngineInit:ASOO is enabled for developer volumes 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.167 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:24:25.199 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\589c52fa70d1a8ff5c09c3a8d5ec3cf0c88d1639 Dynamic Signature Compilation Timestamp:04-18-2026 22:41:19 Persistence Type:Duration Time remaining:864000000 2026-04-20T06:24:25.199 MpWriteUupSignatureVersion 1.449.186.0, hr = 0 2026-04-20T06:24:25.199 [SigStatUpd] CSignatureStatus: back to good 2026-04-20T06:24:25.199 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T06:24:25.214 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T06:24:25.214 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T06:24:25.214 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T06:24:25.214 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T06:24:25.214 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T06:24:25.230 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T06:24:25.230 [Plugin] Initializing RTP plugin state... 2026-04-20T06:24:25.230 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T06:24:25.230 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2075 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11445 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2247 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T06:24:25.230 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA} 2026-04-20T06:24:25.230 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:24:25.230 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:24:25.230 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:24:25.230 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T06:24:25.230 MdCoreSvc is supported in this platform and OS 2026-04-20T06:24:25.230 Engine loaded! 2026-04-20T06:24:25.230 [DLP] Create FeatureControlState instance 2026-04-20T06:24:25.230 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-20T06:24:25.230 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-20T06:24:25.230 RegisterSModeChangeListener: hr = 0x1 2026-04-20T06:24:25.230 RegisterHybridModeChangeListener: hr = 0 2026-04-20T06:24:25.246 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-20T06:24:25.246 [SigReleaseHb] Initialized with Stage 0 2026-04-20T06:24:25.246 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-20T06:24:25.246 [SCC][CID=23968_5324] Initializing ... 2026-04-20T06:24:25.246 [SCC][CID=23968_5324] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-20T06:24:25.246 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6800] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6828]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T06:24:25.246 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T06:24:25.246 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T06:24:25.261 [NRI] Stopping NIS service ... 2026-04-20T06:24:25.261 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-20T06:24:25.261 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.186.0 AV Signature Version: 1.449.186.0 ************************************************************ 2026-04-20T06:24:25.261 Resource usage Monitoring is enabled 2026-04-20T06:24:25.261 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T06:24:25.261 Job Notification: New process added to job (4552) 2026-04-20T06:24:25.261 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-20T06:24:25.308 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-20T06:24:25.339 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T06:24:25.339 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T06:24:25.339 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T06:24:25.339 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T06:24:25.339 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T06:24:25.339 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T06:24:25.339 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T06:24:25.339 [RTP] Generating the base plugin configuration ... 2026-04-20T06:24:25.339 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-20T06:24:25.339 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T06:24:25.339 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-20T06:24:25.355 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-20T06:24:25.355 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T06:24:25.355 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T06:24:25.355 [RTP] [RTP] StartCommunication 0x00000186A78955D0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T06:24:25.355 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-20T06:24:25.355 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-20T06:24:25.667 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:24:25.699 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T06:24:25.699 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T06:24:25.699 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T06:24:25.761 [AutoPurge] Verification Routine tasks have started. 2026-04-20T06:24:25.761 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T06:24:25.949 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-20T06:24:25.949 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-20T06:24:25.964 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-20T06:24:25.980 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-20T06:24:25.980 [AutoPurge] Verification Routine tasks have ended. 2026-04-20T06:24:28.246 [RTP] Duplicating the current plugin configuration object... 2026-04-20T06:24:28.246 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T06:24:28.246 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-20T06:24:28.246 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T06:24:28.246 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-20T06:25:18.792 Process scan (poststartupscan) started. 2026-04-20T06:25:18.792 Process scan (poststartupscan) completed. 2026-04-20T06:25:19.308 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-20T06:25:19.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-20T06:25:19.324 [RTP] Duplicating the current plugin configuration object... 2026-04-20T06:25:19.324 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T06:25:19.324 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-20T06:25:19.324 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T06:25:19.324 [RTP] No config change detected. Not updating plugin configuration. 2026-04-20T06:25:19.324 [RTP] No config changes found. No configuration switch. 2026-04-20T06:25:19.324 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-20T06:25:19.324 [RTP] Duplicating the current plugin configuration object... 2026-04-20T06:25:19.324 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T06:25:19.324 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-04-20T06:25:19.324 [RTP] No config change detected. Not updating plugin configuration. 2026-04-20T06:25:19.324 [RTP] No config changes found. No configuration switch. 2026-04-20T06:25:19.324 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-20T06:25:19.324 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-20T06:25:19.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:25:19.324 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T06:25:19.324 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T06:25:19.324 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T06:25:19.324 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T06:25:19.324 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-20T06:25:19.324 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-20T06:25:19.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:25:19.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:25:19.339 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:25:21.902 [RTP] Duplicating the current plugin configuration object... 2026-04-20T06:25:21.902 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T06:25:21.902 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-04-20T06:25:21.902 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T06:25:21.902 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-04-20T06:26:18.246 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:26:18.261 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T06:26:18.261 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:26:38.167 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\E630E160-A8A0-4C8B-BB72-A017612011E21a98.1dcd08ea3b4d6b6 2026-04-20T06:26:38.246 Verifying engine and signature files (source: 0) ... 2026-04-20T06:26:38.246 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpengine.dll] due to PPL. 2026-04-20T06:26:38.246 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasbase.vdm] (file in cache) 2026-04-20T06:26:38.261 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-20T06:26:38.261 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasdlta.vdm] 2026-04-20T06:26:38.261 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpavbase.vdm] (file in cache) 2026-04-20T06:26:38.261 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-20T06:26:38.277 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpavdlta.vdm] 2026-04-20T06:26:38.433 [Engine] IsHybridMode: 0 2026-04-20T06:26:38.449 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T06:26:38.449 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7C922533FCABE9BD746228F84119D63945842E28.bin): 0x00000002 2026-04-20T06:26:38.449 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7C922533FCABE9BD746228F84119D63945842E28.bin) 2026-04-20T06:26:38.449 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-20T06:26:38.449 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-20T06:26:38.449 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-20T06:26:38.449 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T06:26:50.511 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T06:26:50.511 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T06:26:50.511 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB6A2B8020, lRefCount: 5, hr=0 2026-04-20T06:26:50.511 [Engine] New active engine 00007FFB63EF8020 replacing engine 00007FFB6A2B8020. Number of active engines: 2 2026-04-20T06:26:50.511 EngineInit:Global ASOC is enabled 2026-04-20T06:26:50.511 EngineInit:ASOO is enabled for developer volumes 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.574 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T06:26:50.589 MpWriteUupSignatureVersion 1.449.199.0, hr = 0 2026-04-20T06:26:50.589 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T06:26:50.605 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T06:26:50.605 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T06:26:50.605 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T06:26:50.605 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T06:26:50.605 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T06:26:50.621 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T06:26:50.621 [Plugin] Initializing RTP plugin state... 2026-04-20T06:26:50.621 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T06:26:50.621 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎20‎-‎2026 08:24:25 Last Perf:‎04‎-‎20‎-‎2026 08:24:25 First RTP Scan:‎04‎-‎20‎-‎2026 08:24:25 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:438 Misses:595 BM Queue:0,11,0 Proc:0,11,0 File:0,7,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:1060 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2112524 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2649 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13959 TotalHits:2515 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2880 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (99/24) Success: 24, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T06:26:50.621 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D} 2026-04-20T06:26:50.621 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{66E78A81-F613-427B-86C5-71C788AA9146} removed 2026-04-20T06:26:50.621 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA}\mpasbase.vdm in use, hr=0x80070020 2026-04-20T06:26:50.621 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T06:26:50.621 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.621 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.621 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.621 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.621 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-20-2026 06:26:50 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 06:26:50 2026-04-20T06:26:50.621 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T06:26:50.621 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T06:26:50.621 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T06:26:50.621 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T06:26:50.621 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T06:26:50.636 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.636 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.636 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.636 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T06:26:50.636 MdCoreSvc is supported in this platform and OS Signature updated on 04-20-2026 06:26:50 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.199.0 AV Signature Version: 1.449.199.0 ************************************************************ 2026-04-20T06:26:50.636 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-20T06:26:50.636 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\E630E160-A8A0-4C8B-BB72-A017612011E21a98.1dcd08ea3b4d6b6 2026-04-20T06:26:50.714 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T06:26:50.714 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T06:26:51.011 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T06:26:51.011 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T06:26:51.011 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T06:26:51.011 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T06:26:51.011 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T06:26:51.011 [Engine] Engine 00007FFB6A2B8020 no longer in use. Number of active engines: 1 2026-04-20T06:26:51.011 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T06:26:51.011 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-20T06:26:51.089 ProcessImageName: WmiPrvSE.exe, Pid: 4232, TotalTime: 375, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf->(UTF-16LE), EstimatedImpact: 18% 2026-04-20T06:26:51.089 ProcessImageName: brynhildr.exe, Pid: 3392, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-20T06:26:51.121 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T06:26:51.121 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T06:26:51.121 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T06:26:51.121 [Engine] RSIG_UNLOADENGINE, 00007FFB6A2B8020, err=0x0 2026-04-20T06:26:51.136 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F6A5A435-7D54-4DC4-8826-F47785DE9DBA} removed 2026-04-20T06:26:52.636 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:26:52.636 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T06:26:52.636 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:29:25.246 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T06:30:53.416 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-20T06:30:53.447 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-04-20T06:30:53.447 [RTP] Duplicating the current plugin configuration object... 2026-04-20T06:30:53.447 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T06:30:53.447 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-20T06:30:53.447 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-20T06:30:53.447 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-20T06:30:54.713 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-20T06:31:17.444 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4380, FileId: 0x16000000013653, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:31:50.565 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T06:32:19.252 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #6049, FileId: 0x6000000000644c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.268 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6483, FileId: 0x44000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.377 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6489, FileId: 0xb9000000006619, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.377 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6490, FileId: 0x49000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.377 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6487, FileId: 0x46000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.377 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6488, FileId: 0xb8000000006619, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.690 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6511, FileId: 0xc5000000006619, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.690 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6510, FileId: 0x5a000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:33:18.706 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0a493d96-b97d-4a2b-ba51-c4afd45ab091. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6513, FileId: 0x35000000007cab, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:34:25.252 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-20T06:34:25.252 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-20T06:34:25.268 Job Notification: New process added to job (10228) 2026-04-20T06:34:25.268 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-20T06:34:25.284 Job Notification: New process added to job (8596) 2026-04-20T06:34:25.299 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:10228] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8596]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T06:34:25.346 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 63129927(ms) from now at 02:06 (00:06 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-20T06:34:25.377 Job Notification: New process added to job (11176) 2026-04-20T06:34:25.393 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-20T06:34:25.393 Job Notification: New process added to job (10948) 2026-04-20T06:34:25.393 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11176] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10948]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T06:34:42.534 Job Notification: Process exited from job (11176) 2026-04-20T06:34:42.534 Job Notification: Process exited from job (10948) 2026-04-20T06:34:42.612 Job Notification: Process exited from job (10228) 2026-04-20T06:34:42.612 Job Notification: Process exited from job (8596) 2026-04-20T06:35:18.799 Process scan (postsignatureupdatescan) started. 2026-04-20T06:35:38.331 Process scan (postsignatureupdatescan) completed. 2026-04-20T06:35:47.471 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6954, FileId: 0x6600000000761f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:37:17.831 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2735.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #6974, FileId: 0xb0000000006049, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:08.612 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpED85.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #6985, FileId: 0xb2000000006049, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:16.440 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7880, FileId: 0xc10000000066cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:16.502 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:C18E0937-7A2D-4469-9DDB-028ABD564B07, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-20T06:38:16.502 Scheduled scan with Id C18E0937-7A2D-4469-9DDB-028ABD564B07 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-20T06:38:16.502 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-20T06:38:16.502 [SFC] System file cache build is not needed (already completed) 2026-04-20T06:38:16.518 [AutoPurge] Cleanup Routine tasks have started. 2026-04-20T06:38:16.534 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-20T06:38:16.534 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-20T06:38:16.534 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-20-2026 06:38:16 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 06:38:16 2026-04-20T06:38:16.565 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-20T06:38:16.565 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-20T06:38:16.565 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-20T06:38:16.565 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-20T06:38:16.565 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-20T06:38:16.643 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-20T06:38:16.643 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-20T06:38:16.643 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-20T06:38:16.643 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-20T06:38:16.643 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-20T06:38:16.721 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-04-20T06:38:16.831 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-04-20T06:38:16.862 Engine:Setting original file name "System.Printing" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\system.printing.dll", hr=0x800710da 2026-04-20T06:38:17.002 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-04-20T06:38:17.096 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:17.627 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-04-20T06:38:18.127 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-04-20T06:38:18.159 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-04-20T06:38:18.284 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-04-20T06:38:18.315 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-04-20T06:38:18.502 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:38:18.518 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T06:38:18.518 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:38:18.877 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-04-20T06:38:19.065 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-20T06:38:19.096 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-04-20T06:38:19.440 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-04-20T06:38:19.502 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-04-20T06:38:19.627 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-04-20T06:38:19.909 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-04-20T06:38:20.268 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-04-20T06:38:20.581 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-04-20T06:38:20.831 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-20T06:38:20.846 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:20.877 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-04-20T06:38:21.065 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-04-20T06:38:21.159 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-04-20T06:38:21.534 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-04-20T06:38:21.799 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-04-20T06:38:21.846 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-04-20T06:38:22.221 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-04-20T06:38:22.268 Engine:Setting original file name "vcamp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-20T06:38:22.440 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-04-20T06:38:23.096 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:23.127 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-20T06:38:23.206 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:23.440 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-20T06:38:23.565 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-20T06:38:23.721 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-04-20T06:38:23.971 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-04-20T06:38:24.081 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-04-20T06:38:24.096 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-04-20T06:38:24.127 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-20T06:38:24.362 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-04-20T06:38:24.440 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-20T06:38:24.596 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-04-20T06:38:24.768 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-04-20T06:38:25.331 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-04-20T06:38:25.346 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2EF5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8178, FileId: 0x4900000000831c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:25.346 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-04-20T06:38:25.612 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-20T06:38:25.690 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-04-20T06:38:26.237 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-04-20T06:38:26.284 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-04-20T06:38:26.299 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-04-20T06:38:26.299 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-04-20T06:38:26.362 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-04-20T06:38:26.424 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-04-20T06:38:26.549 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-04-20T06:38:26.862 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-04-20T06:38:26.987 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-04-20T06:38:27.081 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-04-20T06:38:27.112 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:27.127 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-04-20T06:38:27.174 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-04-20T06:38:27.502 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-20T06:38:27.565 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-04-20T06:38:27.596 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-04-20T06:38:27.612 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-04-20T06:38:27.862 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-04-20T06:38:28.034 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-20T06:38:28.049 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-04-20T06:38:28.299 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-20T06:38:28.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-04-20T06:38:28.846 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-04-20T06:38:28.846 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-04-20T06:38:28.909 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-20T06:38:29.331 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-04-20T06:38:29.346 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-04-20T06:38:29.737 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-04-20T06:38:29.815 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-04-20T06:38:29.815 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-04-20T06:38:29.893 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-04-20T06:38:29.909 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-20T06:38:29.956 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-04-20T06:38:30.362 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-04-20T06:38:30.409 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-20T06:38:30.518 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-04-20T06:38:30.549 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-04-20T06:38:30.846 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-04-20T06:38:30.987 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-04-20T06:38:31.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-04-20T06:38:31.096 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-04-20T06:38:31.237 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-04-20T06:38:31.518 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:31.893 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-04-20T06:38:31.940 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-04-20T06:38:31.956 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:32.018 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:32.706 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:32.799 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:33.143 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-04-20T06:38:33.190 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-04-20T06:38:33.331 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-04-20T06:38:33.424 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-04-20T06:38:33.471 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-04-20T06:38:33.487 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-04-20T06:38:33.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-04-20T06:38:33.940 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-04-20T06:38:34.018 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-04-20T06:38:34.112 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-04-20T06:38:34.143 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-04-20T06:38:34.268 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-04-20T06:38:34.424 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-04-20T06:38:34.596 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-04-20T06:38:34.674 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-04-20T06:38:34.706 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-04-20T06:38:34.706 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-04-20T06:38:34.956 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-04-20T06:38:34.956 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-04-20T06:38:35.127 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-04-20T06:38:35.674 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-04-20T06:38:35.893 Engine:Setting original file name "accbdc.dll" for "c:\program files\microsoft office\root\vfs\windows\assembly\gac_64\microsoft.office.access.businessdatacatalog\16.0.0.0__71e9bce111e9429c\microsoft.office.access.businessdatacatalog.dll", hr=0x800710da 2026-04-20T06:38:35.909 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-04-20T06:38:35.971 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-04-20T06:38:36.440 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-04-20T06:38:36.502 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-04-20T06:38:36.581 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-04-20T06:38:36.659 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-04-20T06:38:36.768 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-20T06:38:36.768 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-20T06:38:37.143 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.22000.653_none_8587430a3a996be3\schtasks.exe", hr=0x800710da 2026-04-20T06:38:37.268 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-20T06:38:37.346 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-04-20T06:38:37.362 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-04-20T06:38:37.659 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-04-20T06:38:37.784 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-04-20T06:38:37.877 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-20T06:38:38.112 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-04-20T06:38:38.221 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-20T06:38:38.362 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-04-20T06:38:38.768 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-04-20T06:38:38.846 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-04-20T06:38:38.877 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-04-20T06:38:39.018 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-04-20T06:38:39.034 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-20T06:38:39.159 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-04-20T06:38:39.206 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-04-20T06:38:39.377 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-04-20T06:38:39.502 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-04-20T06:38:39.502 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:39.799 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-04-20T06:38:40.081 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-04-20T06:38:40.112 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-04-20T06:38:40.159 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-20T06:38:40.331 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-04-20T06:38:40.596 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-04-20T06:38:40.659 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:40.690 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-04-20T06:38:40.815 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:41.299 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-04-20T06:38:41.424 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-04-20T06:38:41.518 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-04-20T06:38:41.909 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-04-20T06:38:41.940 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-04-20T06:38:41.940 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-04-20T06:38:42.206 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-04-20T06:38:42.440 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-04-20T06:38:42.471 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-04-20T06:38:42.612 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-04-20T06:38:42.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-04-20T06:38:42.768 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-04-20T06:38:42.971 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-04-20T06:38:43.331 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-04-20T06:38:43.346 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-04-20T06:38:43.440 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-20T06:38:43.831 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-04-20T06:38:43.893 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-04-20T06:38:43.893 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-04-20T06:38:44.096 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-04-20T06:38:44.565 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-04-20T06:38:44.690 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-04-20T06:38:44.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-04-20T06:38:44.784 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-04-20T06:38:44.877 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7B42.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8282, FileId: 0x1870000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:44.940 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-04-20T06:38:45.018 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-04-20T06:38:45.081 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-20T06:38:45.190 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:38:45.315 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-04-20T06:38:45.487 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-04-20T06:38:45.596 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-20T06:38:45.815 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-04-20T06:38:46.049 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-04-20T06:38:46.065 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-04-20T06:38:46.159 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-04-20T06:38:46.862 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-04-20T06:38:47.252 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-04-20T06:38:47.268 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-20T06:38:47.346 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-04-20T06:38:47.565 Engine:Setting original file name "MSPPT12.OLB" for "c:\program files\microsoft office\root\office16\msppt.olb", hr=0x800710da 2026-04-20T06:38:47.581 Engine:Setting original file name "Microsoft Office Policy Tips" for "c:\program files\microsoft office\root\office16\microsoft.office.policytips.dll", hr=0x800710da 2026-04-20T06:38:47.956 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-04-20T06:38:48.331 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-04-20T06:38:48.393 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-04-20T06:38:48.581 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-04-20T06:38:48.815 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-04-20T06:38:48.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-04-20T06:38:49.174 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-04-20T06:38:49.252 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-04-20T06:38:49.315 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-04-20T06:38:49.346 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-04-20T06:38:49.471 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-04-20T06:38:49.893 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-04-20T06:38:49.971 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-04-20T06:38:50.237 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-04-20T06:38:50.268 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-04-20T06:38:50.956 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-20T06:38:51.049 Engine:Setting original file name "libcrypto" for "c:\program files\microsoft onedrive\26.055.0323.0004\libcrypto-3-x64.dll", hr=0x800710da 2026-04-20T06:38:51.315 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-04-20T06:38:51.471 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-04-20T06:38:51.690 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-04-20T06:38:51.768 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:51.815 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-04-20T06:38:51.815 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:51.877 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-04-20T06:38:51.987 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-04-20T06:38:52.034 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-04-20T06:38:52.096 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-04-20T06:38:52.190 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-04-20T06:38:52.206 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-04-20T06:38:52.206 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-04-20T06:38:52.252 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-04-20T06:38:52.268 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-04-20T06:38:52.518 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-20T06:38:52.518 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-20T06:38:52.565 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-04-20T06:38:52.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-04-20T06:38:52.815 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-04-20T06:38:53.127 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-04-20T06:38:53.424 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-04-20T06:38:53.706 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-04-20T06:38:53.831 Engine:Setting original file name "VisioUtils.dll" for "c:\program files\microsoft office\root\office16\visutils.dll", hr=0x800710da 2026-04-20T06:38:53.909 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-04-20T06:38:53.940 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php91E9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8292, FileId: 0x1890000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:53.987 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-04-20T06:38:54.206 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-04-20T06:38:54.346 Engine:Setting original file name "msvcp140_atomic_wait_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_atomic_wait_app.dll", hr=0x800710da 2026-04-20T06:38:54.565 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-04-20T06:38:54.768 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-04-20T06:38:54.877 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-04-20T06:38:55.127 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-04-20T06:38:55.221 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-04-20T06:38:55.299 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-04-20T06:38:55.346 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-04-20T06:38:55.362 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-04-20T06:38:55.377 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-04-20T06:38:55.440 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-04-20T06:38:55.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-04-20T06:38:55.768 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-04-20T06:38:55.956 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-04-20T06:38:56.268 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-20T06:38:56.362 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-04-20T06:38:56.971 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-04-20T06:38:56.987 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-20T06:38:57.284 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-04-20T06:38:57.346 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-04-20T06:38:57.409 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-04-20T06:38:57.706 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAD24.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8294, FileId: 0x18b0000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:38:57.877 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-20T06:38:58.159 Engine:Setting original file name "PRODUCT_NAME .DLL" for "c:\program files\microsoft office\root\vfs\system\fm20.dll", hr=0x800710da 2026-04-20T06:38:58.221 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-04-20T06:38:58.596 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-04-20T06:38:58.706 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-04-20T06:38:58.924 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-04-20T06:38:59.440 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-20T06:38:59.502 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-04-20T06:38:59.612 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-04-20T06:38:59.690 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-04-20T06:38:59.721 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-04-20T06:38:59.862 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-04-20T06:39:00.190 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-04-20T06:39:00.221 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-04-20T06:39:01.096 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-04-20T06:39:01.346 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-04-20T06:39:01.440 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:39:01.565 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-04-20T06:39:01.987 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-04-20T06:39:02.065 Engine:Setting original file name "PPINTL.DLL" for "c:\program files\microsoft office\root\office16\ppintl.common.dll", hr=0x800710da 2026-04-20T06:39:02.096 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-04-20T06:39:02.143 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-04-20T06:39:02.174 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-04-20T06:39:02.237 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-04-20T06:39:02.252 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:39:02.377 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-20T06:39:02.424 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-20T06:39:02.581 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-04-20T06:39:02.643 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-04-20T06:39:02.706 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-04-20T06:39:02.831 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-04-20T06:39:03.159 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-04-20T06:39:03.237 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-04-20T06:39:03.424 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-04-20T06:39:03.627 Engine:Triggered AR EMS scan 2026-04-20T06:39:03.627 Engine:EMS scan for process: lsass pid: 768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.643 Engine:EMS scan for process: svchost pid: 984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.659 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-04-20T06:39:03.659 Engine:EMS scan for process: svchost pid: 800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.674 Engine:EMS scan for process: svchost pid: 1056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.674 Engine:EMS scan for process: svchost pid: 1192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.674 Engine:EMS scan for process: svchost pid: 1200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.690 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.690 Engine:EMS scan for process: svchost pid: 1244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.690 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.706 Engine:EMS scan for process: svchost pid: 1360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.706 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.706 Engine:EMS scan for process: svchost pid: 1452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.706 Engine:EMS scan for process: svchost pid: 1480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.721 Engine:EMS scan for process: svchost pid: 1540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.721 Engine:EMS scan for process: svchost pid: 1576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.737 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.737 Engine:EMS scan for process: svchost pid: 1680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.737 Engine:EMS scan for process: svchost pid: 1728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.737 Engine:EMS scan for process: svchost pid: 1984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.752 Engine:EMS scan for process: svchost pid: 480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.752 Engine:EMS scan for process: svchost pid: 1776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.752 Engine:EMS scan for process: svchost pid: 2060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.752 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.768 Engine:EMS scan for process: svchost pid: 2272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.768 Engine:EMS scan for process: svchost pid: 2348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.768 Engine:EMS scan for process: svchost pid: 2408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.768 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.784 Engine:EMS scan for process: svchost pid: 2436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.784 Engine:EMS scan for process: svchost pid: 2620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.784 Engine:EMS scan for process: svchost pid: 2636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.784 Engine:EMS scan for process: svchost pid: 2676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.784 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.799 Engine:EMS scan for process: svchost pid: 2980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.799 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.815 Engine:EMS scan for process: svchost pid: 2596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.815 Engine:EMS scan for process: svchost pid: 2632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.815 Engine:EMS scan for process: svchost pid: 3504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.815 Engine:EMS scan for process: svchost pid: 3512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.831 Engine:EMS scan for process: svchost pid: 3576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.831 Engine:EMS scan for process: svchost pid: 3584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.846 Engine:EMS scan for process: svchost pid: 3796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.862 Engine:EMS scan for process: svchost pid: 3852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.862 Engine:EMS scan for process: svchost pid: 4052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.862 Engine:EMS scan for process: svchost pid: 3624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.862 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.877 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.877 Engine:EMS scan for process: svchost pid: 4336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.877 Engine:EMS scan for process: svchost pid: 4352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.893 Engine:EMS scan for process: svchost pid: 4388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.893 Engine:EMS scan for process: svchost pid: 4444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.893 Engine:EMS scan for process: svchost pid: 4564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.909 Engine:EMS scan for process: svchost pid: 2224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.909 Engine:EMS scan for process: svchost pid: 5532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.924 Engine:EMS scan for process: svchost pid: 5540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.924 Engine:EMS scan for process: svchost pid: 5948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.924 Engine:EMS scan for process: svchost pid: 6084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.924 Engine:EMS scan for process: dllhost pid: 6096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.940 Engine:EMS scan for process: svchost pid: 1228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.940 Engine:EMS scan for process: svchost pid: 6796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.940 Engine:EMS scan for process: svchost pid: 6928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.940 Engine:EMS scan for process: svchost pid: 860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.956 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.956 Engine:EMS scan for process: svchost pid: 7000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.956 Engine:EMS scan for process: svchost pid: 4632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.956 Engine:EMS scan for process: svchost pid: 2848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.971 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.971 Engine:EMS scan for process: svchost pid: 2488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:03.971 Engine:EMS scan for process: explorer pid: 4044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.034 Engine:EMS scan for process: svchost pid: 2032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.034 Engine:EMS scan for process: svchost pid: 3036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.034 Engine:EMS scan for process: svchost pid: 5900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.034 Engine:EMS scan for process: svchost pid: 8164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.049 Engine:EMS scan for process: dllhost pid: 8304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.049 Engine:EMS scan for process: svchost pid: 8612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.049 Engine:EMS scan for process: svchost pid: 12240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.049 Engine:EMS scan for process: svchost pid: 11612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.065 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-20T06:39:04.065 Engine:EMS scan for process: svchost pid: 10148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.065 Engine:EMS scan for process: svchost pid: 7456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.065 Engine:EMS scan for process: svchost pid: 7056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.081 Engine:EMS scan for process: svchost pid: 3472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.081 Engine:EMS scan for process: svchost pid: 10612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.081 Engine:EMS scan for process: svchost pid: 9480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-20T06:39:04.143 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-04-20T06:39:04.706 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-04-20T06:39:05.096 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-04-20T06:39:05.424 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-04-20T06:39:05.487 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-04-20T06:39:05.565 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-04-20T06:39:05.862 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-04-20T06:39:05.987 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-04-20T06:39:06.096 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-04-20T06:39:06.565 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-04-20T06:39:06.971 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-04-20T06:39:07.002 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-20T06:39:07.096 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-20T06:39:07.112 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-04-20T06:39:07.127 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-04-20T06:39:07.502 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-04-20T06:39:07.706 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-04-20T06:39:07.768 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-04-20T06:39:07.831 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-04-20T06:39:08.096 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-04-20T06:39:08.315 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-04-20T06:39:08.393 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-20T06:39:08.440 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-04-20T06:39:08.471 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-04-20T06:39:08.596 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-04-20T06:39:08.877 Engine:Setting original file name "ExcelUnitUDF.dll" for "c:\users\ithan\appdata\local\amsterchem\excel cape-open unit operation\excelunitudf64.dll", hr=0x800710da 2026-04-20T06:39:09.143 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-04-20T06:39:09.377 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-04-20T06:39:09.393 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-04-20T06:39:09.440 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-04-20T06:39:09.565 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-20T06:39:09.659 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-04-20T06:39:09.768 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-04-20T06:39:09.893 Engine:Setting original file name "Gantt Chart.DLL" for "c:\program files\microsoft office\root\office16\gantt.dll", hr=0x800710da 2026-04-20T06:39:10.096 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDDBB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8433, FileId: 0xf3000000001288, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:39:10.190 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-04-20T06:39:10.206 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-04-20T06:39:10.206 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-04-20T06:39:10.487 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-04-20T06:39:10.596 Engine:Setting original file name "ProjectModel.dll" for "c:\program files\microsoft office\root\office16\projmodl.dll", hr=0x800710da 2026-04-20T06:39:10.659 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-04-20T06:39:10.768 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-04-20T06:39:10.987 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-04-20T06:39:11.049 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-20T06:39:11.096 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-20T06:39:11.127 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-04-20T06:39:11.424 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-04-20T06:39:11.502 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-04-20T06:39:11.534 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-04-20T06:39:11.596 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-04-20T06:39:12.471 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-04-20T06:39:12.659 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-04-20T06:39:12.706 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-04-20T06:39:12.909 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-04-20T06:39:12.956 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-04-20T06:39:13.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-04-20T06:39:13.112 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-04-20T06:39:13.174 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-04-20T06:39:13.206 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-04-20T06:39:13.221 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-04-20T06:39:13.299 OriginalFileName Maintenance::10638 files in Moac, 267 skipped (cached), 1 filename set 2026-04-20T06:39:13.299 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-20T06:39:32.596 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php35A1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8441, FileId: 0x13a0000000014b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:39:36.706 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php45C0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8443, FileId: 0x18e0000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:39:41.081 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php56D9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8445, FileId: 0x1900000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:39:50.706 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7C74.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8447, FileId: 0x1920000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:40:19.799 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEDFD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8449, FileId: 0x1940000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:40:25.221 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php34C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8451, FileId: 0x1960000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:40:27.596 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC95.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8453, FileId: 0x1980000000008a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:40:29.237 RPC Rundown called on ScanID: C18E0937-7A2D-4469-9DDB-028ABD564B07 2026-04-20T06:40:29.237 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:C18E0937-7A2D-4469-9DDB-028ABD564B07. bRemoveFromList(ClientKilled):1 2026-04-20T06:40:29.237 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:C18E0937-7A2D-4469-9DDB-028ABD564B07 2026-04-20T06:40:29.237 QuickScan:ScanID:C18E0937-7A2D-4469-9DDB-028ABD564B07: User scan error=000003e3 2026-04-20T06:40:29.252 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:C18E0937-7A2D-4469-9DDB-028ABD564B07 2026-04-20T06:40:29.252 QuickScan:ScanID:C18E0937-7A2D-4469-9DDB-028ABD564B07: Quick scan aborted by callback after end stage 2026-04-20T06:40:29.252 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:C18E0937-7A2D-4469-9DDB-028ABD564B07 2026-04-20T06:40:29.252 OnDemandScanWorker: Scan Cancelled! scanId:C18E0937-7A2D-4469-9DDB-028ABD564B07, hr = 0x80508018 2026-04-20T06:40:31.268 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:40:31.268 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T06:40:31.268 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:40:34.315 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php26C6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8460, FileId: 0x13c0000000014b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:40:40.831 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php403C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8493, FileId: 0x13e0000000014b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:05.534 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8B2C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8618, FileId: 0x74000000004442, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:10.518 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9EA7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8620, FileId: 0x76000000004442, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:20.784 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC6B3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8622, FileId: 0x78000000004442, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.049 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB51FD69DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8947, FileId: 0x770000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.049 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8D4EA958. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8948, FileId: 0x780000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.065 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2922CC97D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8950, FileId: 0x790000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.148 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA90D519D1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8957, FileId: 0x11b00000000992c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.192 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF08CE196D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8963, FileId: 0x7c0000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.254 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2D385A9A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8966, FileId: 0x440000000095f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.301 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0C7B609D3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8967, FileId: 0x7f0000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.332 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6985D191D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8969, FileId: 0x800000000097cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:47.379 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj329625934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8971, FileId: 0xa500000000994a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:42:48.056 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFFB7549D6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8983, FileId: 0xa900000000994a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:43:01.619 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9122, FileId: 0xe50000000041ab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:43:01.697 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9124, FileId: 0x93000000008963, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:43:01.838 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9130, FileId: 0x1b0000000091fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:44:03.238 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9153, FileId: 0xeb0000000041ab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:44:30.253 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T06:45:49.624 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #9215, FileId: 0xff000000004b34, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:53:01.953 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9442, FileId: 0x20400000000aa06, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:53:01.968 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9444, FileId: 0x4e00000000f346, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:35.988 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:7E11E2E0-AD1D-458D-902F-E1B84CB7C0E6, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-20T06:54:35.988 Scheduled scan with Id 7E11E2E0-AD1D-458D-902F-E1B84CB7C0E6 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-20T06:54:35.994 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-20T06:54:35.994 [SFC] System file cache build is not needed (already completed) 2026-04-20T06:54:37.263 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9507, FileId: 0x11d00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:38.014 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:54:38.023 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T06:54:38.023 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T06:54:39.983 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9541, FileId: 0x6d000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.988 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9542, FileId: 0x5d000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.988 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9539, FileId: 0x6c000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.993 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9544, FileId: 0x6e000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.993 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9540, FileId: 0x5c000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.998 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9546, FileId: 0x6f000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.998 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9547, FileId: 0x5f000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:39.998 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9548, FileId: 0x70000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.003 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9545, FileId: 0x5e000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.004 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9551, FileId: 0x61000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.004 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9550, FileId: 0x71000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.004 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9553, FileId: 0x62000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.024 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9552, FileId: 0x72000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.024 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9556, FileId: 0x74000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.024 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9558, FileId: 0x75000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.029 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9559, FileId: 0x76000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.029 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9554, FileId: 0x73000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.033 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9557, FileId: 0x65000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.043 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9563, FileId: 0x78000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.048 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9560, FileId: 0x66000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.465 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\23b079b3-c7a0-4b0f-b8d7-75bfe3816c58. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #9597, FileId: 0x4d100000000fcc5, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T06:54:40.465 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9595, FileId: 0x6a000000006549, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-20-2026 07:45:11 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/20/2026 07:45:11.279560300 UTC (14000 ms since boot) 2026-04-20T07:45:11.299 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-20T07:45:11.304 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T07:45:11.307 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T07:45:11.354 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260420-074511-00000003-fffffffeffffffff.bin ... 2026-04-20T07:45:11.489 [WPP] Trace session started - MpWppTracing-20260420-074511-00000003-fffffffeffffffff.bin 2026-04-20T07:45:11.494 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-20T07:45:11.494 [RbM] Rollback manager succesfully initialized. 2026-04-20T07:45:11.494 [RbM] Rollback manager EnableRollbackManager called. 2026-04-20T07:45:11.504 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-20T07:45:11.504 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-20T07:45:11.504 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-20T07:45:11.504 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-20T07:45:11.504 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-20T07:45:11.509 MdCoreSvc is supported in this platform and OS 2026-04-20T07:45:11.509 MdCoreSvc is supported in this platform and OS 2026-04-20T07:45:11.509 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T07:45:11.509 [PlatUpd] Starting MdCoreSvc service 2026-04-20T07:45:11.545 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-20T07:45:16.766 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-20T07:45:16.766 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-20T07:45:16.766 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-20T07:45:16.766 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-20T07:45:16.766 [PlatUpd] CSP platform update started 2026-04-20T07:45:16.766 [PlatUpd] Defender MDM CSP platform update not required 2026-04-20T07:45:16.766 [PlatUpd] WMI/PS provider platform update started 2026-04-20T07:45:16.766 [PlatUpd] WMI/PS provider platform update not required 2026-04-20T07:45:16.766 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-20T07:45:16.766 MdCoreSvc is supported in this platform and OS 2026-04-20T07:45:16.766 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T07:45:16.766 [PlatUpd] Starting MdCoreSvc service 2026-04-20T07:45:16.766 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-20T07:45:16.766 [TS] Troublshooting mode is not available! 2026-04-20T07:45:16.766 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T07:45:16.766 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-20T07:45:16.797 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-20T07:45:16.797 [Service] Enabling AutoLoggers ... 2026-04-20T07:45:16.797 [Service] Enabling AMSI registration ... 2026-04-20T07:45:16.797 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-20T07:45:16.813 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52176 Number of invalid entries is 0 Number of inserts issued is 1572784 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6363 Number of lookups is 106787281 Number of lookup misses is 5117189 Number of fast lookup misses is 54518999 Number of false fast lookups is 5117184 Number of invalidations is 728910 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-20T07:45:16.813 Verifying license file... 2026-04-20T07:45:16.813 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-20T07:45:16.844 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-20T07:45:16.844 Loaded module#0 MpComServer. 2026-04-20T07:45:16.844 Loaded module#1 StartupPolicies. 2026-04-20T07:45:16.844 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T07:45:16.844 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T07:45:16.844 COM server initialized successfully. 2026-04-20T07:45:16.860 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-20T07:45:16.860 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-20T07:45:16.860 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-20T07:45:16.891 [RTP] [RTP] FilterCommunicator object 0x000001E16F40D100 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T07:45:16.891 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-20T07:45:16.891 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T07:45:16.891 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T07:45:16.891 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-20T07:45:16.891 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-20T07:45:16.891 [RTP] [RTP] FilterCommunicator object 0x000001E16F40D310 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T07:45:16.891 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-20T07:45:16.891 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-20T07:45:16.891 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-20T07:45:16.891 [RTP] [RTP] StartCommunication 0x000001E16F40D100 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T07:45:16.891 [init][RTP] RTPPlugin initialization completed 2026-04-20T07:45:16.891 OS boot count = 2 2026-04-20T07:45:16.891 OS Install = 0 2026-04-20T07:45:16.954 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-20T07:45:16.954 [KSL] Entering CKSLEngine::Initialize. 2026-04-20T07:45:16.954 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-20T07:45:16.954 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-20T07:45:16.954 [KSL] MpInstallKslD: hr=0x1 2026-04-20T07:45:16.954 [KSL] MpRegisterKslD: hr=0 2026-04-20T07:45:16.969 [KSL] MpStartKslD: hr=0 2026-04-20T07:45:16.969 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T07:45:16.969 Loading engine... 2026-04-20T07:45:17.000 Verifying engine and signature files (source: 1) ... 2026-04-20T07:45:17.000 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpengine.dll] due to PPL. 2026-04-20T07:45:17.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasbase.vdm] (file in cache) 2026-04-20T07:45:17.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasdlta.vdm] (file in cache) 2026-04-20T07:45:17.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpavbase.vdm] (file in cache) 2026-04-20T07:45:17.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpavdlta.vdm] (file in cache) 2026-04-20T07:45:17.047 [Engine] IsHybridMode: 0 2026-04-20T07:45:17.063 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T07:45:17.094 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7C922533FCABE9BD746228F84119D63945842E28.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T07:45:31.646 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T07:45:31.661 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T07:45:31.661 [Engine] New active engine 00007FFFF3AC8020 (no old engine). Number of active engines: 1 2026-04-20T07:45:31.677 EngineInit:Global ASOC is enabled 2026-04-20T07:45:31.677 EngineInit:ASOO is enabled for developer volumes 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.786 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:45:31.818 MpWriteUupSignatureVersion 1.449.199.0, hr = 0 2026-04-20T07:45:31.833 [SigStatUpd] CSignatureStatus: back to good 2026-04-20T07:45:31.833 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T07:45:31.849 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T07:45:31.849 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T07:45:31.849 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T07:45:31.849 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T07:45:31.849 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T07:45:31.880 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T07:45:31.880 [Plugin] Initializing RTP plugin state... 2026-04-20T07:45:31.880 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3690 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18483 TotalHits:0 InstanceCacheInserts:30 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3851 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T07:45:31.880 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T07:45:31.880 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D} 2026-04-20T07:45:31.880 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:45:31.880 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:45:31.880 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:45:31.880 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T07:45:31.880 MdCoreSvc is supported in this platform and OS 2026-04-20T07:45:31.880 Engine loaded! 2026-04-20T07:45:31.880 [DLP] Create FeatureControlState instance 2026-04-20T07:45:31.896 RegisterSModeChangeListener: hr = 0x1 2026-04-20T07:45:31.896 RegisterHybridModeChangeListener: hr = 0 2026-04-20T07:45:31.896 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-20T07:45:31.896 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-20T07:45:31.910 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-20T07:45:31.910 [SigReleaseHb] Initialized with Stage 0 2026-04-20T07:45:31.911 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-20T07:45:31.912 [SCC][CID=34625_5356] Initializing ... 2026-04-20T07:45:31.913 [SCC][CID=34625_5356] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-20T07:45:31.916 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T07:45:31.916 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T07:45:31.918 [NRI] Stopping NIS service ... 2026-04-20T07:45:31.919 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-20T07:45:31.919 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.199.0 AV Signature Version: 1.449.199.0 ************************************************************ 2026-04-20T07:45:31.920 Resource usage Monitoring is enabled 2026-04-20T07:45:31.921 Job Notification: New process added to job (4392) 2026-04-20T07:45:31.922 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-20T07:45:31.933 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T07:45:31.970 Job Notification: New process added to job (10752) 2026-04-20T07:45:31.970 Job Notification: New process added to job (10740) 2026-04-20T07:45:31.986 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:10752] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10740]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T07:45:32.033 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T07:45:32.033 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T07:45:32.033 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T07:45:32.033 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T07:45:32.033 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T07:45:32.033 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T07:45:32.033 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T07:45:32.033 [RTP] Generating the base plugin configuration ... 2026-04-20T07:45:32.033 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-20T07:45:32.033 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T07:45:32.033 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-20T07:45:32.048 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-20T07:45:32.048 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T07:45:32.048 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T07:45:32.048 [RTP] [RTP] StartCommunication 0x000001E16F40D310 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T07:45:32.048 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-20T07:45:32.064 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-20T07:45:32.111 Job Notification: Process exited from job (10752) 2026-04-20T07:45:32.111 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-20T07:45:32.111 Job Notification: Process exited from job (10740) 2026-04-20T07:45:32.345 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T07:45:32.345 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T07:45:32.345 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T07:45:32.392 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T07:45:35.054 [RTP] Duplicating the current plugin configuration object... 2026-04-20T07:45:35.054 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T07:45:35.054 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-20T07:45:35.054 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T07:45:35.054 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-20T07:45:45.119 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #914, FileId: 0x58000000004079, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:45:46.349 Bm signature throttled:0x00002db31bed458f 2026-04-20T07:45:59.329 Bm signature throttled:0x00002db31bed458f 2026-04-20T07:46:16.836 Process scan (poststartupscan) started. 2026-04-20T07:46:16.836 Process scan (poststartupscan) completed. 2026-04-20T07:46:17.336 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-20T07:46:17.351 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-20T07:46:19.929 [RTP] Duplicating the current plugin configuration object... 2026-04-20T07:46:19.929 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T07:46:19.929 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-20T07:46:19.929 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T07:46:19.929 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-20T07:46:34.654 [RTP] [Mini-filter] Denied registry key creation of [\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications] triggered by process [\Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe]. 2026-04-20T07:46:34.654 [RTP] [Mini-filter] Denied registry key creation of [\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Defender] triggered by process [\Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe]. 2026-04-20T07:46:34.700 [RTP] [Mini-filter] Denied registry key creation of [\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications] triggered by process [\Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe]. 2026-04-20T07:46:34.700 [RTP] [Mini-filter] Denied registry key creation of [\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Defender] triggered by process [\Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe]. 2026-04-20T07:47:13.696 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T07:47:13.696 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T07:47:13.712 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T07:48:11.015 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4060, FileId: 0xe00000000185f0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:50:13.618 Bm signature throttled:0x00002db31bed458f 2026-04-20T07:50:16.669 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4151, FileId: 0x5300000001860e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:50:31.704 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T07:50:31.923 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T07:52:22.145 Bm signature throttled:0x00002db31bed458f 2026-04-20T07:55:31.910 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-20T07:55:31.930 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-20T07:55:31.946 Job Notification: New process added to job (3164) 2026-04-20T07:55:31.962 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-20T07:55:31.962 Job Notification: New process added to job (2148) 2026-04-20T07:55:31.977 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:3164] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2148]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T07:55:32.024 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 61509681(ms) from now at 03:00 (01:00 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-20T07:55:32.071 Job Notification: New process added to job (980) 2026-04-20T07:55:32.071 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-20T07:55:32.071 Job Notification: New process added to job (1752) 2026-04-20T07:55:32.087 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:980] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:1752]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T07:55:43.607 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\FC3318C9-8FF8-4DF8-A8B0-4DA6BD2DC7CB6ec.1dcd09b15d2ce4b 2026-04-20T07:55:43.779 Verifying engine and signature files (source: 0) ... 2026-04-20T07:55:43.779 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpengine.dll] due to PPL. 2026-04-20T07:55:43.779 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasbase.vdm] (file in cache) 2026-04-20T07:55:43.779 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-20T07:55:43.794 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasdlta.vdm] 2026-04-20T07:55:43.794 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpavbase.vdm] (file in cache) 2026-04-20T07:55:43.794 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-20T07:55:43.810 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpavdlta.vdm] 2026-04-20T07:55:43.966 [Engine] IsHybridMode: 0 2026-04-20T07:55:43.966 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T07:55:43.982 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DB145F40C26D0BE5E22A4ADC5941F2900B658FB3.bin): 0x00000002 2026-04-20T07:55:43.982 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DB145F40C26D0BE5E22A4ADC5941F2900B658FB3.bin) 2026-04-20T07:55:43.982 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-20T07:55:43.982 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-20T07:55:43.982 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-20T07:55:43.982 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T07:55:56.243 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T07:55:56.243 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T07:55:56.243 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFFF3AC8020, lRefCount: 5, hr=0 2026-04-20T07:55:56.243 [Engine] New active engine 00007FFF9B978020 replacing engine 00007FFFF3AC8020. Number of active engines: 2 2026-04-20T07:55:56.258 EngineInit:Global ASOC is enabled 2026-04-20T07:55:56.258 EngineInit:ASOO is enabled for developer volumes 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T07:55:56.321 MpWriteUupSignatureVersion 1.449.201.0, hr = 0 2026-04-20T07:55:56.321 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T07:55:56.337 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T07:55:56.352 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T07:55:56.352 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T07:55:56.352 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T07:55:56.352 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T07:55:56.368 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T07:55:56.368 [Plugin] Initializing RTP plugin state... 2026-04-20T07:55:56.368 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T07:55:56.368 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎20‎-‎2026 09:45:32 Last Perf:‎04‎-‎20‎-‎2026 09:45:31 First RTP Scan:‎04‎-‎20‎-‎2026 09:45:32 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1855 Misses:2524 BM Queue:0,441,0 Proc:0,239,0 File:0,202,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:4843 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:21159662 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6270 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:80815 TotalHits:15836 InstanceCacheInserts:287 InstanceCacheUpdates:0 InstanceCacheDeletes:238 InstanceCacheHits:1 InstanceCacheMisses:7485 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (623/152) Success: 152, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T07:55:56.368 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276} 2026-04-20T07:55:56.368 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{556450D1-A423-4967-AA3F-4CEBB249C4EC} removed 2026-04-20T07:55:56.368 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T07:55:56.368 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D}\mpasbase.vdm in use, hr=0x80070020 2026-04-20T07:55:56.368 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.368 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.368 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.368 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.368 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-20-2026 07:55:56 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 07:55:56 2026-04-20T07:55:56.368 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T07:55:56.368 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T07:55:56.368 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T07:55:56.368 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T07:55:56.368 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T07:55:56.383 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.383 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.383 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.383 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T07:55:56.383 MdCoreSvc is supported in this platform and OS Signature updated on 04-20-2026 07:55:56 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.201.0 AV Signature Version: 1.449.201.0 ************************************************************ 2026-04-20T07:55:56.383 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-20T07:55:56.383 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\FC3318C9-8FF8-4DF8-A8B0-4DA6BD2DC7CB6ec.1dcd09b15d2ce4b 2026-04-20T07:55:56.462 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T07:55:56.462 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-20-2026 07:55:56 ************************************************************ 2026-04-20T07:55:56.493 Job Notification: Process exited from job (980) 2026-04-20T07:55:56.493 Job Notification: Process exited from job (1752) 2026-04-20T07:55:56.571 Job Notification: Process exited from job (3164) 2026-04-20T07:55:56.571 Job Notification: Process exited from job (2148) 2026-04-20T07:55:56.774 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T07:55:56.774 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T07:55:56.774 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T07:55:56.774 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T07:55:56.774 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T07:55:56.774 [Engine] Engine 00007FFFF3AC8020 no longer in use. Number of active engines: 1 2026-04-20T07:55:56.774 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T07:55:56.774 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-20T07:55:56.821 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T07:55:56.821 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T07:55:56.821 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T07:55:56.868 ProcessImageName: CCC.exe, Pid: 13332, TotalTime: 30230, Count: 583, MaxTime: 1968, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 44% 2026-04-20T07:55:56.868 ProcessImageName: AsPowerBar.exe, Pid: 12168, TotalTime: 3035, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 12% 2026-04-20T07:55:56.868 ProcessImageName: explorer.exe, Pid: 6816, TotalTime: 2728, Count: 15, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-20T07:55:56.868 ProcessImageName: MOM.exe, Pid: 6704, TotalTime: 1959, Count: 33, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 6% 2026-04-20T07:55:56.868 ProcessImageName: AISuite3.exe, Pid: 6476, TotalTime: 1401, Count: 15, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 13% 2026-04-20T07:55:56.868 ProcessImageName: websockify.exe, Pid: 12404, TotalTime: 882, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 33% 2026-04-20T07:55:56.868 ProcessImageName: svchost.exe, Pid: 3456, TotalTime: 828, Count: 2, MaxTime: 828, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 9% 2026-04-20T07:55:56.868 ProcessImageName: DipAwayMode.exe, Pid: 6508, TotalTime: 715, Count: 8, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 68% 2026-04-20T07:55:56.868 ProcessImageName: WhatsApp.Root.exe, Pid: 12120, TotalTime: 391, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\33f30818f7af3210717048464ecd35f98e2ec928.tbres->(UTF-16LE), EstimatedImpact: 0% 2026-04-20T07:55:56.868 ProcessImageName: svchost.exe, Pid: 2628, TotalTime: 343, Count: 2, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 100% 2026-04-20T07:55:56.868 ProcessImageName: FileCoAuth.exe, Pid: 11360, TotalTime: 211, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-20T07:55:56.868 ProcessImageName: brynhildr.exe, Pid: 2900, TotalTime: 186, Count: 4, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-20T07:55:56.868 ProcessImageName: PhoneExperienceHost.exe, Pid: 5448, TotalTime: 180, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\AppPatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-20T07:55:56.868 ProcessImageName: runonce.exe, Pid: 12604, TotalTime: 167, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\websockify.exe, EstimatedImpact: 4% 2026-04-20T07:55:56.868 ProcessImageName: CLIStart.exe, Pid: 1144, TotalTime: 123, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 60% 2026-04-20T07:55:56.915 [Engine] RSIG_UNLOADENGINE, 00007FFFF3AC8020, err=0x0 2026-04-20T07:55:56.915 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8119D5E-9D84-49A0-AF16-8184DC58725D} removed 2026-04-20T07:55:58.384 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T07:55:58.384 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T07:55:58.399 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T07:56:16.846 Process scan (postsignatureupdatescan) started. 2026-04-20T07:56:36.262 Process scan (postsignatureupdatescan) completed. 2026-04-20T07:57:16.093 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8EBEE970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5403, FileId: 0x5100000001b1ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.112 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj072D0A960. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5404, FileId: 0x5200000001b1ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.117 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA0DE8697E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5405, FileId: 0x2b00000001ac80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.196 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj50D92C9A8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5412, FileId: 0x2d00000001ac80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.210 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC763E594F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5415, FileId: 0x5400000001b1ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.302 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2892A39F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5425, FileId: 0x3400000001ac80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.334 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj50B4A499A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5427, FileId: 0x5600000001b1ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.365 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj61D4BC96A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5443, FileId: 0x3600000001ac80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.412 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E14239CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5445, FileId: 0x2000000001b727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:16.427 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8284A191C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5446, FileId: 0x2300000001b727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:17.063 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEE73359E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5457, FileId: 0x9c000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:30.644 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5607, FileId: 0x42000000010d35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:30.722 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5609, FileId: 0x6f000000017d44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:57:30.816 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5615, FileId: 0xc900000000866b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T07:58:31.052 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5619, FileId: 0xcf00000000866b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:00:17.202 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #6103, FileId: 0x100000000004b34, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:00:56.267 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T08:05:36.913 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T08:07:30.859 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6667, FileId: 0x84000000010614, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:07:30.875 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6669, FileId: 0x73000000017d44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:15:50.138 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:16:14.745 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:20:35.353 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:20:41.920 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T08:25:49.896 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #9667, FileId: 0x5500000001860e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:28:25.649 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-04-20T08:28:25.649 [RTP] Duplicating the current plugin configuration object... 2026-04-20T08:28:25.649 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T08:28:25.649 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-20T08:28:25.649 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-20T08:28:25.649 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-20T08:28:25.649 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-20T08:29:35.708 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-20T08:31:38.777 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\Program Files\desktop.ini 2026-04-20T08:32:43.864 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:35:46.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T08:39:15.863 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:45:31.916 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-20T08:49:06.066 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11232, FileId: 0x12200000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.098 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11237, FileId: 0x7d000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.098 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11236, FileId: 0x12300000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.098 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11238, FileId: 0x12400000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.098 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11239, FileId: 0x7e000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11244, FileId: 0x80000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11245, FileId: 0x12800000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11243, FileId: 0x12600000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.113 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11246, FileId: 0x82000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.129 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11250, FileId: 0x84000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.129 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11248, FileId: 0x83000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.129 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11253, FileId: 0x12c00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11254, FileId: 0x12d00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11255, FileId: 0x87000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11257, FileId: 0x88000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11258, FileId: 0x12f00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11256, FileId: 0x12e00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.144 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11249, FileId: 0x12a00000000fbee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.504 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11288, FileId: 0x8a000000006627, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:49:06.519 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\14761246-3e90-4178-a6b7-3d4c1cba2365. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #11290, FileId: 0x7a00000003a739, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T08:50:40.024 Bm signature throttled:0x00002db31bed458f 2026-04-20T08:50:51.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T08:53:13.774 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-20T08:53:13.806 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-20T08:53:13.837 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-20T09:02:33.527 [RTP] [Mini-filter] OpenWithoutRead notification (1161, 10036, \Device\HarddiskVolume3\Windows\System32\ApplicationFrameHost.exe) sent successfully. 2026-04-20T09:02:41.862 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #12325, FileId: 0xc0000000b7590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T09:05:56.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T09:21:01.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T09:27:53.659 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14617, FileId: 0xc0000000b7593, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T09:28:57.048 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #15207, FileId: 0x1eb0000000002cc, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T09:33:42.238 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\Festplatten\SMB-Dateiserver_Freigabe.bat Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x698e3580 2026-04-20T09:34:22.958 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T09:34:22.958 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T09:34:22.958 [Cloud] Queued cloud request. 2026-04-20T09:34:22.958 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T09:34:22.958 [Cloud] Dequeued cloud request. 2026-04-20T09:34:22.958 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T09:34:23.388 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b648a7136e496844ef6ef04555bef80e9695bb52 Dynamic Signature Compilation Timestamp:04-20-2026 09:34:24 Persistence Type:Duration Time remaining:50065408 2026-04-20T09:34:23.388 [Cloud] End of cloud request. 2026-04-20T09:34:23.388 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T09:34:23.898 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T09:36:06.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T09:39:28.313 Bm signature throttled:0x00002db31bed458f 2026-04-20T09:47:24.412 Bm signature throttled:0x00002db31bed458f 2026-04-20T09:50:00.469 Bm signature throttled:0x00002db31bed458f 2026-04-20T09:51:11.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T09:55:56.245 ProcessImageName: explorer.exe, Pid: 6816, TotalTime: 6930, Count: 289, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\$RYFR8EC.exe, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: AcroCEF.exe, Pid: 2976, TotalTime: 3588, Count: 174, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-20T09:55:56.245 ProcessImageName: mysqld.exe, Pid: 2884, TotalTime: 1006, Count: 122, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 5% 2026-04-20T09:55:56.245 ProcessImageName: firefox.exe, Pid: 11668, TotalTime: 618, Count: 49, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05584, EstimatedImpact: 43% 2026-04-20T09:55:56.245 ProcessImageName: Notepad.exe, Pid: 13832, TotalTime: 562, Count: 59, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: WinSCP.exe, Pid: 10724, TotalTime: 517, Count: 43, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.de, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 349, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 23% 2026-04-20T09:55:56.245 ProcessImageName: svchost.exe, Pid: 6620, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: WinSCP.exe, Pid: 7836, TotalTime: 242, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: AdobeCollabSync.exe, Pid: 3676, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: winvnc.exe, Pid: 6976, TotalTime: 225, Count: 1425, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: mmc.exe, Pid: 11292, TotalTime: 170, Count: 6, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 11% 2026-04-20T09:55:56.245 ProcessImageName: backgroundTaskHost.exe, Pid: 8288, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-04-20T09:55:56.245 ProcessImageName: Acrobat.exe, Pid: 4820, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 21% 2026-04-20T09:55:56.245 ProcessImageName: FileCoAuth.exe, Pid: 9876, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0825.9876.1.aodl, EstimatedImpact: 1% 2026-04-20T09:55:56.245 ProcessImageName: xampp-control.exe, Pid: 4580, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: taskhostw.exe, Pid: 3724, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-20T09:55:56.245 ProcessImageName: mmc.exe, Pid: 14132, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\GILSANUB.TTF, EstimatedImpact: 7% 2026-04-20T09:55:56.245 ProcessImageName: SDXHelper.exe, Pid: 5004, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 5% 2026-04-20T09:55:56.245 ProcessImageName: SDXHelper.exe, Pid: 4460, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-20T09:55:56.245 ProcessImageName: PhoneExperienceHost.exe, Pid: 5448, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: OfficeC2RClient.exe, Pid: 9636, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 2% 2026-04-20T09:55:56.245 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 61, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: svchost.exe, Pid: 1396, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\87c7da6d-dd5b-46a7-8afa-148335b759fa, EstimatedImpact: 7% 2026-04-20T09:55:56.245 ProcessImageName: svchost.exe, Pid: 1812, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: FileZilla Server Interface.exe, Pid: 1380, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: AdobeARM.exe, Pid: 5952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-20T09:55:56.245 ProcessImageName: AcroCEF.exe, Pid: 8788, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: xampp-control.exe, Pid: 2636, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: FileZilla Server Interface.exe, Pid: 6000, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: FileCoAuth.exe, Pid: 9912, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0902.9912.1.aodl, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: xampp-control.exe, Pid: 11132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 1% 2026-04-20T09:55:56.245 ProcessImageName: Notepad.exe, Pid: 10048, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\8adef259-3cdb-4b07-9770-8511c21a6252.bin, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: xampp-control.exe, Pid: 9152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: SDXHelper.exe, Pid: 6260, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-04-20T09:55:56.245 ProcessImageName: svchost.exe, Pid: 12264, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: mmc.exe, Pid: 6184, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: Acrobat.exe, Pid: 6064, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-04-20T09:55:56.245 ProcessImageName: AggregatorHost.exe, Pid: 4048, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T09:57:43.061 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16218, FileId: 0x1a0000000b7663, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T10:06:16.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T10:21:21.920 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T10:24:56.368 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16856, FileId: 0x190000000b76ac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T10:29:43.762 Bm signature throttled:0x00002db31bed458f 2026-04-20T10:29:44.337 Bm signature throttled:0x00002db31bed458f 2026-04-20T10:30:14.117 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume1\EFI\Microsoft\Boot\BCD.LOG 2026-04-20T10:30:25.357 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #17154, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T10:35:54.298 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17334, FileId: 0x220000000b76bb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T10:36:26.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T10:41:32.543 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17359, FileId: 0x140000000b76e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T10:51:31.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T10:59:38.078 Bm signature throttled:0x00002db31bed458f 2026-04-20T10:59:46.433 Bm signature throttled:0x00002db31bed458f 2026-04-20T11:06:08.318 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17537, FileId: 0x210000000b76ac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T11:06:36.928 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T11:21:41.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T11:36:46.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T11:46:59.162 Bm signature throttled:0x00002db31bed458f 2026-04-20T11:51:51.929 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T11:52:08.929 Bm signature throttled:0x00002db31bed458f 2026-04-20T11:55:56.255 ProcessImageName: explorer.exe, Pid: 6816, TotalTime: 7233, Count: 317, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\$RYFR8EC.exe, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: AcroCEF.exe, Pid: 2976, TotalTime: 3588, Count: 174, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-20T11:55:56.255 ProcessImageName: notepad++.exe, Pid: 6692, TotalTime: 2035, Count: 152, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: PartitionWizard.exe, Pid: 10392, TotalTime: 1603, Count: 14, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 11% 2026-04-20T11:55:56.255 ProcessImageName: mysqld.exe, Pid: 2884, TotalTime: 1006, Count: 122, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 5% 2026-04-20T11:55:56.255 ProcessImageName: firefox.exe, Pid: 11668, TotalTime: 618, Count: 49, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05584, EstimatedImpact: 43% 2026-04-20T11:55:56.255 ProcessImageName: Notepad.exe, Pid: 13832, TotalTime: 562, Count: 59, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: WinSCP.exe, Pid: 10724, TotalTime: 517, Count: 43, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.de, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: httpd.exe, Pid: 3808, TotalTime: 362, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 349, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 23% 2026-04-20T11:55:56.255 ProcessImageName: WinSCP.exe, Pid: 7836, TotalTime: 349, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 6620, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: AdobeCollabSync.exe, Pid: 3676, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: winvnc.exe, Pid: 6976, TotalTime: 225, Count: 1425, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: AdobeARM.exe, Pid: 12884, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 3% 2026-04-20T11:55:56.255 ProcessImageName: mmc.exe, Pid: 11292, TotalTime: 170, Count: 6, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 11% 2026-04-20T11:55:56.255 ProcessImageName: backgroundTaskHost.exe, Pid: 8288, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-04-20T11:55:56.255 ProcessImageName: Acrobat.exe, Pid: 4820, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 21% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 1396, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: WinSCP.exe, Pid: 3416, TotalTime: 107, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: FileCoAuth.exe, Pid: 9876, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0825.9876.1.aodl, EstimatedImpact: 1% 2026-04-20T11:55:56.255 ProcessImageName: xampp-control.exe, Pid: 4580, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 1812, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: taskhostw.exe, Pid: 3724, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-20T11:55:56.255 ProcessImageName: SDXHelper.exe, Pid: 5004, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 5% 2026-04-20T11:55:56.255 ProcessImageName: mmc.exe, Pid: 14132, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\GILSANUB.TTF, EstimatedImpact: 7% 2026-04-20T11:55:56.255 ProcessImageName: SDXHelper.exe, Pid: 4460, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: PhoneExperienceHost.exe, Pid: 5448, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: dllhost.exe, Pid: 6108, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 9636, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 61, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 2888, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1224.log, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\87c7da6d-dd5b-46a7-8afa-148335b759fa, EstimatedImpact: 7% 2026-04-20T11:55:56.255 ProcessImageName: , Pid: 4, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdrvio.sys, EstimatedImpact: 25% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 11608, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: FileZilla Server Interface.exe, Pid: 1380, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 13120, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1157.log, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 7772, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1235.log, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: AdobeARM.exe, Pid: 5952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-20T11:55:56.255 ProcessImageName: AcroCEF.exe, Pid: 8788, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: xampp-control.exe, Pid: 2636, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: FileZilla Server Interface.exe, Pid: 6000, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: FileCoAuth.exe, Pid: 9912, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0902.9912.1.aodl, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: OfficeC2RClient.exe, Pid: 2052, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1306.log, EstimatedImpact: 1% 2026-04-20T11:55:56.255 ProcessImageName: xampp-control.exe, Pid: 11132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 1% 2026-04-20T11:55:56.255 ProcessImageName: Notepad.exe, Pid: 10048, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\8adef259-3cdb-4b07-9770-8511c21a6252.bin, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: AggregatorHost.exe, Pid: 4048, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: xampp-control.exe, Pid: 9152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: SDXHelper.exe, Pid: 6260, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 12264, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: svchost.exe, Pid: 8244, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITD055.tmp, EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: mmc.exe, Pid: 6184, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-20T11:55:56.255 ProcessImageName: Acrobat.exe, Pid: 6064, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-04-20T12:06:56.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T12:20:36.832 Bm signature throttled:0x00002db31bed458f 2026-04-20T12:22:01.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T12:32:05.820 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #18842, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:37:06.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T12:42:22.260 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19826, FileId: 0x120000000b77ce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:48:08.110 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19876, FileId: 0x120000000b77d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:52:11.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T12:54:02.090 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB0931A94A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20153, FileId: 0xb0000000b81c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:54:02.145 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45FC07919. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20156, FileId: 0xa0000000b81cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:54:02.170 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC31A619E6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20158, FileId: 0xb0000000b81cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:54:03.695 Bm signature throttled:0x00002db31bed458f 2026-04-20T12:54:03.700 Bm signature throttled:0x00002db31bed458f 2026-04-20T12:54:16.980 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20187, FileId: 0x170000000b77a6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:54:17.090 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20189, FileId: 0x3300000001b21f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:55:17.040 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20257, FileId: 0x120000000b78ba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:57:56.540 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21637, FileId: 0x1d0000000b818e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:31.953 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7ADC679B3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21644, FileId: 0xb0000000b823d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:32.073 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD72F4F92B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21647, FileId: 0xb0000000b824d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:32.085 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj17BB679EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21648, FileId: 0xc0000000b824d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:38.352 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCBFA2E98E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21742, FileId: 0x140000000b81b4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:38.377 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj21F0AC9B5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21743, FileId: 0xe0000000b823d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:38.404 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C917E974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21744, FileId: 0xf0000000b823d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:46.920 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21783, FileId: 0xaa000000006a85, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T12:59:46.943 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21785, FileId: 0x220000000b77ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:00:46.970 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21791, FileId: 0x4b00000001860a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:06:26.231 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21831, FileId: 0x240000000b818e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:07:16.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T13:08:05.953 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC03B499E6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21845, FileId: 0xe0000000b824d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:06.081 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5ECF9B952. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21846, FileId: 0xb0000000b8253, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:06.100 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0C5F1F94C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21847, FileId: 0xc0000000b8253, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:10.150 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE56CFE9ED. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21856, FileId: 0x1b0000000b77db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:10.200 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF0BEAD971. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21858, FileId: 0x150000000b824d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:12.640 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD872199CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21891, FileId: 0xe0000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:12.661 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2E7C5A92C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21892, FileId: 0xf0000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:15.622 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj418C0E9C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21908, FileId: 0x2b0000000b818e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:15.655 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0ABC039BD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21909, FileId: 0x140000000b8253, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:15.671 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0E8A0798E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21910, FileId: 0x130000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:30.619 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21972, FileId: 0x5c00000001a850, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:08:30.634 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21974, FileId: 0xe0000000b81c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:09:30.650 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22003, FileId: 0x5000000001860a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:17.860 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj57B9FB97F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22056, FileId: 0xa0000000b8261, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:17.922 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj12B6BA9BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22057, FileId: 0xb0000000b8261, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:17.946 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj66368C95D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22058, FileId: 0xc0000000b8261, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:20.390 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6DA13B9BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22095, FileId: 0x360000000b818e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:20.470 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7FC15A92F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22098, FileId: 0xf0000000b825d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:20.485 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB25222970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22099, FileId: 0x100000000b825d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:24.060 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6CEC209DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22123, FileId: 0x110000000b825d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:24.111 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD3501D9B6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22124, FileId: 0xa0000000b826c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:24.125 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFAD9B79A4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22127, FileId: 0xb0000000b826c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:32.861 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22160, FileId: 0x2b0000000b78ba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:12:32.864 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22161, FileId: 0xf600000000438f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:13:32.891 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22187, FileId: 0x300000000b77d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:00.970 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD8E94D9D0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22218, FileId: 0x180000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:00.991 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDDE40796B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22219, FileId: 0x190000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.001 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3DCDE190C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22220, FileId: 0x1a0000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.011 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF56667965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22221, FileId: 0x1b0000000b8256, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.031 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj02911D974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22222, FileId: 0x140000000b8261, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.045 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj14E13A935. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22223, FileId: 0x150000000b8261, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.364 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9D789192D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22238, FileId: 0xc0000000b82ae, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:01.892 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1BD77921. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22269, FileId: 0xb2000000004118, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:02.243 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCDFC0C907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22286, FileId: 0x6600000000ed1d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:02.566 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2B76BF944. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22315, FileId: 0x7300000000ed1d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:02.886 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45503E964. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22330, FileId: 0x4600000001038e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:16:31.041 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22498, FileId: 0x1e0000000b81c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:18:25.124 Bm signature throttled:0x00002db31bed458f 2026-04-20T13:22:21.916 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T13:33:25.700 Bm signature throttled:0x00002db31bed458f 2026-04-20T13:33:30.028 Bm signature throttled:0x00002db31bed458f 2026-04-20T13:37:26.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T13:43:16.919 Bm signature throttled:0x00002db31bed458f 2026-04-20T13:47:38.194 Bm signature throttled:0x00002db31bed458f 2026-04-20T13:52:31.913 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T13:54:39.519 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23428, FileId: 0x5d00000000f346, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T13:55:56.269 ProcessImageName: explorer.exe, Pid: 6816, TotalTime: 7866, Count: 338, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\$RYFR8EC.exe, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: AcroCEF.exe, Pid: 2976, TotalTime: 3588, Count: 174, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-20T13:55:56.269 ProcessImageName: httpd.exe, Pid: 3808, TotalTime: 2244, Count: 186, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_86.php, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: notepad++.exe, Pid: 6692, TotalTime: 2035, Count: 152, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: mmc.exe, Pid: 2612, TotalTime: 1698, Count: 211, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 17% 2026-04-20T13:55:56.269 ProcessImageName: PartitionWizard.exe, Pid: 10392, TotalTime: 1603, Count: 14, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 11% 2026-04-20T13:55:56.269 ProcessImageName: mysqld.exe, Pid: 2884, TotalTime: 1006, Count: 122, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 5% 2026-04-20T13:55:56.269 ProcessImageName: WmiPrvSE.exe, Pid: 10268, TotalTime: 630, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 90% 2026-04-20T13:55:56.269 ProcessImageName: firefox.exe, Pid: 11668, TotalTime: 618, Count: 49, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05584, EstimatedImpact: 43% 2026-04-20T13:55:56.269 ProcessImageName: Notepad.exe, Pid: 13832, TotalTime: 562, Count: 59, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 10724, TotalTime: 517, Count: 43, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.de, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: firefox.exe, Pid: 14544, TotalTime: 466, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 61% 2026-04-20T13:55:56.269 ProcessImageName: AdobeCollabSync.exe, Pid: 3676, TotalTime: 436, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 349, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 23% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 7836, TotalTime: 349, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 14100, TotalTime: 316, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\microsoftNucleusTelemetryCache.otc-shm, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 6620, TotalTime: 281, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: winvnc.exe, Pid: 6976, TotalTime: 225, Count: 1425, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: AdobeARM.exe, Pid: 12884, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 3% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 8568, TotalTime: 184, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: mmc.exe, Pid: 11292, TotalTime: 170, Count: 6, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 11% 2026-04-20T13:55:56.269 ProcessImageName: backgroundTaskHost.exe, Pid: 8288, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 1396, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: Acrobat.exe, Pid: 4820, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 21% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 7152, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\winscp.rnd, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 3416, TotalTime: 107, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: FileCoAuth.exe, Pid: 9876, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0825.9876.1.aodl, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: dllhost.exe, Pid: 6108, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: xampp-control.exe, Pid: 4580, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 1812, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 10324, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NNNIUZK1NFFBD15JKMRT.temp, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: taskhostw.exe, Pid: 3724, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-20T13:55:56.269 ProcessImageName: mmc.exe, Pid: 14132, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\GILSANUB.TTF, EstimatedImpact: 7% 2026-04-20T13:55:56.269 ProcessImageName: SDXHelper.exe, Pid: 5004, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 5% 2026-04-20T13:55:56.269 ProcessImageName: SDXHelper.exe, Pid: 4460, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: PhoneExperienceHost.exe, Pid: 5448, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 9636, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 61, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: SecurityHealthHost.exe, Pid: 6400, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 5% 2026-04-20T13:55:56.269 ProcessImageName: dasHost.exe, Pid: 1792, TotalTime: 46, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\fa095ecc-e13e-40e7-8e6c-5c49799ba6dc_0.bmp, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 14436, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\87c7da6d-dd5b-46a7-8afa-148335b759fa, EstimatedImpact: 7% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 4424, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1442.log, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 2888, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1224.log, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: , Pid: 4, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdrvio.sys, EstimatedImpact: 25% 2026-04-20T13:55:56.269 ProcessImageName: FileZilla Server Interface.exe, Pid: 1380, TotalTime: 45, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 11608, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: SDXHelper.exe, Pid: 5864, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 7% 2026-04-20T13:55:56.269 ProcessImageName: AggregatorHost.exe, Pid: 4048, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 13120, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1157.log, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: AdobeARM.exe, Pid: 5952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 7772, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1235.log, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: WinSCP.exe, Pid: 10932, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9VSVITZEGDS5GJGOCZZO.temp, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: FileZillaServer.exe, Pid: 13824, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server.xml, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: RuntimeBroker.exe, Pid: 8752, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{11A7483A-13BB-49EA-8816-257B9804F7C4}.json, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: AcroCEF.exe, Pid: 8788, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: xampp-control.exe, Pid: 2636, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: cmd.exe, Pid: 7792, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: FileZilla Server Interface.exe, Pid: 6000, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 2052, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1306.log, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: FileCoAuth.exe, Pid: 9912, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0902.9912.1.aodl, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: pingsender.exe, Pid: 14560, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\3cad5900-0808-4b65-985e-9bc1737604fa, EstimatedImpact: 5% 2026-04-20T13:55:56.269 ProcessImageName: xampp-control.exe, Pid: 11132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: TeamViewer.exe, Pid: 7856, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 9112, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1448.log, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 6464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITB90B.tmp, EstimatedImpact: 4% 2026-04-20T13:55:56.269 ProcessImageName: Notepad.exe, Pid: 10048, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\8adef259-3cdb-4b07-9770-8511c21a6252.bin, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 14508, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-20T13:55:56.269 ProcessImageName: FileZilla Server Interface.exe, Pid: 14860, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-9D2F8FF4.pf, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 14592, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1457.log, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 14512, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1525.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: SDXHelper.exe, Pid: 6260, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-04-20T13:55:56.269 ProcessImageName: OfficeC2RClient.exe, Pid: 1332, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1506.log, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: xampp-control.exe, Pid: 9152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 12264, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: svchost.exe, Pid: 8244, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITD055.tmp, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: FileZilla Server Interface.exe, Pid: 8320, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp_7.4.1_mit_Programme\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: mmc.exe, Pid: 6184, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-20T13:55:56.269 ProcessImageName: Acrobat.exe, Pid: 6064, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-04-20T14:07:36.920 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T14:08:43.789 Bm signature throttled:0x00002db31bed458f 2026-04-20T14:22:41.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T14:37:46.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T14:52:51.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T15:07:56.930 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T15:23:01.921 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T15:30:09.321 Bm signature throttled:0x00002db31bed458f 2026-04-20T15:38:06.921 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T15:49:05.409 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25324, FileId: 0x120000000b72f1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T15:49:05.447 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25339, FileId: 0x1b0000000b72f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T15:53:11.978 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T15:55:56.384 ProcessImageName: explorer.exe, Pid: 6816, TotalTime: 8161, Count: 344, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\$RYFR8EC.exe, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: AcroCEF.exe, Pid: 2976, TotalTime: 3588, Count: 174, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-04-20T15:55:56.384 ProcessImageName: httpd.exe, Pid: 3808, TotalTime: 2244, Count: 186, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_86.php, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: notepad++.exe, Pid: 6692, TotalTime: 2035, Count: 152, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: mmc.exe, Pid: 2612, TotalTime: 1698, Count: 211, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 17% 2026-04-20T15:55:56.384 ProcessImageName: PartitionWizard.exe, Pid: 10392, TotalTime: 1603, Count: 14, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 11% 2026-04-20T15:55:56.384 ProcessImageName: mysqld.exe, Pid: 2884, TotalTime: 1006, Count: 122, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 5% 2026-04-20T15:55:56.384 ProcessImageName: WmiPrvSE.exe, Pid: 10268, TotalTime: 630, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 90% 2026-04-20T15:55:56.384 ProcessImageName: firefox.exe, Pid: 11668, TotalTime: 618, Count: 49, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05584, EstimatedImpact: 43% 2026-04-20T15:55:56.384 ProcessImageName: Notepad.exe, Pid: 13832, TotalTime: 562, Count: 59, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_94.php, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 10724, TotalTime: 517, Count: 43, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.de, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: firefox.exe, Pid: 14544, TotalTime: 466, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 61% 2026-04-20T15:55:56.384 ProcessImageName: firefox.exe, Pid: 4100, TotalTime: 450, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa06516, EstimatedImpact: 58% 2026-04-20T15:55:56.384 ProcessImageName: AdobeCollabSync.exe, Pid: 3676, TotalTime: 436, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 6620, TotalTime: 406, Count: 3, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 349, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 23% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 7836, TotalTime: 349, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 14100, TotalTime: 316, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\ListSync\Business1\microsoftNucleusTelemetryCache.otc-shm, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 1396, TotalTime: 240, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: winvnc.exe, Pid: 6976, TotalTime: 225, Count: 1425, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: AdobeARM.exe, Pid: 12884, TotalTime: 196, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 3% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 8568, TotalTime: 184, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: mmc.exe, Pid: 11292, TotalTime: 170, Count: 6, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 11% 2026-04-20T15:55:56.384 ProcessImageName: backgroundTaskHost.exe, Pid: 8288, TotalTime: 165, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 6468, TotalTime: 139, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BIT3013.tmp, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: Acrobat.exe, Pid: 4820, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 21% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 7152, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\winscp.rnd, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: dllhost.exe, Pid: 6108, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 3416, TotalTime: 107, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\WinSCP-5.9.2\WinSCP.ini, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: FileCoAuth.exe, Pid: 9876, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0825.9876.1.aodl, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: xampp-control.exe, Pid: 4580, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 1812, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 10324, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NNNIUZK1NFFBD15JKMRT.temp, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: taskhostw.exe, Pid: 3724, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-20T15:55:56.384 ProcessImageName: SDXHelper.exe, Pid: 5004, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 5% 2026-04-20T15:55:56.384 ProcessImageName: mmc.exe, Pid: 14132, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\GILSANUB.TTF, EstimatedImpact: 7% 2026-04-20T15:55:56.384 ProcessImageName: SDXHelper.exe, Pid: 4460, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: AggregatorHost.exe, Pid: 4048, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: PhoneExperienceHost.exe, Pid: 5448, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 9636, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9FC92D06-0227-48CD-B442-E9DAFF45BBC8, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 61, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: armsvc.exe, Pid: 4052, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 30% 2026-04-20T15:55:56.384 ProcessImageName: AdobeARM.exe, Pid: 10340, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\AcroManifest3.msi, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: SecurityHealthHost.exe, Pid: 6400, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 5% 2026-04-20T15:55:56.384 ProcessImageName: dasHost.exe, Pid: 1792, TotalTime: 46, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\fa095ecc-e13e-40e7-8e6c-5c49799ba6dc_0.bmp, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: AdobeARM.exe, Pid: 13892, TotalTime: 46, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 14436, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 4424, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1442.log, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\87c7da6d-dd5b-46a7-8afa-148335b759fa, EstimatedImpact: 7% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 2888, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1224.log, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: , Pid: 4, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdrvio.sys, EstimatedImpact: 25% 2026-04-20T15:55:56.384 ProcessImageName: FileZilla Server Interface.exe, Pid: 1380, TotalTime: 45, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 11608, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: SDXHelper.exe, Pid: 5864, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 7% 2026-04-20T15:55:56.384 ProcessImageName: WinSCP.exe, Pid: 10932, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9VSVITZEGDS5GJGOCZZO.temp, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 13120, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1157.log, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 7772, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1235.log, EstimatedImpact: 2% 2026-04-20T15:55:56.384 ProcessImageName: AdobeARM.exe, Pid: 5952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-20T15:55:56.384 ProcessImageName: FileZillaServer.exe, Pid: 13824, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server.xml, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: RuntimeBroker.exe, Pid: 8752, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{11A7483A-13BB-49EA-8816-257B9804F7C4}.json, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: AcroCEF.exe, Pid: 8788, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: xampp-control.exe, Pid: 2636, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 13760, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1623.log, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 11664, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1628.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: cmd.exe, Pid: 7792, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: FileZilla Server Interface.exe, Pid: 6000, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: FileCoAuth.exe, Pid: 9912, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-20.0902.9912.1.aodl, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 2052, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1306.log, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: pingsender.exe, Pid: 14560, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\3cad5900-0808-4b65-985e-9bc1737604fa, EstimatedImpact: 5% 2026-04-20T15:55:56.384 ProcessImageName: OfficeC2RClient.exe, Pid: 9112, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-1448.log, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: TeamViewer.exe, Pid: 7856, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: xampp-control.exe, Pid: 11132, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: svchost.exe, Pid: 6464, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITB90B.tmp, EstimatedImpact: 4% 2026-04-20T15:55:56.384 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 14508, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-20T15:55:56.384 ProcessImageName: Notepad.exe, Pid: 10048, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\8adef259-3cdb-4b07-9770-8511c21a6252.bin, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: FileZilla Server Interface.exe, Pid: 14860, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-9D2F8FF4.pf, EstimatedImpact: 0% 2026-04-20T15:55:56.384 ProcessImageName: cmd.exe, Pid: 11048, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-20-2026 16:52:40 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/20/2026 16:52:40.518202100 UTC (14234 ms since boot) 2026-04-20T16:52:40.601 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-20T16:52:40.614 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T16:52:40.614 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T16:52:40.680 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260420-165240-00000003-fffffffeffffffff.bin ... 2026-04-20T16:52:40.727 [WPP] Trace session started - MpWppTracing-20260420-165240-00000003-fffffffeffffffff.bin 2026-04-20T16:52:40.727 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-20T16:52:40.727 [RbM] Rollback manager succesfully initialized. 2026-04-20T16:52:40.727 [RbM] Rollback manager EnableRollbackManager called. 2026-04-20T16:52:40.742 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-20T16:52:40.742 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-20T16:52:40.742 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-20T16:52:40.742 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-20T16:52:40.742 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-20T16:52:40.742 MdCoreSvc is supported in this platform and OS 2026-04-20T16:52:40.742 MdCoreSvc is supported in this platform and OS 2026-04-20T16:52:40.742 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T16:52:40.742 [PlatUpd] Starting MdCoreSvc service 2026-04-20T16:52:40.773 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-20T16:52:45.695 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-20T16:52:45.695 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-20T16:52:45.695 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-20T16:52:45.695 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-20T16:52:45.695 [PlatUpd] CSP platform update started 2026-04-20T16:52:45.695 [PlatUpd] Defender MDM CSP platform update not required 2026-04-20T16:52:45.695 [PlatUpd] WMI/PS provider platform update started 2026-04-20T16:52:45.695 [PlatUpd] WMI/PS provider platform update not required 2026-04-20T16:52:45.695 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-20T16:52:45.695 MdCoreSvc is supported in this platform and OS 2026-04-20T16:52:45.695 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T16:52:45.695 [PlatUpd] Starting MdCoreSvc service 2026-04-20T16:52:45.695 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-20T16:52:45.695 [TS] Troublshooting mode is not available! 2026-04-20T16:52:45.695 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T16:52:45.695 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-20T16:52:45.742 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-20T16:52:45.742 [Service] Enabling AutoLoggers ... 2026-04-20T16:52:45.742 [Service] Enabling AMSI registration ... 2026-04-20T16:52:45.742 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-20T16:52:45.758 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52189 Number of invalid entries is 0 Number of inserts issued is 1572811 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6370 Number of lookups is 106859745 Number of lookup misses is 5119581 Number of fast lookup misses is 54541416 Number of false fast lookups is 5119576 Number of invalidations is 728923 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-20T16:52:45.758 Verifying license file... 2026-04-20T16:52:45.758 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-20T16:52:45.773 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-20T16:52:45.773 Loaded module#0 MpComServer. 2026-04-20T16:52:45.773 Loaded module#1 StartupPolicies. 2026-04-20T16:52:45.773 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T16:52:45.773 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T16:52:45.789 COM server initialized successfully. 2026-04-20T16:52:45.805 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-20T16:52:45.805 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-20T16:52:45.805 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-20T16:52:45.820 [RTP] [RTP] FilterCommunicator object 0x000001B2FC497DC0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T16:52:45.836 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-20T16:52:45.836 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T16:52:45.836 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T16:52:45.836 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-20T16:52:45.836 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-20T16:52:45.836 [RTP] [RTP] FilterCommunicator object 0x000001B2FC497FD0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T16:52:45.836 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-20T16:52:45.836 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-20T16:52:45.836 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-20T16:52:45.836 [RTP] [RTP] StartCommunication 0x000001B2FC497DC0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T16:52:45.836 [init][RTP] RTPPlugin initialization completed 2026-04-20T16:52:45.836 OS boot count = 2 2026-04-20T16:52:45.836 OS Install = 0 2026-04-20T16:52:45.898 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-20T16:52:45.898 [KSL] Entering CKSLEngine::Initialize. 2026-04-20T16:52:45.898 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-20T16:52:45.898 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-20T16:52:45.898 [KSL] MpInstallKslD: hr=0x1 2026-04-20T16:52:45.898 [KSL] MpRegisterKslD: hr=0 2026-04-20T16:52:45.914 [KSL] MpStartKslD: hr=0 2026-04-20T16:52:45.914 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T16:52:45.914 Loading engine... 2026-04-20T16:52:45.930 Verifying engine and signature files (source: 1) ... 2026-04-20T16:52:45.930 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpengine.dll] due to PPL. 2026-04-20T16:52:45.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasbase.vdm] (file in cache) 2026-04-20T16:52:45.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasdlta.vdm] (file in cache) 2026-04-20T16:52:45.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpavbase.vdm] (file in cache) 2026-04-20T16:52:45.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpavdlta.vdm] (file in cache) 2026-04-20T16:52:45.977 [Engine] IsHybridMode: 0 2026-04-20T16:52:45.977 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T16:52:46.023 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DB145F40C26D0BE5E22A4ADC5941F2900B658FB3.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T16:53:00.582 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T16:53:00.582 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T16:53:00.582 [Engine] New active engine 00007FF9781D8020 (no old engine). Number of active engines: 1 2026-04-20T16:53:00.597 EngineInit:Global ASOC is enabled 2026-04-20T16:53:00.597 EngineInit:ASOO is enabled for developer volumes 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.738 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T16:53:00.785 MpWriteUupSignatureVersion 1.449.201.0, hr = 0 2026-04-20T16:53:00.785 [SigStatUpd] CSignatureStatus: back to good 2026-04-20T16:53:00.785 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T16:53:00.832 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T16:53:00.847 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T16:53:00.847 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T16:53:00.847 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T16:53:00.847 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T16:53:00.863 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T16:53:00.863 [Plugin] Initializing RTP plugin state... 2026-04-20T16:53:00.863 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3745 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18386 TotalHits:0 InstanceCacheInserts:28 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3925 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T16:53:00.863 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T16:53:00.863 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276} 2026-04-20T16:53:00.863 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T16:53:00.863 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T16:53:00.863 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T16:53:00.863 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T16:53:00.863 MdCoreSvc is supported in this platform and OS 2026-04-20T16:53:00.863 Engine loaded! 2026-04-20T16:53:00.878 [DLP] Create FeatureControlState instance 2026-04-20T16:53:00.878 RegisterSModeChangeListener: hr = 0x1 2026-04-20T16:53:00.878 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-20T16:53:00.878 RegisterHybridModeChangeListener: hr = 0 2026-04-20T16:53:00.878 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-20T16:53:00.894 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-20T16:53:00.894 [SigReleaseHb] Initialized with Stage 0 2026-04-20T16:53:00.894 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-20T16:53:00.894 [SCC][CID=34609_5584] Initializing ... 2026-04-20T16:53:00.894 [SCC][CID=34609_5584] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-20T16:53:00.894 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T16:53:00.894 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T16:53:00.894 [NRI] Stopping NIS service ... 2026-04-20T16:53:00.910 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-20T16:53:00.910 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.201.0 AV Signature Version: 1.449.201.0 ************************************************************ 2026-04-20T16:53:00.910 Resource usage Monitoring is enabled 2026-04-20T16:53:00.910 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-20T16:53:00.910 Job Notification: New process added to job (4408) 2026-04-20T16:53:00.925 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T16:53:00.925 Job Notification: New process added to job (11528) 2026-04-20T16:53:00.925 Job Notification: New process added to job (11536) 2026-04-20T16:53:00.941 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11528] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11536]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T16:53:01.050 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T16:53:01.066 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T16:53:01.066 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T16:53:01.066 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T16:53:01.066 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T16:53:01.066 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T16:53:01.066 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T16:53:01.066 [RTP] Generating the base plugin configuration ... 2026-04-20T16:53:01.066 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-20T16:53:01.066 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T16:53:01.066 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-20T16:53:01.066 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-20T16:53:01.066 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T16:53:01.066 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T16:53:01.082 [RTP] [RTP] StartCommunication 0x000001B2FC497FD0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T16:53:01.082 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-20T16:53:01.128 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-20T16:53:01.207 Job Notification: Process exited from job (11528) 2026-04-20T16:53:01.222 Job Notification: Process exited from job (11536) 2026-04-20T16:53:01.222 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-20T16:53:01.300 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T16:53:01.300 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T16:53:01.300 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T16:53:01.488 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T16:53:04.041 [RTP] Duplicating the current plugin configuration object... 2026-04-20T16:53:04.041 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T16:53:04.041 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-20T16:53:04.042 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T16:53:04.043 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-20T16:53:15.677 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #803, FileId: 0xd0000000b859a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T16:53:17.174 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #872, FileId: 0xe0000000b8bb2, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T16:53:17.796 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\Prefetch\SETHC.EXE-1E0D0DA0.pf. Process: \Device\HarddiskVolume3\Windows\System32\sethc.exe, Status: 0xc000004b, State: 0, ScanRequest #913, FileId: 0xb0000000b8bbe, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T16:53:22.558 Bm signature throttled:0x00002db31bed458f 2026-04-20T16:53:45.787 Process scan (poststartupscan) started. 2026-04-20T16:53:45.787 Process scan (poststartupscan) completed. 2026-04-20T16:53:46.286 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-20T16:53:46.302 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-20T16:53:48.873 [RTP] Duplicating the current plugin configuration object... 2026-04-20T16:53:48.873 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T16:53:48.873 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-20T16:53:48.874 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T16:53:48.874 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-20T16:54:08.534 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-04-20T16:54:08.534 [RTP] Duplicating the current plugin configuration object... 2026-04-20T16:54:08.534 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T16:54:08.534 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-20T16:54:08.534 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-20T16:54:08.534 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-20T16:54:08.549 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-20T16:54:09.299 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-20T16:54:42.814 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T16:54:42.814 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T16:54:42.814 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T16:57:43.275 Bm signature throttled:0x00002db31bed458f 2026-04-20T16:57:46.213 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #3984, FileId: 0x1a0000000bce78, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T16:58:00.638 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T16:58:00.903 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T17:01:12.956 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe (PPID:9640:134211780723968813) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe, EnableCfa:1 2026-04-20T17:01:35.426 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\CHANGES\%Local AppData%\Microsoft\Windows\INetCache\IE\DUJMIIJA\update2[1].xml. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, Status: 0xc0000001, State: 0, ScanRequest #4504, FileId: 0xc0000000bce7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:01:35.664 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\CHANGES\%Local AppData%\Microsoft\Windows\INetCache\IE\DUJMIIJA\default[1]. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, Status: 0xc0000001, State: 0, ScanRequest #4505, FileId: 0xd0000000bce7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:01:36.045 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5724:134211780959613795) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:36.045 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:36.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3060:134211780964374797) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:36.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:36.940 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:15100:134211780968846067) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:36.940 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:37.409 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2236:134211780973531002) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:37.409 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:37.898 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:12472:134211780978329814) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:37.898 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:38.359 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:12540:134211780982921087) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:38.359 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:38.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:12648:134211780987662592) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:38.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:39.300 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2588:134211780992346314) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:39.300 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:39.767 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:988:134211780996884787) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:39.767 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:40.253 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:10504:134211781001955441) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:40.253 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:40.725 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3928:134211781006676235) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:40.725 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:41.190 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7504:134211781011280010) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:41.190 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:41.659 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3112:134211781015927301) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:41.659 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:42.128 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:13952:134211781020617603) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:42.128 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:42.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:1408:134211781025244307) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:42.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:44.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3100:134211781042312871) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:44.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:44.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7092:134211781047160025) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:44.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:50.065 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:13464:134211781099950445) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:50.065 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:50.628 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:8036:134211781105612732) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:50.628 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:51.148 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3988:134211781110577585) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:51.148 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:51.609 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:15108:134211781115516732) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:51.609 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:52.065 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3992:134211781120160195) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:52.065 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:52.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7488:134211781124838603) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:52.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:53.018 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:12672:134211781129491207) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:53.018 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:53.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:8280:134211781134400689) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:53.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:53.987 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:1516:134211781139170490) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:53.987 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:54.456 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2980:134211781143996689) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:54.456 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:54.924 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:1752:134211781148588721) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:54.924 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:55.393 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2644:134211781153368416) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:55.393 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:55.846 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3440:134211781157959030) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:55.846 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:01:56.315 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5048:134211781162496252) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:01:56.315 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:00.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2496:134211781204682470) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:00.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:01.042 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5840:134211781209732952) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:01.042 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:02.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7088:134211781227710880) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:02.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:05.706 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7164:134211781256313631) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:05.706 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:06.237 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:1812:134211781261766088) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:06.237 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:06.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:8032:134211781266554726) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:06.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:07.221 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:11700:134211781271383902) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:07.221 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:07.737 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5872:134211781276667697) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:07.737 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:08.190 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:14192:134211781281343543) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:08.190 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:08.659 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2268:134211781285885917) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:08.659 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:09.237 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7156:134211781291493664) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:09.237 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:09.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:9580:134211781296999057) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:09.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:10.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:15356:134211781302284685) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:10.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:10.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:4884:134211781307275376) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:10.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:11.252 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:6296:134211781311870883) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:11.252 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:11.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:8076:134211781316558771) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:11.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:12.174 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:6276:134211781321239041) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:12.174 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:12.612 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:13616:134211781325926196) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:12.612 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:13.112 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3084:134211781330561216) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:13.112 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:13.597 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:14032:134211781335409063) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:13.597 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:14.081 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7612:134211781340166080) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:14.081 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:14.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7368:134211781344843974) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:14.549 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:15.034 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:11120:134211781349627615) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:15.034 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:15.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:2684:134211781354365218) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:15.503 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:15.971 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:10632:134211781359051806) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:15.971 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:16.449 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7980:134211781363830525) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:16.449 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:16.909 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7908:134211781368419407) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:16.909 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:17.393 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:10660:134211781373279164) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:17.393 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:17.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:14028:134211781377801714) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:17.831 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:18.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:4672:134211781382311265) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:18.299 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:18.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5900:134211781387288745) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:18.784 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:19.253 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:6120:134211781391861755) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:19.253 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:19.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:5748:134211781396516574) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:19.721 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:20.175 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3320:134211781401183772) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:20.175 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:20.643 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:7972:134211781405784168) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:20.643 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:21.096 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:12748:134211781410473904) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:21.096 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:02:21.674 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe (PPID:3136:134211781414985102) is tainted: TaintType:0x8. TaintReason:C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3.exe, EnableCfa:1 2026-04-20T17:02:21.674 Engine:Process C:\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\moviethumb.exe originally tainted by: TaintType:0x8, TaintReason:C:\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe 2026-04-20T17:03:00.900 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-20T17:03:00.900 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-20T17:03:00.940 Job Notification: New process added to job (14044) 2026-04-20T17:03:00.948 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-20T17:03:00.948 Aggressive catchup quick scan threshold: 365049558590 / 25920000000000 2026-04-20T17:03:00.948 Job Notification: New process added to job (2744) 2026-04-20T17:03:00.948 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:14044] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2744]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T17:03:01.011 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 31939067(ms) from now at 03:55 (01:55 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-20T17:03:01.043 Job Notification: New process added to job (14148) 2026-04-20T17:03:01.058 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-20T17:03:01.058 Job Notification: New process added to job (3468) 2026-04-20T17:03:01.065 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:14148] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3468]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T17:03:01.264 Job Notification: New process added to job (3964) 2026-04-20T17:03:01.264 Task(GetDeviceTicket -AccessKey E8D8B3D7-49A0-9225-4435-E8670B6B6628 ) launched as network service 2026-04-20T17:03:01.455 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-20T17:03:01.455 [RTP] Duplicating the current plugin configuration object... 2026-04-20T17:03:01.455 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T17:03:01.455 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-20T17:03:01.455 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T17:03:01.455 [RTP] No config change detected. Not updating plugin configuration. 2026-04-20T17:03:01.455 [RTP] No config changes found. No configuration switch. 2026-04-20T17:03:01.455 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-20T17:03:01.752 Job Notification: Process exited from job (3964) 2026-04-20T17:03:01.815 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-20T17:03:01.815 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:03:01.815 [Cloud] Queued cloud request. 2026-04-20T17:03:01.815 [Cloud] Dequeued cloud request. 2026-04-20T17:03:01.815 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:03:02.002 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-20T17:03:02.002 [Cloud] End of cloud request. 2026-04-20T17:03:02.315 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T17:03:15.737 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\C276FB96-4AD7-42CD-9454-AE580433FA183b34.1dcd0e7933bbbe0 2026-04-20T17:03:15.815 Verifying engine and signature files (source: 0) ... 2026-04-20T17:03:15.815 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpengine.dll] due to PPL. 2026-04-20T17:03:15.815 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpasbase.vdm] (file in cache) 2026-04-20T17:03:15.815 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-20T17:03:15.831 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpasdlta.vdm] 2026-04-20T17:03:15.831 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpavbase.vdm] (file in cache) 2026-04-20T17:03:15.831 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-20T17:03:15.846 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpavdlta.vdm] 2026-04-20T17:03:16.018 [Engine] IsHybridMode: 0 2026-04-20T17:03:16.018 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T17:03:16.034 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-944A352C830A7661684463EED71B46FDA84C4CA5.bin): 0x00000002 2026-04-20T17:03:16.034 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-944A352C830A7661684463EED71B46FDA84C4CA5.bin) 2026-04-20T17:03:16.034 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-20T17:03:16.034 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-20T17:03:16.034 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-20T17:03:16.034 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T17:03:27.893 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T17:03:27.893 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T17:03:27.909 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF9781D8020, lRefCount: 5, hr=0 2026-04-20T17:03:27.909 [Engine] New active engine 00007FF94F088020 replacing engine 00007FF9781D8020. Number of active engines: 2 2026-04-20T17:03:27.909 EngineInit:Global ASOC is enabled 2026-04-20T17:03:27.909 EngineInit:ASOO is enabled for developer volumes 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.971 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T17:03:27.987 MpWriteUupSignatureVersion 1.449.206.0, hr = 0 2026-04-20T17:03:27.987 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T17:03:28.002 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T17:03:28.002 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T17:03:28.002 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T17:03:28.002 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T17:03:28.002 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T17:03:28.018 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T17:03:28.018 [Plugin] Initializing RTP plugin state... 2026-04-20T17:03:28.018 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T17:03:28.018 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎20‎-‎2026 18:53:01 Last Perf:‎04‎-‎20‎-‎2026 18:53:00 First RTP Scan:‎04‎-‎20‎-‎2026 18:53:01 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2127 Misses:2435 BM Queue:0,345,0 Proc:0,235,0 File:0,143,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:4937 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:13816518 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:7074 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:29882 TotalHits:21870 InstanceCacheInserts:523 InstanceCacheUpdates:0 InstanceCacheDeletes:302 InstanceCacheHits:0 InstanceCacheMisses:8888 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:6ms (1801/258) Success: 258, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T17:03:28.018 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C} 2026-04-20T17:03:28.034 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6B90565A-EB09-41F8-A9FC-7145CE902AC0} removed 2026-04-20T17:03:28.034 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276}\mpasbase.vdm in use, hr=0x80070020 2026-04-20T17:03:28.034 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-20-2026 17:03:28 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 17:03:28 2026-04-20T17:03:28.034 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T17:03:28.034 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T17:03:28.034 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T17:03:28.034 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T17:03:28.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T17:03:28.034 MdCoreSvc is supported in this platform and OS Signature updated on 04-20-2026 17:03:28 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.206.0 AV Signature Version: 1.449.206.0 ************************************************************ 2026-04-20T17:03:28.034 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-20T17:03:28.034 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\C276FB96-4AD7-42CD-9454-AE580433FA183b34.1dcd0e7933bbbe0 2026-04-20T17:03:28.112 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T17:03:28.112 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-20-2026 17:03:28 ************************************************************ 2026-04-20T17:03:28.143 Job Notification: Process exited from job (14148) 2026-04-20T17:03:28.143 Job Notification: Process exited from job (3468) 2026-04-20T17:03:28.221 Job Notification: Process exited from job (14044) 2026-04-20T17:03:28.221 Job Notification: Process exited from job (2744) 2026-04-20T17:03:28.409 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T17:03:28.409 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T17:03:28.409 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T17:03:28.409 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T17:03:28.409 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T17:03:28.424 [Engine] Engine 00007FF9781D8020 no longer in use. Number of active engines: 1 2026-04-20T17:03:28.424 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T17:03:28.424 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-20T17:03:28.502 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T17:03:28.502 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T17:03:28.502 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T17:03:28.518 ProcessImageName: explorer.exe, Pid: 6396, TotalTime: 20850, Count: 210, MaxTime: 3984, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Picasa\PICASA.cameyo.exe->(EXEEmb), EstimatedImpact: 3% 2026-04-20T17:03:28.518 ProcessImageName: PICASA.cameyo.exe, Pid: 3696, TotalTime: 3436, Count: 9, MaxTime: 3328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\AppVirtDll_Picasa.dll, EstimatedImpact: 15% 2026-04-20T17:03:28.518 ProcessImageName: AsPowerBar.exe, Pid: 13024, TotalTime: 2957, Count: 19, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 52% 2026-04-20T17:03:28.518 ProcessImageName: DipAwayMode.exe, Pid: 6860, TotalTime: 2644, Count: 27, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 12% 2026-04-20T17:03:28.518 ProcessImageName: Picasa3.exe, Pid: 9640, TotalTime: 2301, Count: 202, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\VOS\Picasa\PROG\%Program Files (x86)%\Google\Picasa3\Picasa3i18n.dll, EstimatedImpact: 3% 2026-04-20T17:03:28.518 ProcessImageName: MOM.exe, Pid: 15188, TotalTime: 1728, Count: 29, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-04-20T17:03:28.518 ProcessImageName: AISuite3.exe, Pid: 6872, TotalTime: 1413, Count: 24, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-20T17:03:28.518 ProcessImageName: notepad++.exe, Pid: 4192, TotalTime: 920, Count: 68, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 2% 2026-04-20T17:03:28.518 ProcessImageName: websockify.exe, Pid: 15212, TotalTime: 896, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\_ssl.pyd, EstimatedImpact: 58% 2026-04-20T17:03:28.518 ProcessImageName: WhatsApp.Root.exe, Pid: 13908, TotalTime: 240, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-20T17:03:28.518 ProcessImageName: TabTip.exe, Pid: 13684, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-20T17:03:28.518 ProcessImageName: brynhildr.exe, Pid: 3176, TotalTime: 140, Count: 4, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-20T17:03:28.518 ProcessImageName: runonce.exe, Pid: 12828, TotalTime: 137, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\websockify.exe, EstimatedImpact: 1% 2026-04-20T17:03:28.518 ProcessImageName: PhoneExperienceHost.exe, Pid: 8416, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-20T17:03:28.549 [Engine] RSIG_UNLOADENGINE, 00007FF9781D8020, err=0x0 2026-04-20T17:03:28.565 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FDE06591-C2CE-404B-AAAD-D54E6A5DB276} removed 2026-04-20T17:03:30.034 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T17:03:30.034 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T17:03:30.034 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T17:03:45.784 Process scan (postsignatureupdatescan) started. 2026-04-20T17:04:04.003 Process scan (postsignatureupdatescan) completed. 2026-04-20T17:04:45.424 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD70A01927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5414, FileId: 0x13000000013ed1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.424 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBE53569C2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5416, FileId: 0xad0000000041b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.440 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj222C38973. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5418, FileId: 0xae0000000041b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.534 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj076ED395E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5428, FileId: 0x2d00000001aa98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.565 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCBD1FA966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5433, FileId: 0x2f00000001aa98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.806 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7E36D992F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5444, FileId: 0x2600000001b09b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.821 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC007909AF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5453, FileId: 0x56000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.837 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4DE56C9D1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5448, FileId: 0x3100000001aa98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.900 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3F83929ED. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5471, FileId: 0x3200000001aa98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.931 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCA7BC39DC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5488, FileId: 0x59000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:45.993 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3341DA934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5510, FileId: 0xd30000000044f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:46.009 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBF1A8E907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5511, FileId: 0x2800000001b3de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:04:46.622 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj98D6BA9FB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5552, FileId: 0xf500000001b22b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:05:00.159 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5805, FileId: 0xd00000000ff35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:05:00.237 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5809, FileId: 0x6700000001005b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:05:00.331 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5813, FileId: 0x1300000001006b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:05:40.190 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 Internal signature match:subtype=Lowfi, sigseq=0x00000555178D773A, sigsha=0fc2c923cbcd9797cf319c1df7fa3d8f521ce2a9, cached=false, source=0, resourceid=0x182e1412 2026-04-20T17:05:40.221 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.237 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.299 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.362 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.456 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.471 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:05:40.596 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:05:40.596 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:05:40.596 [Cloud] Queued cloud request. 2026-04-20T17:05:40.596 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:05:40.596 [Cloud] Dequeued cloud request. 2026-04-20T17:05:40.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c703967ed1a945623c2600e10d4cd23480caa174 Dynamic Signature Compilation Timestamp:04-20-2026 17:05:41 Persistence Type:Duration Time remaining:150196224 2026-04-20T17:05:40.909 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00000555178D773A, sigsha=0fc2c923cbcd9797cf319c1df7fa3d8f521ce2a9, cached=false, source=0, resourceid=0x182e1412 Internal signature match:subtype=Lowfi, sigseq=0x00000070DE3CA1F0, sigsha=da39a3ee5e6b4b0d3255bfef95601890afd80709, cached=false, source=0, resourceid=0x182e1412 2026-04-20T17:05:41.018 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x6459d2927ffffffe 2026-04-20T17:05:41.034 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-04-20T17:05:41.413 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T17:05:41.694 Dynamic signature received 2026-04-20T17:05:43.304 ReportLowfi(c:\users\ithan\desktop\portdesktop\3_portable\portable\xboot-1-0-build-14-en-win\xbootvs1.0beta14.exe, 0x9f2a1f55) from 0x000ecebd8f6a4b58 2026-04-20T17:06:00.378 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6310, FileId: 0x6800000001005b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:07:46.987 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #6507, FileId: 0x101000000004b34, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:08:27.925 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T17:09:32.940 Lua SetAttribute:Filter caching disabled for \Device\HarddiskVolume3\Users\ITHAN\Downloads\websockify-master\websockify-master\CHANGES.txt (runtime MpDisableCaching from 0x00040cbdc4489f5e) 2026-04-20T17:09:32.940 MpLog-Throttle:The above 1 log lines will be snoozed for 3600000 ms Internal signature match:subtype=Lowfi, sigseq=0x000017E741530473, sigsha=60462a18b8bebb90c4c31884470339e8172f14bb, cached=false, source=2, resourceid=0x93059360 Internal signature match:subtype=Lowfi, sigseq=0x000112E75BEB89A0, sigsha=df2e4c6cfedf431b491a3226e0c0200928a3db58, cached=false, source=2, resourceid=0x93059360 2026-04-20T17:09:32.956 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\Downloads\websockify-master\websockify-master\CHANGES.txt. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x17e741530473 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3a67ba1e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x67704ae4 2026-04-20T17:12:44.800 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:12:44.800 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:12:44.800 [Cloud] Queued cloud request. 2026-04-20T17:12:44.800 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:12:44.800 [Cloud] Dequeued cloud request. 2026-04-20T17:12:44.800 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3ec8f46c 2026-04-20T17:12:45.096 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ba8b638a59158c67aad218bb5e8c306de4a0501 Dynamic Signature Compilation Timestamp:04-20-2026 17:12:46 Persistence Type:Duration Time remaining:50065408 2026-04-20T17:12:45.096 [Cloud] End of cloud request. 2026-04-20T17:12:45.096 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:12:45.596 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T17:13:05.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T17:15:00.362 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7703, FileId: 0x200000000067ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:15:00.378 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7705, FileId: 0xf700000000ada1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:15:10.549 Bm signature throttled:0x00002db31bed458f 2026-04-20T17:22:05.659 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9100, FileId: 0x39000000033690, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:28:10.898 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T17:29:38.065 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0xb36f07dc 2026-04-20T17:39:44.688 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10589, FileId: 0x710000000b76bd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T17:43:15.898 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x802c102a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x97e219b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4d39d04d 2026-04-20T17:45:16.565 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:45:16.565 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:45:16.565 [Cloud] Queued cloud request. 2026-04-20T17:45:16.565 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:45:16.565 [Cloud] Dequeued cloud request. 2026-04-20T17:45:16.565 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:45:16.596 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:45:16.596 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:45:16.596 [Cloud] Queued cloud request. 2026-04-20T17:45:16.596 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:45:16.596 [Cloud] Dequeued cloud request. 2026-04-20T17:45:16.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:45:16.846 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:45:16.846 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:45:16.846 [Cloud] Queued cloud request. 2026-04-20T17:45:16.846 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:45:16.846 [Cloud] Dequeued cloud request. 2026-04-20T17:45:16.846 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:45:17.081 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b95c30a0c989c32a726fba15c32296c8b7a9d6c4 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:150196224 2026-04-20T17:45:17.081 [Cloud] End of cloud request. 2026-04-20T17:45:17.081 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:45:17.174 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99ba0a09d1bc911801cedc65156d2cf1c148c699 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:50065408 2026-04-20T17:45:17.174 [Cloud] End of cloud request. 2026-04-20T17:45:17.174 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:45:17.221 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d82c0f9ac9458f091392a5850ee343cbbd1537c0 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:864000000 2026-04-20T17:45:17.221 [Cloud] End of cloud request. 2026-04-20T17:45:17.221 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:45:17.581 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T17:45:40.581 Bm signature throttled:0x00002db31bed458f 2026-04-20T17:47:16.565 [RTP] [Mini-filter] OpenWithoutRead notification (1160, 10001, \Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b24a55e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5c4a426 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdb5c7179 2026-04-20T17:47:51.034 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:47:51.034 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:47:51.034 [Cloud] Queued cloud request. 2026-04-20T17:47:51.034 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:47:51.034 [Cloud] Dequeued cloud request. 2026-04-20T17:47:51.034 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:47:51.034 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:47:51.034 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:47:51.034 [Cloud] Queued cloud request. 2026-04-20T17:47:51.034 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:47:51.034 [Cloud] Dequeued cloud request. 2026-04-20T17:47:51.034 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:47:51.065 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:47:51.065 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:47:51.065 [Cloud] Queued cloud request. 2026-04-20T17:47:51.065 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:47:51.065 [Cloud] Dequeued cloud request. 2026-04-20T17:47:51.065 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:47:51.518 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6e8857ed54dc2bd6273e01d921ab3dd9c95f9bce Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:288000000 2026-04-20T17:47:51.518 [Cloud] End of cloud request. 2026-04-20T17:47:51.518 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:47:51.628 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e4cbcc83926e7f0a6f747bd17f4a16b16b3db74d Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:150196224 2026-04-20T17:47:51.628 [Cloud] End of cloud request. 2026-04-20T17:47:51.628 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:47:51.628 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bb8689391a52b0d52f6b49c83594fb9b841642dd Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:150196224 2026-04-20T17:47:51.628 [Cloud] End of cloud request. 2026-04-20T17:47:51.628 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:47:52.018 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00009E61BBCAF801, sigsha=368f7e2a436a021e7c1810febc511ecdefdbfcde, cached=false, source=2, resourceid=0x7b91ac05 2026-04-20T17:48:24.049 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\Vbsedit\vbsedit.exe. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x9e61bbcaf801 Internal signature match:subtype=Lowfi, sigseq=0x00009E61BBCAF801, sigsha=368f7e2a436a021e7c1810febc511ecdefdbfcde, cached=true, source=2, resourceid=0x7b91ac05 2026-04-20T17:53:00.903 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-20T17:54:27.799 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\Documents\desktop.ini 2026-04-20T17:54:27.799 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-20T17:54:27.799 [RTP] Duplicating the current plugin configuration object... 2026-04-20T17:54:27.799 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T17:54:27.799 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-20T17:54:27.799 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-20T17:54:27.799 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-20T17:54:53.956 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\Program Files\desktop.ini Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2507f149 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x708f699e 2026-04-20T17:55:18.878 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T17:55:18.878 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T17:55:18.878 [Cloud] Queued cloud request. 2026-04-20T17:55:18.878 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T17:55:18.878 [Cloud] Dequeued cloud request. 2026-04-20T17:55:18.878 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T17:55:19.768 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\06be8c6887e9f6a154c0c4db72aafd679c637a26 Dynamic Signature Compilation Timestamp:04-20-2026 17:55:20 Persistence Type:Duration Time remaining:150196224 2026-04-20T17:55:19.768 [Cloud] End of cloud request. 2026-04-20T17:55:19.768 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T17:55:20.269 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb2d4992d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4800f287 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42c3467b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4800f287 2026-04-20T17:56:28.362 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-20T17:56:28.362 [RTP] Duplicating the current plugin configuration object... 2026-04-20T17:56:28.362 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T17:56:28.362 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-20T17:56:28.362 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T17:56:28.362 [RTP] No config change detected. Not updating plugin configuration. 2026-04-20T17:56:28.362 [RTP] No config changes found. No configuration switch. 2026-04-20T17:56:28.362 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-20T17:58:20.895 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T18:01:25.749 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11519, FileId: 0xc0000000bcf14, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T18:06:13.862 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x843ef6f3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5cd82058 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfdcafa44 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x43abd8b5 2026-04-20T18:13:25.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T18:16:04.440 Bm signature throttled:0x00002db31bed458f 2026-04-20T18:22:48.907 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11832, FileId: 0x150000000ba529, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T18:28:30.907 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T18:29:10.857 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12050, FileId: 0x170000000bcf15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T18:29:22.441 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\EBF713A3-C213-42B9-A1F1-7CD7D60EE1C01f68.1dcd0f39ad6709e 2026-04-20T18:29:22.519 Verifying engine and signature files (source: 0) ... 2026-04-20T18:29:22.519 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpengine.dll] due to PPL. 2026-04-20T18:29:22.519 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasbase.vdm] (file in cache) 2026-04-20T18:29:22.519 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-20T18:29:22.535 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasdlta.vdm] 2026-04-20T18:29:22.535 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpavbase.vdm] (file in cache) 2026-04-20T18:29:22.535 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-20T18:29:22.550 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpavdlta.vdm] 2026-04-20T18:29:22.707 [Engine] IsHybridMode: 0 2026-04-20T18:29:22.707 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T18:29:22.722 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-46A4FAF2A4BD10F5FEB177B070FA12F40FE99BC9.bin): 0x00000002 2026-04-20T18:29:22.722 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-46A4FAF2A4BD10F5FEB177B070FA12F40FE99BC9.bin) 2026-04-20T18:29:22.722 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-20T18:29:22.722 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-20T18:29:22.722 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-20T18:29:22.722 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T18:29:34.461 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T18:29:34.461 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T18:29:34.461 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF94F088020, lRefCount: 5, hr=0 2026-04-20T18:29:34.461 [Engine] New active engine 00007FF921248020 replacing engine 00007FF94F088020. Number of active engines: 2 2026-04-20T18:29:34.477 EngineInit:Global ASOC is enabled 2026-04-20T18:29:34.477 EngineInit:ASOO is enabled for developer volumes 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T18:29:34.539 MpWriteUupSignatureVersion 1.449.209.0, hr = 0 2026-04-20T18:29:34.539 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T18:29:34.555 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T18:29:34.570 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T18:29:34.570 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T18:29:34.570 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T18:29:34.570 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T18:29:34.586 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T18:29:34.586 [Plugin] Initializing RTP plugin state... 2026-04-20T18:29:34.586 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T18:29:34.586 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎20‎-‎2026 19:03:28 Last Perf:‎04‎-‎20‎-‎2026 19:03:28 First RTP Scan:‎04‎-‎20‎-‎2026 19:03:29 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1211 Misses:5362 BM Queue:0,248,0 Proc:0,207,0 File:0,96,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:12157 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:59502447 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:9929 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:42213 TotalHits:97611 InstanceCacheInserts:999 InstanceCacheUpdates:0 InstanceCacheDeletes:524 InstanceCacheHits:156 InstanceCacheMisses:13421 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (499/350) Success: 350, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T18:29:34.586 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9} 2026-04-20T18:29:34.586 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C}\mpasbase.vdm in use, hr=0x80070020 2026-04-20T18:29:34.586 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5947652E-6BF2-4837-A7AA-957906C8C85A} removed 2026-04-20T18:29:34.586 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T18:29:34.586 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.586 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.586 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.586 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.586 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-20-2026 18:29:34 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 18:29:34 2026-04-20T18:29:34.586 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T18:29:34.586 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T18:29:34.602 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T18:29:34.602 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T18:29:34.602 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T18:29:34.602 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.602 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.602 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.602 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T18:29:34.602 MdCoreSvc is supported in this platform and OS Signature updated on 04-20-2026 18:29:34 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.209.0 AV Signature Version: 1.449.209.0 ************************************************************ 2026-04-20T18:29:34.602 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-20T18:29:34.602 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\EBF713A3-C213-42B9-A1F1-7CD7D60EE1C01f68.1dcd0f39ad6709e 2026-04-20T18:29:34.617 Process scan (postsignatureupdatescan) started. 2026-04-20T18:29:34.695 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T18:29:34.695 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T18:29:35.008 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T18:29:35.008 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T18:29:35.008 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T18:29:35.008 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T18:29:35.008 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T18:29:35.008 [Engine] Engine 00007FF94F088020 no longer in use. Number of active engines: 1 2026-04-20T18:29:35.008 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T18:29:35.008 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-20T18:29:35.055 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T18:29:35.055 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T18:29:35.055 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T18:29:35.133 ProcessImageName: explorer.exe, Pid: 6396, TotalTime: 15178, Count: 189, MaxTime: 1781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-20T18:29:35.133 ProcessImageName: AcroCEF.exe, Pid: 11908, TotalTime: 3847, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 31% 2026-04-20T18:29:35.133 ProcessImageName: xbootvs1.0beta14.exe, Pid: 6312, TotalTime: 1380, Count: 187, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 41% 2026-04-20T18:29:35.133 ProcessImageName: notepad++.exe, Pid: 2592, TotalTime: 769, Count: 49, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-20T18:29:35.133 ProcessImageName: svchost.exe, Pid: 8148, TotalTime: 702, Count: 2, MaxTime: 687, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 15% 2026-04-20T18:29:35.133 ProcessImageName: vbsedit.exe, Pid: 15288, TotalTime: 691, Count: 26, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\Vbsedit\vbsedit32.dll, EstimatedImpact: 62% 2026-04-20T18:29:35.133 ProcessImageName: WmiPrvSE.exe, Pid: 12080, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\refs.sys, EstimatedImpact: 88% 2026-04-20T18:29:35.133 ProcessImageName: svchost.exe, Pid: 6976, TotalTime: 530, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume8\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T18:29:35.133 ProcessImageName: xampp-control.exe, Pid: 5472, TotalTime: 230, Count: 7, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume7\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 0% 2026-04-20T18:29:35.133 ProcessImageName: AdobeCollabSync.exe, Pid: 3664, TotalTime: 196, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\collab_low\6b60e77b-3787-4a72-aa25-234dd03eb1f1_temp.zip, EstimatedImpact: 0% 2026-04-20T18:29:35.133 ProcessImageName: backgroundTaskHost.exe, Pid: 12224, TotalTime: 180, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 11% 2026-04-20T18:29:35.133 ProcessImageName: TabTip.exe, Pid: 3976, TotalTime: 170, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 99% 2026-04-20T18:29:35.133 ProcessImageName: dllhost.exe, Pid: 13708, TotalTime: 150, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\Public\desktop.ini, EstimatedImpact: 3% 2026-04-20T18:29:35.133 ProcessImageName: Notepad.exe, Pid: 8000, TotalTime: 137, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 0% 2026-04-20T18:29:35.180 [Engine] RSIG_UNLOADENGINE, 00007FF94F088020, err=0x0 2026-04-20T18:29:35.195 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{08AC4527-75B4-4D4A-BF6F-0BFA64530F2C} removed 2026-04-20T18:29:36.602 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T18:29:36.617 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T18:29:36.617 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-20T18:29:52.695 Process scan (postsignatureupdatescan) completed. 2026-04-20T18:34:34.485 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T18:43:35.902 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T18:48:52.110 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13040, FileId: 0x89000000004cc8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T18:48:57.755 Bm signature throttled:0x00002db31bed458f 2026-04-20T18:48:58.801 Bm signature throttled:0x00002db31bed458f 2026-04-20T18:48:59.238 Engine:Process 692 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-20T18:53:01.096 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13641, FileId: 0x190000000ba54e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T18:58:40.909 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T18:59:46.065 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15129, FileId: 0xfd000000002f4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T19:01:40.299 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #15205, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T19:13:45.900 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T19:13:53.155 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15406, FileId: 0x55000000004e39, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T19:28:50.906 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T19:43:55.899 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T19:59:00.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T20:14:05.894 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T20:19:15.893 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5670ccc 2026-04-20T20:29:10.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T20:29:34.469 ProcessImageName: explorer.exe, Pid: 6396, TotalTime: 5647, Count: 144, MaxTime: 1375, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: svchost.exe, Pid: 8216, TotalTime: 561, Count: 3, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: WmiPrvSE.exe, Pid: 15136, TotalTime: 511, Count: 66, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\compositebus.inf->(UTF-16LE), EstimatedImpact: 15% 2026-04-20T20:29:34.469 ProcessImageName: TabTip.exe, Pid: 3268, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-20T20:29:34.469 ProcessImageName: mmc.exe, Pid: 3544, TotalTime: 108, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 9% 2026-04-20T20:29:34.469 ProcessImageName: SDXHelper.exe, Pid: 5488, TotalTime: 106, Count: 13, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0D313E3-E137-411E-AF44-E7B38EF7163E, EstimatedImpact: 16% 2026-04-20T20:29:34.469 ProcessImageName: cmd.exe, Pid: 5308, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: OfficeC2RClient.exe, Pid: 6232, TotalTime: 91, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 3% 2026-04-20T20:29:34.469 ProcessImageName: xampp-control.exe, Pid: 11816, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: svchost.exe, Pid: 1476, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 7% 2026-04-20T20:29:34.469 ProcessImageName: OfficeC2RClient.exe, Pid: 2148, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2059.log, EstimatedImpact: 2% 2026-04-20T20:29:34.469 ProcessImageName: svchost.exe, Pid: 3432, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1b22f6bc141e8f5efca9e524a43bbb948a733dfe\content.phf, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: dllhost.exe, Pid: 5416, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: FileZilla Server Interface.exe, Pid: 2744, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: OfficeC2RClient.exe, Pid: 13204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2113.log, EstimatedImpact: 1% 2026-04-20T20:29:34.469 ProcessImageName: FileZilla Server Interface.exe, Pid: 5344, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: TeamViewer.exe, Pid: 6844, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 5% 2026-04-20T20:29:34.469 ProcessImageName: AdobeCollabSync.exe, Pid: 3664, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: OfficeC2RClient.exe, Pid: 13756, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2052.log, EstimatedImpact: 0% 2026-04-20T20:29:34.469 ProcessImageName: AggregatorHost.exe, Pid: 5324, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T20:29:44.213 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18810, FileId: 0xad0000000046db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:44:15.898 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19370, FileId: 0x9600000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19372, FileId: 0x9700000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19374, FileId: 0xce000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19371, FileId: 0xcd000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19373, FileId: 0x9800000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.130 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19376, FileId: 0x9900000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.146 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19375, FileId: 0xcf000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.146 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19378, FileId: 0x9a00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.146 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19379, FileId: 0x59000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.162 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19381, FileId: 0xd2000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.162 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19383, FileId: 0xd4000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.162 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19384, FileId: 0x9e00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.162 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19377, FileId: 0xd0000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.177 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19382, FileId: 0x9d00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.177 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19387, FileId: 0xd6000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.177 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19385, FileId: 0xd5000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.615 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19436, FileId: 0xa600000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.615 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19438, FileId: 0xa700000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.615 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19434, FileId: 0xa500000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.615 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19439, FileId: 0xdc000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19441, FileId: 0xdd000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19442, FileId: 0xde000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19444, FileId: 0xa900000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19440, FileId: 0xa800000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19435, FileId: 0xdb000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.630 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19446, FileId: 0xaa00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19452, FileId: 0xac00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19456, FileId: 0xad00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19453, FileId: 0xe1000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19455, FileId: 0xe2000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19460, FileId: 0xae00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19465, FileId: 0xaf00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19467, FileId: 0xb000000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19468, FileId: 0xe6000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19466, FileId: 0xe5000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.927 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19499, FileId: 0x810000000047ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.927 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19501, FileId: 0x820000000047ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.927 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19502, FileId: 0xb400000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.927 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19498, FileId: 0x5b000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:40.927 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19500, FileId: 0xb300000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:41.787 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19584, FileId: 0x850000000047ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:41.787 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19583, FileId: 0xb600000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:54:42.849 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\d091c48b-7bd0-4cea-a710-f1b5f1c7d245. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #19678, FileId: 0xc400000000464f, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T20:59:20.903 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T21:14:25.903 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x627ab259 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbfc9fa03 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe3e0bb99 2026-04-20T21:26:23.706 Bm signature throttled:0x00002db31bed458f 2026-04-20T21:29:30.904 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc1b4bdd0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5670ccc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb3f26246 2026-04-20T21:39:20.429 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22101, FileId: 0x470000000050e2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T21:44:35.900 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T21:46:44.436 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22742, FileId: 0x4a0000000050e2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T21:54:07.143 Bm signature throttled:0x00002db31bed458f 2026-04-20T21:59:40.894 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf4e7207d 2026-04-20T22:02:10.659 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-20T22:02:10.659 [Cloud] Start of cloud request. Passive mode: 0 2026-04-20T22:02:10.659 [Cloud] Queued cloud request. 2026-04-20T22:02:10.659 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-20T22:02:10.659 [Cloud] Dequeued cloud request. 2026-04-20T22:02:10.659 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-20T22:02:11.034 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6c0bfa799a49c01ca1118735aed319c8ba59e577 Dynamic Signature Compilation Timestamp:04-20-2026 22:02:12 Persistence Type:Duration Time remaining:50065408 2026-04-20T22:02:11.034 RTSD:RTSD recieved, rescanning impacted resources 2026-04-20T22:02:11.034 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0c4c2f76 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x0c4c2f76 2026-04-20T22:02:11.549 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=5, resourceid=0xdeab029e Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=5, resourceid=0x9606fc04 2026-04-20T22:14:45.893 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T22:17:36.502 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.502 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.565 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.565 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.612 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.612 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.659 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.659 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.674 Engine:EMS scan for process: pid_6396 pid: 6396, sigseq: 0x0, sendMemoryScanReport: 0, source: 8 2026-04-20T22:17:36.706 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.706 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.752 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.752 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.799 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.799 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.846 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.846 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.893 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.893 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.987 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:36.987 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.049 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.049 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.081 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.081 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.143 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.143 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.190 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.190 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.237 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.237 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.284 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.284 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.331 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.331 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.377 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.377 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.424 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.424 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.471 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.471 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.518 mp.TriggerScanResource(0x00000008, process, pid:6396), delay = 0 from 0x002010bd9cc67d2f 2026-04-20T22:17:37.518 mp.TriggerScanResource(0x00000008, ems, pid:6396), delay = 0 from 0x002010bd9cc67d2f Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xab584236 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0xdd021ec8 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x9d99a7c3 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x3d507d66 Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x7f8bfa4e Internal signature match:subtype=Lowfi, sigseq=0x00002029EE42DDC7, sigsha=f5c3aee0a4850e373f8e84843c1322a2b76a074b, cached=false, source=5, resourceid=0x55ac6675 Internal signature match:subtype=Lowfi, sigseq=0x00001A2985E55790, sigsha=88cbf2a3b3bf6b6a86b3ca3d8c024e1f4a6f32b9, cached=false, source=5, resourceid=0x8ad869bf 2026-04-20T22:25:58.706 Bm signature throttled:0x00002db31bed458f 2026-04-20T22:29:34.500 ProcessImageName: explorer.exe, Pid: 6396, TotalTime: 304329, Count: 50326, MaxTime: 1718, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp-portable-windows-x64-8.1.4-1-VS16\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 2% 2026-04-20T22:29:34.500 ProcessImageName: firefox.exe, Pid: 13008, TotalTime: 2402, Count: 246, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 66% 2026-04-20T22:29:34.500 ProcessImageName: svchost.exe, Pid: 6976, TotalTime: 1404, Count: 6, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: php.exe, Pid: 6496, TotalTime: 732, Count: 72, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 17% 2026-04-20T22:29:34.500 ProcessImageName: svchost.exe, Pid: 8216, TotalTime: 701, Count: 4, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: WmiPrvSE.exe, Pid: 15136, TotalTime: 511, Count: 66, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\compositebus.inf->(UTF-16LE), EstimatedImpact: 15% 2026-04-20T22:29:34.500 ProcessImageName: Notepad.exe, Pid: 14244, TotalTime: 213, Count: 23, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialogGroup.xbf, EstimatedImpact: 1% 2026-04-20T22:29:34.500 ProcessImageName: mmc.exe, Pid: 3336, TotalTime: 185, Count: 8, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[2], EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: awk.exe, Pid: 1588, TotalTime: 181, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\pciconf, EstimatedImpact: 89% 2026-04-20T22:29:34.500 ProcessImageName: xampp-control.exe, Pid: 7520, TotalTime: 170, Count: 3, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: TabTip.exe, Pid: 3268, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-20T22:29:34.500 ProcessImageName: httpd.exe, Pid: 4080, TotalTime: 151, Count: 64, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 14% 2026-04-20T22:29:34.500 ProcessImageName: svchost.exe, Pid: 1476, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: Notepad.exe, Pid: 11316, TotalTime: 135, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8798426f-49af-4c5e-960d-c26db8da228e.1.bin, EstimatedImpact: 20% 2026-04-20T22:29:34.500 ProcessImageName: PhoneExperienceHost.exe, Pid: 8416, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-04-20T22:29:34.500 ProcessImageName: mmc.exe, Pid: 3544, TotalTime: 108, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 9% 2026-04-20T22:29:34.501 ProcessImageName: SDXHelper.exe, Pid: 5488, TotalTime: 106, Count: 13, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0D313E3-E137-411E-AF44-E7B38EF7163E, EstimatedImpact: 16% 2026-04-20T22:29:34.501 ProcessImageName: cmd.exe, Pid: 5308, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 6232, TotalTime: 91, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 3% 2026-04-20T22:29:34.501 ProcessImageName: xampp-control.exe, Pid: 11816, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: Notepad.exe, Pid: 14084, TotalTime: 90, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\94295083-b6f2-482c-bb7e-2024e8e3efcb.0.bin, EstimatedImpact: 6% 2026-04-20T22:29:34.501 ProcessImageName: xampp-control.exe, Pid: 8656, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 11% 2026-04-20T22:29:34.501 ProcessImageName: xampp-control.exe, Pid: 14416, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: xampp-control.exe, Pid: 12692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: dllhost.exe, Pid: 5416, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: Notepad.exe, Pid: 10876, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\80c1c5f8-b2df-4243-8b51-2cca0fc038c6.bin, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: Notepad.exe, Pid: 8068, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\2f32eab5-d4c1-4394-8b17-06ccf15998ad.0.bin, EstimatedImpact: 8% 2026-04-20T22:29:34.501 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 7% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 2148, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2059.log, EstimatedImpact: 2% 2026-04-20T22:29:34.501 ProcessImageName: svchost.exe, Pid: 3432, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1b22f6bc141e8f5efca9e524a43bbb948a733dfe\content.phf, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: FileZilla Server Interface.exe, Pid: 2744, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 10736, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2229.log, EstimatedImpact: 1% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 13820, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2346.log, EstimatedImpact: 1% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 7888, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2339.log, EstimatedImpact: 1% 2026-04-20T22:29:34.501 ProcessImageName: OfficeC2RClient.exe, Pid: 13204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2113.log, EstimatedImpact: 1% 2026-04-20T22:29:34.501 ProcessImageName: FileZilla Server Interface.exe, Pid: 5344, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\FILEZILLA SERVER INTERFACE.EX-93310CB6.pf, EstimatedImpact: 0% 2026-04-20T22:29:34.501 ProcessImageName: TeamViewer.exe, Pid: 6844, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 5% 2026-04-20T22:29:34.502 ProcessImageName: AggregatorHost.exe, Pid: 5324, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-20T22:29:34.502 ProcessImageName: AdobeCollabSync.exe, Pid: 3664, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-20T22:29:34.502 ProcessImageName: mmc.exe, Pid: 11864, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-20T22:29:34.502 ProcessImageName: mmc.exe, Pid: 5496, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 0% 2026-04-20T22:29:34.502 ProcessImageName: OfficeC2RClient.exe, Pid: 13756, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260420-2052.log, EstimatedImpact: 0% 2026-04-20T22:29:50.905 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T22:44:55.902 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T22:46:25.225 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #75354, FileId: 0x1500000003a8d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.545 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75398, FileId: 0xbd00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.545 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75397, FileId: 0x5e000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.545 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75399, FileId: 0x60000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.545 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75400, FileId: 0x62000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.568 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75401, FileId: 0xbe00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.568 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75405, FileId: 0x66000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.568 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75406, FileId: 0xc300000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.577 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75402, FileId: 0xbf00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.577 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75404, FileId: 0xc000000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.577 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75407, FileId: 0x67000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.593 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75408, FileId: 0xc400000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.593 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75411, FileId: 0xc600000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.593 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75412, FileId: 0xc700000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:04.593 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #75409, FileId: 0x68000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:49:05.032 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\f53b7deb-a6c7-45f3-a97b-e33e2a2eb755. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #75451, FileId: 0x3d0000000461ab, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:53:13.299 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #75948, FileId: 0x600000000ff31, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T22:54:11.437 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #76015, FileId: 0x5c0000000037f0, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-20-2026 23:04:57 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/20/2026 23:04:57.545742500 UTC (16265 ms since boot) 2026-04-20T23:04:57.570 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-20T23:04:57.575 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T23:04:57.575 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T23:04:57.623 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260420-230457-00000003-fffffffeffffffff.bin ... 2026-04-20T23:04:57.711 [WPP] Trace session started - MpWppTracing-20260420-230457-00000003-fffffffeffffffff.bin 2026-04-20T23:04:57.721 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-20T23:04:57.721 [RbM] Rollback manager succesfully initialized. 2026-04-20T23:04:57.721 [RbM] Rollback manager EnableRollbackManager called. 2026-04-20T23:04:57.726 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-20T23:04:57.726 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-20T23:04:57.726 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-20T23:04:57.726 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-20T23:04:57.731 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-20T23:04:57.731 MdCoreSvc is supported in this platform and OS 2026-04-20T23:04:57.731 MdCoreSvc is supported in this platform and OS 2026-04-20T23:04:57.731 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T23:04:57.735 [PlatUpd] Starting MdCoreSvc service 2026-04-20T23:04:57.770 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-20T23:05:02.283 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-20T23:05:02.283 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-20T23:05:02.283 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-20T23:05:02.283 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-20T23:05:02.283 [PlatUpd] CSP platform update started 2026-04-20T23:05:02.283 [PlatUpd] Defender MDM CSP platform update not required 2026-04-20T23:05:02.283 [PlatUpd] WMI/PS provider platform update started 2026-04-20T23:05:02.283 [PlatUpd] WMI/PS provider platform update not required 2026-04-20T23:05:02.283 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-20T23:05:02.283 MdCoreSvc is supported in this platform and OS 2026-04-20T23:05:02.283 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-20T23:05:02.283 [PlatUpd] Starting MdCoreSvc service 2026-04-20T23:05:02.283 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-20T23:05:02.283 [TS] Troublshooting mode is not available! 2026-04-20T23:05:02.283 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T23:05:02.283 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-20T23:05:02.315 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-20T23:05:02.315 [Service] Enabling AutoLoggers ... 2026-04-20T23:05:02.315 [Service] Enabling AMSI registration ... 2026-04-20T23:05:02.315 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-20T23:05:02.330 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52282 Number of invalid entries is 0 Number of inserts issued is 1572934 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6384 Number of lookups is 106923122 Number of lookup misses is 5121475 Number of fast lookup misses is 54562326 Number of false fast lookups is 5121470 Number of invalidations is 728951 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-20T23:05:02.330 Verifying license file... 2026-04-20T23:05:02.330 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-20T23:05:02.346 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-20T23:05:02.346 Loaded module#0 MpComServer. 2026-04-20T23:05:02.346 Loaded module#1 StartupPolicies. 2026-04-20T23:05:02.346 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-20T23:05:02.362 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T23:05:02.362 COM server initialized successfully. 2026-04-20T23:05:02.362 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-20T23:05:02.377 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-20T23:05:02.377 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-20T23:05:02.393 [RTP] [RTP] FilterCommunicator object 0x000001F3B94944C0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T23:05:02.393 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-20T23:05:02.393 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T23:05:02.393 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T23:05:02.393 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-20T23:05:02.393 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-20T23:05:02.393 [RTP] [RTP] FilterCommunicator object 0x000001F3B94946D0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T23:05:02.393 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-20T23:05:02.393 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-20T23:05:02.393 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-20T23:05:02.393 [RTP] [RTP] StartCommunication 0x000001F3B94944C0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-20T23:05:02.393 [init][RTP] RTPPlugin initialization completed 2026-04-20T23:05:02.393 OS boot count = 2 2026-04-20T23:05:02.393 OS Install = 0 2026-04-20T23:05:02.455 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-20T23:05:02.455 [KSL] Entering CKSLEngine::Initialize. 2026-04-20T23:05:02.455 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-20T23:05:02.455 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-20T23:05:02.455 [KSL] MpInstallKslD: hr=0x1 2026-04-20T23:05:02.455 [KSL] MpRegisterKslD: hr=0 2026-04-20T23:05:02.455 [KSL] MpStartKslD: hr=0 2026-04-20T23:05:02.455 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T23:05:02.455 Loading engine... 2026-04-20T23:05:02.471 Verifying engine and signature files (source: 1) ... 2026-04-20T23:05:02.471 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpengine.dll] due to PPL. 2026-04-20T23:05:02.471 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasbase.vdm] (file in cache) 2026-04-20T23:05:02.471 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasdlta.vdm] (file in cache) 2026-04-20T23:05:02.471 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpavbase.vdm] (file in cache) 2026-04-20T23:05:02.471 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpavdlta.vdm] (file in cache) 2026-04-20T23:05:02.518 [Engine] IsHybridMode: 0 2026-04-20T23:05:02.518 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T23:05:02.549 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-46A4FAF2A4BD10F5FEB177B070FA12F40FE99BC9.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T23:05:19.181 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T23:05:19.182 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T23:05:19.183 [Engine] New active engine 00007FFFAA168020 (no old engine). Number of active engines: 1 2026-04-20T23:05:19.203 EngineInit:Global ASOC is enabled 2026-04-20T23:05:19.203 EngineInit:ASOO is enabled for developer volumes 2026-04-20T23:05:19.472 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T23:05:19.473 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.473 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T23:05:19.473 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.474 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.496 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.497 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.498 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.501 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.501 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:05:19.501 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b543d929a24da961038626fd151e6824bb556d2e Dynamic Signature Compilation Timestamp:04-18-2026 22:36:20 Persistence Type:Duration Time remaining:1728000000 2026-04-20T23:05:19.613 MpWriteUupSignatureVersion 1.449.209.0, hr = 0 2026-04-20T23:05:19.617 [SigStatUpd] CSignatureStatus: back to good 2026-04-20T23:05:19.618 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T23:05:19.638 Dynamic signature dropped 2026-04-20T23:05:19.699 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T23:05:19.699 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T23:05:19.699 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T23:05:19.699 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T23:05:19.794 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T23:05:19.794 [Plugin] Initializing RTP plugin state... 2026-04-20T23:05:19.795 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T23:05:19.795 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9} 2026-04-20T23:05:19.797 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:05:19.797 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:05:19.797 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:05:19.797 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T23:05:19.798 MdCoreSvc is supported in this platform and OS 2026-04-20T23:05:19.798 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T23:05:19.798 Engine loaded! 2026-04-20T23:05:19.799 [DLP] Create FeatureControlState instance 2026-04-20T23:05:19.816 RegisterSModeChangeListener: hr = 0x1 2026-04-20T23:05:19.816 RegisterHybridModeChangeListener: hr = 0 2026-04-20T23:05:19.829 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:2,2,0 SetEngine:1,1,0 SetState:1,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3712 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18508 TotalHits:0 InstanceCacheInserts:41 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3924 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T23:05:19.855 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-20T23:05:19.855 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-20T23:05:19.878 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-20T23:05:19.878 [SigReleaseHb] Initialized with Stage 0 2026-04-20T23:05:19.878 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-20T23:05:19.879 [SCC][CID=38593_5516] Initializing ... 2026-04-20T23:05:19.879 [SCC][CID=38593_5516] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-20T23:05:19.882 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T23:05:19.882 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T23:05:19.889 [NRI] Stopping NIS service ... 2026-04-20T23:05:19.889 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-20T23:05:19.889 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.209.0 AV Signature Version: 1.449.209.0 ************************************************************ 2026-04-20T23:05:19.891 Resource usage Monitoring is enabled 2026-04-20T23:05:19.893 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-20T23:05:19.957 Job Notification: New process added to job (4436) 2026-04-20T23:05:19.957 Job Notification: New process added to job (8372) 2026-04-20T23:05:19.987 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T23:05:20.011 Job Notification: New process added to job (8380) 2026-04-20T23:05:20.132 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:8372] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8380]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T23:05:20.290 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T23:05:20.290 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T23:05:20.290 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T23:05:20.398 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T23:05:20.418 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-20T23:05:20.438 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T23:05:20.438 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T23:05:20.439 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T23:05:20.439 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T23:05:20.439 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T23:05:20.439 [RTP] Generating the base plugin configuration ... 2026-04-20T23:05:20.439 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-20T23:05:20.440 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T23:05:20.440 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-20T23:05:20.451 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-20T23:05:20.451 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T23:05:20.451 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T23:05:20.460 [RTP] [RTP] StartCommunication 0x000001F3B94946D0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-20T23:05:20.480 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-20T23:05:20.713 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16 2026-04-20T23:05:20.932 Job Notification: Process exited from job (8372) 2026-04-20T23:05:20.932 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T23:05:20.969 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-20T23:05:21.016 Job Notification: Process exited from job (8380) 2026-04-20T23:05:23.512 [RTP] Duplicating the current plugin configuration object... 2026-04-20T23:05:23.512 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T23:05:23.512 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-20T23:05:23.515 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T23:05:23.516 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-20T23:05:31.133 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #965, FileId: 0x4e00000000ce8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF068315B, sigsha=3b4863129d0d1afbcbee84275299c87de3d6d4ee, cached=false, source=2, resourceid=0x16b61975 2026-04-20T23:05:58.262 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.46819220#\ede075794b94571fdaa9236b687f600e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.ni.dll. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x157ef068315b 2026-04-20T23:06:02.356 Process scan (poststartupscan) started. 2026-04-20T23:06:02.356 Process scan (poststartupscan) completed. 2026-04-20T23:06:02.840 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-20T23:06:02.856 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-20T23:06:05.434 [RTP] Duplicating the current plugin configuration object... 2026-04-20T23:06:05.434 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-20T23:06:05.434 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-20T23:06:05.434 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-20T23:06:05.434 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-20T23:06:31.225 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2996, FileId: 0x28a0000000004a8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:06:59.829 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T23:06:59.829 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T23:06:59.829 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T23:10:00.418 Bm signature throttled:0x00002db31bed458f 2026-04-20T23:10:03.391 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4080, FileId: 0xbd00000001b3dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:10:18.724 Bm signature throttled:0x00002db31bed458f 2026-04-20T23:10:19.239 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T23:10:19.880 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T23:15:19.879 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-20T23:15:19.879 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-20T23:15:19.911 Job Notification: New process added to job (12428) 2026-04-20T23:15:19.926 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-20T23:15:19.926 Job Notification: New process added to job (5160) 2026-04-20T23:15:19.942 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:12428] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5160]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T23:15:19.989 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 7492316(ms) from now at 03:20 (01:20 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-20T23:15:20.020 Job Notification: New process added to job (948) 2026-04-20T23:15:20.036 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-20T23:15:20.036 Job Notification: New process added to job (11312) 2026-04-20T23:15:20.036 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:948] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11312]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-20T23:15:23.223 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4919, FileId: 0x1500000001c0d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:15:41.400 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\BFCBC121-5095-4C33-A217-E1D0415BB34A11d4.1dcd11b9a4ae3b9 2026-04-20T23:15:41.479 Verifying engine and signature files (source: 0) ... 2026-04-20T23:15:41.479 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpengine.dll] due to PPL. 2026-04-20T23:15:41.479 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpasbase.vdm] (file in cache) 2026-04-20T23:15:41.479 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-20T23:15:41.494 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpasdlta.vdm] 2026-04-20T23:15:41.494 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpavbase.vdm] (file in cache) 2026-04-20T23:15:41.494 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-20T23:15:41.510 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpavdlta.vdm] 2026-04-20T23:15:41.666 [Engine] IsHybridMode: 0 2026-04-20T23:15:41.666 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-20T23:15:41.666 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3DD72A19692EA644D253C007DA0BDB8AB4E54E88.bin): 0x00000002 2026-04-20T23:15:41.682 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3DD72A19692EA644D253C007DA0BDB8AB4E54E88.bin) 2026-04-20T23:15:41.682 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-20T23:15:41.682 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-20T23:15:41.682 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-20T23:15:41.682 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-20T23:15:53.234 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-20T23:15:53.234 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-20T23:15:53.234 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFFAA168020, lRefCount: 5, hr=0 2026-04-20T23:15:53.234 [Engine] New active engine 00007FFF4B6A8020 replacing engine 00007FFFAA168020. Number of active engines: 2 2026-04-20T23:15:53.250 EngineInit:Global ASOC is enabled 2026-04-20T23:15:53.250 EngineInit:ASOO is enabled for developer volumes 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.312 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-20T23:15:53.328 MpWriteUupSignatureVersion 1.449.215.0, hr = 0 2026-04-20T23:15:53.328 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-20T23:15:53.343 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-20T23:15:53.343 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-20T23:15:53.343 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-20T23:15:53.343 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-20T23:15:53.343 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-20T23:15:53.359 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-20T23:15:53.359 [Plugin] Initializing RTP plugin state... 2026-04-20T23:15:53.359 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-20T23:15:53.359 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎21‎-‎2026 01:05:20 Last Perf:‎04‎-‎21‎-‎2026 01:05:19 First RTP Scan:‎04‎-‎21‎-‎2026 01:05:20 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1836 Misses:2955 BM Queue:0,260,0 Proc:0,117,0 File:0,160,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5014 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:11490346 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6933 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:27356 TotalHits:14072 InstanceCacheInserts:532 InstanceCacheUpdates:0 InstanceCacheDeletes:267 InstanceCacheHits:150 InstanceCacheMisses:8022 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (264/137) Success: 137, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-20T23:15:53.359 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599} 2026-04-20T23:15:53.359 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9}\mpasbase.vdm in use, hr=0x80070020 2026-04-20T23:15:53.359 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-20T23:15:53.359 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{720229DD-6C32-4D7F-8FD5-982FDD1D6D51} removed 2026-04-20T23:15:53.359 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.359 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.359 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.359 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.359 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-20-2026 23:15:53 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-20-2026 23:15:53 2026-04-20T23:15:53.375 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-20T23:15:53.375 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-20T23:15:53.375 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T23:15:53.375 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-20T23:15:53.375 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-20T23:15:53.375 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.375 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.375 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.375 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-20T23:15:53.375 MdCoreSvc is supported in this platform and OS Signature updated on 04-20-2026 23:15:53 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.215.0 AV Signature Version: 1.449.215.0 ************************************************************ 2026-04-20T23:15:53.375 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-20T23:15:53.375 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\BFCBC121-5095-4C33-A217-E1D0415BB34A11d4.1dcd11b9a4ae3b9 2026-04-20T23:15:53.453 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-20T23:15:53.453 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-20-2026 23:15:53 ************************************************************ 2026-04-20T23:15:53.484 Job Notification: Process exited from job (948) 2026-04-20T23:15:53.484 Job Notification: Process exited from job (11312) 2026-04-20T23:15:53.562 Job Notification: Process exited from job (12428) 2026-04-20T23:15:53.562 Job Notification: Process exited from job (5160) 2026-04-20T23:15:53.750 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-20T23:15:53.750 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-20T23:15:53.750 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-20T23:15:53.750 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-20T23:15:53.750 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-20T23:15:53.750 [Engine] Engine 00007FFFAA168020 no longer in use. Number of active engines: 1 2026-04-20T23:15:53.750 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-20T23:15:53.750 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-20T23:15:53.843 ProcessImageName: CCC.exe, Pid: 13628, TotalTime: 28842, Count: 568, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 46% 2026-04-20T23:15:53.843 ProcessImageName: AsPowerBar.exe, Pid: 13736, TotalTime: 2787, Count: 18, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 41% 2026-04-20T23:15:53.843 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-20T23:15:53.843 ProcessImageName: explorer.exe, Pid: 7784, TotalTime: 2621, Count: 12, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 4% 2026-04-20T23:15:53.843 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-20T23:15:53.843 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-20T23:15:53.843 ProcessImageName: MOM.exe, Pid: 8840, TotalTime: 1804, Count: 30, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 44% 2026-04-20T23:15:53.843 ProcessImageName: AISuite3.exe, Pid: 6928, TotalTime: 1463, Count: 20, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 6% 2026-04-20T23:15:53.843 ProcessImageName: svchost.exe, Pid: 10420, TotalTime: 1203, Count: 2, MaxTime: 625, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100% 2026-04-20T23:15:53.843 ProcessImageName: DipAwayMode.exe, Pid: 6916, TotalTime: 1100, Count: 24, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-04-20T23:15:53.843 ProcessImageName: websockify.exe, Pid: 8600, TotalTime: 882, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 47% 2026-04-20T23:15:53.843 ProcessImageName: svchost.exe, Pid: 3600, TotalTime: 781, Count: 2, MaxTime: 781, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-20T23:15:53.843 ProcessImageName: WhatsApp.Root.exe, Pid: 12272, TotalTime: 300, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-04-20T23:15:53.843 ProcessImageName: FileCoAuth.exe, Pid: 11564, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-20T23:15:53.843 ProcessImageName: PhoneExperienceHost.exe, Pid: 11920, TotalTime: 135, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-04-20T23:15:53.843 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-20T23:15:53.843 ProcessImageName: BackgroundTransferHost.exe, Pid: 4072, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\d30e50d7-9d7c-4453-8562-bb10b36e33db.up_meta_secure, EstimatedImpact: 36% 2026-04-20T23:15:53.843 ProcessImageName: backgroundTaskHost.exe, Pid: 10020, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\c_qvppge7as2g0b934o4siqob9\a_0gq4qh1s4gfdkif787q0kpua.def, EstimatedImpact: 42% 2026-04-20T23:15:53.875 [Engine] RSIG_UNLOADENGINE, 00007FFFAA168020, err=0x0 2026-04-20T23:15:53.890 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{45D75065-0C57-483C-839B-EDA2366FF1F9} removed 2026-04-20T23:15:55.375 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T23:15:55.375 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-20T23:15:55.375 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-20T23:16:02.364 Process scan (postsignatureupdatescan) started. 2026-04-20T23:16:20.233 Process scan (postsignatureupdatescan) completed. 2026-04-20T23:17:02.887 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj819287993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5559, FileId: 0xd4000000003cab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:02.903 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj755C0F968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5561, FileId: 0x15000000013ed1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:02.903 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0230DC94F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5553, FileId: 0x1f000000041d2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:02.919 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj01E7289FE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5564, FileId: 0x62000000040040, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:02.950 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj02778C90B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5570, FileId: 0x64000000040040, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:03.086 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB7931F995. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5578, FileId: 0x1e000000013ed1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:03.123 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjED97219F7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5591, FileId: 0x66000000040040, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:03.152 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAB10E3967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5593, FileId: 0x49000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:03.199 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj06C0B9920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5595, FileId: 0x2d000000048969, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:03.224 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4A89AC9B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5597, FileId: 0x42000000044515, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.137 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C7BFE92F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5622, FileId: 0x3300000001b3de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.175 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAEC1939FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5623, FileId: 0x51000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.189 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj804367911. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5624, FileId: 0x52000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.201 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5EA9AD97E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5625, FileId: 0x53000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.211 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF04DA39EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5626, FileId: 0x54000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.233 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB21585902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5627, FileId: 0x3a00000001b3de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.233 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj94D2C4911. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5628, FileId: 0x56000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.452 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDA707F9B8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5629, FileId: 0x540000000444b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.468 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDAEF88934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5630, FileId: 0x58000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.488 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB993C8913. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5632, FileId: 0x59000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.508 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF285409FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5634, FileId: 0x5a000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.555 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1625B698E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5637, FileId: 0x5b000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.571 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAA441190C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5638, FileId: 0x5c000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.594 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBD567199D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5639, FileId: 0x5d000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.619 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2DA8C99D0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5642, FileId: 0x5e000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.668 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C17209EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5648, FileId: 0x5f000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.696 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E16E6951. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5651, FileId: 0x60000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.707 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFEF438939. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5656, FileId: 0x61000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.739 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9CC066900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5661, FileId: 0x62000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.754 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAA6CF2954. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5662, FileId: 0x63000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.754 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF2CFA7974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5664, FileId: 0x64000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.770 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBC347E989. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5665, FileId: 0x65000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.785 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj24166F94C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5666, FileId: 0x5100000001b3de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.785 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2F6DED9BF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5667, FileId: 0x66000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.895 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3DEB3F924. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5671, FileId: 0x560000000444b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.910 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj72F07C909. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5673, FileId: 0x68000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.926 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECF72394F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5674, FileId: 0x69000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.942 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj63EAFC9D9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5675, FileId: 0x6a000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:04.957 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj603FC2934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5676, FileId: 0x6b000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:05.004 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB5C3CC975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5678, FileId: 0x570000000444b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:05.020 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBB7F0790D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5680, FileId: 0x6d000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:05.035 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF3768E957. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5681, FileId: 0x6e000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:05.051 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj66029199C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5682, FileId: 0x6f000000041df6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:17.467 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5788, FileId: 0x4200000001c58a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:17.529 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5790, FileId: 0x380000000335e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:17:17.717 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5796, FileId: 0x290000000396d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:18:17.838 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5803, FileId: 0x1a000000010075, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:20:04.268 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #5880, FileId: 0xf600000001b22b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:20:53.276 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-20T23:25:24.888 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T23:27:17.807 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5919, FileId: 0x1d000000010075, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:27:17.822 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5921, FileId: 0x3200000003356b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-20T23:40:29.888 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-20T23:55:34.880 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T00:05:19.886 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-21T00:10:39.880 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T00:25:44.892 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T00:40:49.891 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T00:55:54.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T01:04:53.837 [AutoPurge] Verification Routine tasks have started. 2026-04-21T01:04:53.837 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-21T01:04:53.837 [AutoPurge] Cleanup Routine tasks have started. 2026-04-21T01:04:53.837 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-21T01:04:53.837 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-21T01:04:53.837 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-21T01:04:53.837 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-21T01:04:53.837 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-21T01:04:53.837 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-21T01:04:53.853 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:D87F1C5A-6448-4D3A-BF42-FE37CD7B7066, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-21T01:04:53.853 Scheduled scan with Id D87F1C5A-6448-4D3A-BF42-FE37CD7B7066 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-21T01:04:53.853 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-21T01:04:53.853 [SFC] System file cache build is not needed (already completed) 2026-04-21T01:04:53.868 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-21T01:04:53.868 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-21T01:04:53.868 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-21-2026 01:04:53 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-21-2026 01:04:53 2026-04-21T01:04:53.884 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-21T01:04:53.884 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-21T01:04:53.884 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-21T01:04:53.884 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-21T01:04:53.900 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-21T01:04:54.056 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-21T01:04:54.056 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-21T01:04:54.087 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-21T01:04:54.103 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-21T01:04:54.103 [AutoPurge] Verification Routine tasks have ended. 2026-04-21T01:04:55.853 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T01:04:55.869 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-21T01:04:55.869 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T01:05:20.541 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-21T01:05:20.557 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-21T01:05:20.557 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T01:05:20.557 [RTP] Duplicating the current plugin configuration object... 2026-04-21T01:05:20.557 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T01:05:20.557 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-21T01:05:20.557 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T01:05:20.557 [RTP] No config change detected. Not updating plugin configuration. 2026-04-21T01:05:20.557 [RTP] No config changes found. No configuration switch. 2026-04-21T01:05:20.557 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-21T01:05:20.557 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-21T01:05:20.557 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-21T01:05:20.557 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-21T01:05:20.557 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-21T01:05:20.557 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-21T01:05:20.557 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-21T01:05:20.557 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T01:05:20.572 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T01:05:20.572 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T01:05:20.635 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 83868319(ms) from now at 02:23 (00:23 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-21T01:05:23.135 [RTP] Duplicating the current plugin configuration object... 2026-04-21T01:05:23.135 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T01:05:23.135 [RTP] Updating plugin configuration due to recent config changes (0x41e) ... 2026-04-21T01:05:23.135 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-21T01:05:23.135 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x208 2026-04-21T01:05:29.016 Engine:Triggered AR EMS scan 2026-04-21T01:05:29.016 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.047 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.047 Engine:EMS scan for process: svchost pid: 920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.062 Engine:EMS scan for process: svchost pid: 1048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.062 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.062 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.062 Engine:EMS scan for process: svchost pid: 1340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1484, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.078 Engine:EMS scan for process: svchost pid: 1572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 1120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.094 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.109 Engine:EMS scan for process: svchost pid: 2524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.125 Engine:EMS scan for process: svchost pid: 2584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.125 Engine:EMS scan for process: svchost pid: 2640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.125 Engine:EMS scan for process: svchost pid: 2664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.125 Engine:EMS scan for process: svchost pid: 3004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.125 Engine:EMS scan for process: svchost pid: 2852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.141 Engine:EMS scan for process: svchost pid: 2864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.141 Engine:EMS scan for process: svchost pid: 3388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.141 Engine:EMS scan for process: svchost pid: 3392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.141 Engine:EMS scan for process: svchost pid: 3516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.141 Engine:EMS scan for process: svchost pid: 3576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.156 Engine:EMS scan for process: svchost pid: 3636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.156 Engine:EMS scan for process: svchost pid: 4012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.156 Engine:EMS scan for process: svchost pid: 4064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.172 Engine:EMS scan for process: svchost pid: 3344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.172 Engine:EMS scan for process: svchost pid: 3628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.172 Engine:EMS scan for process: svchost pid: 4116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.188 Engine:EMS scan for process: svchost pid: 4284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.188 Engine:EMS scan for process: svchost pid: 4336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.188 Engine:EMS scan for process: svchost pid: 4384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.188 Engine:EMS scan for process: svchost pid: 4444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.188 Engine:EMS scan for process: svchost pid: 5108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: svchost pid: 5796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: dllhost pid: 5176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: svchost pid: 5592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: svchost pid: 6520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: svchost pid: 6528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.203 Engine:EMS scan for process: svchost pid: 6600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.219 Engine:EMS scan for process: svchost pid: 6668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.219 Engine:EMS scan for process: svchost pid: 6740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.219 Engine:EMS scan for process: svchost pid: 6900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.219 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:05:29.219 Engine:EMS scan for process: svchost pid: 7024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.234 Engine:EMS scan for process: svchost pid: 4152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.234 Engine:EMS scan for process: svchost pid: 6808, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.234 Engine:EMS scan for process: svchost pid: 7452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.234 Engine:EMS scan for process: explorer pid: 7784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.281 Engine:EMS scan for process: svchost pid: 8084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.281 Engine:EMS scan for process: svchost pid: 7776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.281 Engine:EMS scan for process: svchost pid: 8208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.281 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:05:29.281 Engine:EMS scan for process: svchost pid: 9024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Engine:EMS scan for process: dllhost pid: 9300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:05:29.297 Engine:EMS scan for process: svchost pid: 9932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Engine:EMS scan for process: svchost pid: 11236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Engine:EMS scan for process: svchost pid: 10300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:05:29.297 Engine:EMS scan for process: svchost pid: 14012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.297 Engine:EMS scan for process: svchost pid: 3748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.313 Engine:EMS scan for process: svchost pid: 1604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.313 Engine:EMS scan for process: svchost pid: 11456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:05:29.328 Engine:EMS scan for process: svchost pid: 10328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-21T01:08:54.957 QuickScan:ScanID:D87F1C5A-6448-4D3A-BF42-FE37CD7B7066: Quick scan finished with error 0 2026-04-21T01:08:55.472 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-21T01:08:55.472 [RTP] Duplicating the current plugin configuration object... 2026-04-21T01:08:55.472 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T01:08:55.472 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-21T01:08:55.472 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T01:08:55.472 [RTP] No config change detected. Not updating plugin configuration. 2026-04-21T01:08:55.472 [RTP] No config changes found. No configuration switch. 2026-04-21T01:08:55.472 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-21T01:08:56.973 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T01:08:56.973 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-21T01:08:56.973 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T01:11:00.058 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T01:15:53.462 ProcessImageName: AcroCEF.exe, Pid: 1852, TotalTime: 3650, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-21T01:15:53.462 ProcessImageName: taskhostw.exe, Pid: 10012, TotalTime: 562, Count: 2, MaxTime: 531, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T01:15:53.462 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 241, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-21T01:15:53.462 ProcessImageName: SDXHelper.exe, Pid: 5676, TotalTime: 231, Count: 11, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 12% 2026-04-21T01:15:53.462 ProcessImageName: backgroundTaskHost.exe, Pid: 4260, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 10% 2026-04-21T01:15:53.462 ProcessImageName: Acrobat.exe, Pid: 2220, TotalTime: 181, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 26% 2026-04-21T01:15:53.462 ProcessImageName: SDXHelper.exe, Pid: 7224, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-21T01:15:53.462 ProcessImageName: AcroCEF.exe, Pid: 6872, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 57% 2026-04-21T01:15:53.462 ProcessImageName: AdobeARM.exe, Pid: 9980, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 8% 2026-04-21T01:15:53.462 ProcessImageName: AcroCEF.exe, Pid: 3848, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 41% 2026-04-21T01:15:53.462 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-21T01:15:53.462 ProcessImageName: Acrobat.exe, Pid: 6732, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 6% 2026-04-21T01:15:53.462 ProcessImageName: sihost.exe, Pid: 6628, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-04-21T01:15:53.462 ProcessImageName: svchost.exe, Pid: 11456, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T01:15:53.462 ProcessImageName: AggregatorHost.exe, Pid: 5276, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T01:15:53.462 ProcessImageName: brynhildr.exe, Pid: 3040, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-21T01:26:05.173 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T01:32:35.488 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C03C6989. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7431, FileId: 0x460000000185e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:35.535 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj08DEAA998. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7432, FileId: 0x1800000001a0fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:35.535 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5256B0931. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7433, FileId: 0x1900000001a0fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:37.177 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:32:37.177 Bm signature throttled:0x00002db31bed458f 2026-04-21T01:32:38.724 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF6CAB99DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7457, FileId: 0xa700000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:38.755 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj12E33C916. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7458, FileId: 0x4b0000000185e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:38.771 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj998102914. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7459, FileId: 0xab00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:50.464 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7477, FileId: 0x5b000000004ba0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:32:50.464 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7479, FileId: 0x4a00000000fbf7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:33:50.527 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7486, FileId: 0x5d000000004ba0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T01:41:10.245 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T01:56:15.313 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T02:00:04.071 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7762, FileId: 0x18100000000148f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T02:11:20.362 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T02:26:25.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T02:41:30.418 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T02:56:35.432 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T03:11:40.451 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T03:15:53.826 ProcessImageName: AcroCEF.exe, Pid: 1852, TotalTime: 3650, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-21T03:15:53.826 ProcessImageName: taskhostw.exe, Pid: 10012, TotalTime: 562, Count: 2, MaxTime: 531, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T03:15:53.826 ProcessImageName: powershell.exe, Pid: 1748, TotalTime: 431, Count: 30, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 39% 2026-04-21T03:15:53.826 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 346, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: SDXHelper.exe, Pid: 5676, TotalTime: 231, Count: 11, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 12% 2026-04-21T03:15:53.826 ProcessImageName: backgroundTaskHost.exe, Pid: 4260, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 10% 2026-04-21T03:15:53.826 ProcessImageName: Acrobat.exe, Pid: 2220, TotalTime: 181, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 26% 2026-04-21T03:15:53.826 ProcessImageName: OfficeC2RClient.exe, Pid: 14076, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 4% 2026-04-21T03:15:53.826 ProcessImageName: SDXHelper.exe, Pid: 7224, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: AcroCEF.exe, Pid: 6872, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 57% 2026-04-21T03:15:53.826 ProcessImageName: AdobeARM.exe, Pid: 9980, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 8% 2026-04-21T03:15:53.826 ProcessImageName: DeviceCensus.exe, Pid: 6752, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume2, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: SDXHelper.exe, Pid: 3108, TotalTime: 45, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 7% 2026-04-21T03:15:53.826 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: AcroCEF.exe, Pid: 3848, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 41% 2026-04-21T03:15:53.826 ProcessImageName: TeamViewer.exe, Pid: 7300, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 18% 2026-04-21T03:15:53.826 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: Acrobat.exe, Pid: 6732, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 6% 2026-04-21T03:15:53.826 ProcessImageName: sihost.exe, Pid: 6628, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: AggregatorHost.exe, Pid: 5276, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: brynhildr.exe, Pid: 3040, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-21T03:15:53.826 ProcessImageName: svchost.exe, Pid: 11456, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T03:26:45.463 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T03:27:16.373 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8768, FileId: 0x105000000004bb7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:32:42.392 Bm signature throttled:0x00002db31bed458f 2026-04-21T03:41:50.469 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T03:54:40.054 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9662, FileId: 0x70000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.054 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9664, FileId: 0xcd00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.054 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9663, FileId: 0xcc00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.054 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9665, FileId: 0x72000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.070 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9668, FileId: 0xcf00000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.070 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9670, FileId: 0xd000000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.070 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9671, FileId: 0xd100000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.070 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9669, FileId: 0x75000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.086 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9674, FileId: 0xd300000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.086 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9677, FileId: 0xd400000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.086 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9676, FileId: 0x79000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.101 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9679, FileId: 0x7a000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.101 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9675, FileId: 0x77000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.101 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9680, FileId: 0xd600000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.476 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9714, FileId: 0xd800000000497c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:54:40.476 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\1546625c-147f-4fd9-99e5-e1d739e31999. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #9716, FileId: 0x2f00000000fa36, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:55:44.576 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9722, FileId: 0x10e000000004bb7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T03:56:55.468 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T04:12:00.475 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T04:27:05.475 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T04:42:10.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T04:57:15.489 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T05:05:31.649 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #10054, FileId: 0xbe00000001b3dd, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:12:20.483 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T05:15:53.873 ProcessImageName: AcroCEF.exe, Pid: 1852, TotalTime: 3650, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-21T05:15:53.873 ProcessImageName: taskhostw.exe, Pid: 10012, TotalTime: 562, Count: 2, MaxTime: 531, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T05:15:53.873 ProcessImageName: firefox.exe, Pid: 12120, TotalTime: 555, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 42% 2026-04-21T05:15:53.873 ProcessImageName: powershell.exe, Pid: 1748, TotalTime: 431, Count: 30, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 39% 2026-04-21T05:15:53.873 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 346, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: SDXHelper.exe, Pid: 5676, TotalTime: 231, Count: 11, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 12% 2026-04-21T05:15:53.873 ProcessImageName: backgroundTaskHost.exe, Pid: 4260, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 10% 2026-04-21T05:15:53.873 ProcessImageName: Acrobat.exe, Pid: 2220, TotalTime: 181, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 26% 2026-04-21T05:15:53.873 ProcessImageName: FileCoAuth.exe, Pid: 6024, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-21T05:15:53.873 ProcessImageName: OfficeC2RClient.exe, Pid: 14076, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 4% 2026-04-21T05:15:53.873 ProcessImageName: SDXHelper.exe, Pid: 7224, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: AcroCEF.exe, Pid: 6872, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 57% 2026-04-21T05:15:53.873 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: AdobeARM.exe, Pid: 9980, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 8% 2026-04-21T05:15:53.873 ProcessImageName: DeviceCensus.exe, Pid: 6752, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume2, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: SDXHelper.exe, Pid: 3108, TotalTime: 45, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 7% 2026-04-21T05:15:53.873 ProcessImageName: OfficeC2RClient.exe, Pid: 3324, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-0527.log, EstimatedImpact: 2% 2026-04-21T05:15:53.873 ProcessImageName: AcroCEF.exe, Pid: 3848, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 41% 2026-04-21T05:15:53.873 ProcessImageName: SDXHelper.exe, Pid: 4992, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 17% 2026-04-21T05:15:53.873 ProcessImageName: OfficeC2RClient.exe, Pid: 7756, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-0555.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-21T05:15:53.873 ProcessImageName: TeamViewer.exe, Pid: 7300, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 18% 2026-04-21T05:15:53.873 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: Acrobat.exe, Pid: 6732, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 6% 2026-04-21T05:15:53.873 ProcessImageName: dllhost.exe, Pid: 5176, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: sihost.exe, Pid: 6628, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: AggregatorHost.exe, Pid: 5276, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: brynhildr.exe, Pid: 3040, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-21T05:15:53.873 ProcessImageName: svchost.exe, Pid: 11456, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T05:27:25.482 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T05:42:30.490 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T05:49:04.469 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10414, FileId: 0xb300000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.485 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10416, FileId: 0xb400000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.485 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10417, FileId: 0x81000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.485 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10418, FileId: 0xb500000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.485 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10419, FileId: 0x82000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.485 Bm signature throttled:0x000045b3435c1067 2026-04-21T05:49:04.501 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10423, FileId: 0x85000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.501 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10413, FileId: 0x7e000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.516 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10426, FileId: 0xbb00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.516 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10427, FileId: 0xbc00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.516 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10424, FileId: 0x86000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.516 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10428, FileId: 0x89000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.532 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10431, FileId: 0xbe00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.532 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10430, FileId: 0x8a000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.954 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10468, FileId: 0x8c000000004a64, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:49:04.954 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\38679289-2c8f-462d-9d91-cec61445d112. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #10470, FileId: 0x4f000000017e0f, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T05:57:35.492 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T06:12:40.483 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T06:19:53.522 [RTP] [Mini-filter] OpenWithoutRead notification (1164, 10007, ) sent successfully. 2026-04-21T06:27:45.483 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T06:39:54.105 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\BE9484D4-BE17-4711-B591-3853428D58FBc4c.1dcd159a889ee7f 2026-04-21T06:39:54.199 Verifying engine and signature files (source: 0) ... 2026-04-21T06:39:54.199 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpengine.dll] due to PPL. 2026-04-21T06:39:54.199 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasbase.vdm] (file in cache) 2026-04-21T06:39:54.199 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-21T06:39:54.215 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasdlta.vdm] 2026-04-21T06:39:54.215 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpavbase.vdm] (file in cache) 2026-04-21T06:39:54.215 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-21T06:39:54.230 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpavdlta.vdm] 2026-04-21T06:39:54.371 [Engine] IsHybridMode: 0 2026-04-21T06:39:54.371 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-21T06:39:54.387 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2FA66DC1C98F91BAC40F37765BBFB64A3E730B0D.bin): 0x00000002 2026-04-21T06:39:54.387 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2FA66DC1C98F91BAC40F37765BBFB64A3E730B0D.bin) 2026-04-21T06:39:54.387 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-21T06:39:54.387 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-21T06:39:54.387 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-21T06:39:54.387 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-21T06:40:05.943 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-21T06:40:05.943 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-21T06:40:05.943 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFF4B6A8020, lRefCount: 5, hr=0 2026-04-21T06:40:05.943 [Engine] New active engine 00007FFF48B98020 replacing engine 00007FFF4B6A8020. Number of active engines: 2 2026-04-21T06:40:05.959 EngineInit:Global ASOC is enabled 2026-04-21T06:40:05.959 EngineInit:ASOO is enabled for developer volumes 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T06:40:06.022 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6e8857ed54dc2bd6273e01d921ab3dd9c95f9bce Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:288000000 2026-04-21T06:40:06.022 MpWriteUupSignatureVersion 1.449.222.0, hr = 0 2026-04-21T06:40:06.037 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-21T06:40:06.053 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-21T06:40:06.053 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T06:40:06.053 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-21T06:40:06.053 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-21T06:40:06.053 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-21T06:40:06.068 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-21T06:40:06.068 [Plugin] Initializing RTP plugin state... 2026-04-21T06:40:06.068 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-21T06:40:06.068 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎21‎-‎2026 01:15:53 Last Perf:‎04‎-‎21‎-‎2026 01:15:53 First RTP Scan:‎04‎-‎21‎-‎2026 01:15:54 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1499 Misses:4045 BM Queue:0,28,0 Proc:0,25,0 File:0,17,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:11306 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:189904590 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:9808 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:53376 TotalHits:247756 InstanceCacheInserts:1165 InstanceCacheUpdates:0 InstanceCacheDeletes:538 InstanceCacheHits:326 InstanceCacheMisses:13266 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (644/515) Success: 515, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-21T06:40:06.068 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621} 2026-04-21T06:40:06.068 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599}\mpasbase.vdm in use, hr=0x80070020 2026-04-21T06:40:06.068 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BED631C-C38D-4A29-8138-E1406FDE63BC} removed 2026-04-21T06:40:06.068 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-21T06:40:06.068 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.068 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.068 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.068 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.068 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-21-2026 06:40:06 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-21-2026 06:40:06 2026-04-21T06:40:06.068 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-21T06:40:06.068 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-21T06:40:06.084 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T06:40:06.084 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-21T06:40:06.084 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T06:40:06.084 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.084 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.084 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.084 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-21T06:40:06.084 MdCoreSvc is supported in this platform and OS Signature updated on 04-21-2026 06:40:06 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.222.0 AV Signature Version: 1.449.222.0 ************************************************************ 2026-04-21T06:40:06.084 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-21T06:40:06.084 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\BE9484D4-BE17-4711-B591-3853428D58FBc4c.1dcd159a889ee7f 2026-04-21T06:40:06.100 Process scan (postsignatureupdatescan) started. 2026-04-21T06:40:06.178 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-21T06:40:06.178 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-21T06:40:06.490 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-21T06:40:06.490 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-21T06:40:06.490 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-21T06:40:06.490 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-21T06:40:06.490 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-21T06:40:06.490 [Engine] Engine 00007FFF4B6A8020 no longer in use. Number of active engines: 1 2026-04-21T06:40:06.490 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T06:40:06.490 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-21T06:40:06.537 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-21T06:40:06.537 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-21T06:40:06.537 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-21T06:40:06.647 ProcessImageName: AcroCEF.exe, Pid: 1852, TotalTime: 3650, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-21T06:40:06.647 ProcessImageName: WmiPrvSE.exe, Pid: 1368, TotalTime: 631, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 94% 2026-04-21T06:40:06.647 ProcessImageName: taskhostw.exe, Pid: 10012, TotalTime: 562, Count: 2, MaxTime: 531, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T06:40:06.647 ProcessImageName: firefox.exe, Pid: 12120, TotalTime: 555, Count: 57, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 42% 2026-04-21T06:40:06.647 ProcessImageName: powershell.exe, Pid: 1748, TotalTime: 431, Count: 30, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 39% 2026-04-21T06:40:06.647 ProcessImageName: firefox.exe, Pid: 6544, TotalTime: 420, Count: 46, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10808, EstimatedImpact: 54% 2026-04-21T06:40:06.647 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 346, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-04-21T06:40:06.647 ProcessImageName: SDXHelper.exe, Pid: 5676, TotalTime: 231, Count: 11, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 12% 2026-04-21T06:40:06.647 ProcessImageName: backgroundTaskHost.exe, Pid: 4260, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 10% 2026-04-21T06:40:06.647 ProcessImageName: Acrobat.exe, Pid: 2220, TotalTime: 181, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 26% 2026-04-21T06:40:06.647 ProcessImageName: FileCoAuth.exe, Pid: 6024, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-21T06:40:06.647 ProcessImageName: SecurityHealthHost.exe, Pid: 10916, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 12% 2026-04-21T06:40:06.647 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T06:40:06.647 ProcessImageName: OfficeC2RClient.exe, Pid: 14076, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 4% 2026-04-21T06:40:06.647 ProcessImageName: SDXHelper.exe, Pid: 7224, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-04-21T06:40:06.709 [Engine] RSIG_UNLOADENGINE, 00007FFF4B6A8020, err=0x0 2026-04-21T06:40:06.725 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{171630C8-C678-478C-A677-ACB39AE33599} removed 2026-04-21T06:40:08.084 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T06:40:08.100 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-21T06:40:08.100 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T06:40:23.677 Process scan (postsignatureupdatescan) completed. 2026-04-21T06:41:53.515 Bm signature throttled:0x00002db31bed458f 2026-04-21T06:41:53.593 Bm signature throttled:0x00002db31bed458f 2026-04-21T06:42:12.488 Bm signature throttled:0x00002db31bed458f 2026-04-21T06:42:26.528 [RTP] 11 newly mounted volumes accumulated, forcing a config update ... 2026-04-21T06:42:26.528 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-21T06:42:26.528 [RTP] Duplicating the current plugin configuration object... 2026-04-21T06:42:26.528 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T06:42:26.528 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-21T06:42:26.528 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-21T06:42:26.528 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-21T06:42:50.491 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T06:45:05.971 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-21T06:51:07.417 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-21T06:51:08.699 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #12873, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T06:57:55.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T06:58:24.182 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13219, FileId: 0x26000000034de8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T07:00:26.292 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0x81d4c93e 2026-04-21T07:08:08.021 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfa831d7ffffffe 2026-04-21T07:08:08.027 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0x81d4c93e 2026-04-21T07:08:08.566 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfa831d7ffffffe 2026-04-21T07:08:08.570 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfa831d7ffffffe 2026-04-21T07:08:09.016 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-04-21T07:08:09.016 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:08:09.016 [Cloud] Queued cloud request. 2026-04-21T07:08:09.016 [Cloud] Dequeued cloud request. 2026-04-21T07:08:09.046 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:08:09.266 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-21T07:08:09.266 [Cloud] End of cloud request. 2026-04-21T07:08:09.796 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0xf4ce2f61 2026-04-21T07:10:55.318 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Program Files\FileZilla Server\Uninstall.exe. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x157ef1bef48f 2026-04-21T07:13:00.494 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T07:14:17.571 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\Prefetch\GEEK.EXE-30F57974.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\geek.exe, Status: 0xc000004b, State: 0, ScanRequest #14273, FileId: 0x1e0000000243c9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T07:14:19.146 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\3N7TXZ6E\update[1].txt. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\geek64.exe, Status: 0xc0000001, State: 0, ScanRequest #14302, FileId: 0x1c0000000ab554, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=2, resourceid=0xf4ce2f61 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=2, resourceid=0x0d39c57c Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=0, resourceid=0x5b289907 2026-04-21T07:21:20.261 Bm signature throttled:0x00002db31bed458f 2026-04-21T07:22:16.526 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #15180, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5670ccc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b 2026-04-21T07:28:04.672 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:04.672 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:04.672 [Cloud] Queued cloud request. 2026-04-21T07:28:04.672 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:04.672 [Cloud] Dequeued cloud request. 2026-04-21T07:28:04.672 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:05.236 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e7aec615ff0a9f52f229899a96ade4530bf88e2c Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:05.236 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:05.236 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a 2026-04-21T07:28:05.416 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:05.416 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:05.416 [Cloud] Queued cloud request. 2026-04-21T07:28:05.416 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:05.416 [Cloud] Dequeued cloud request. 2026-04-21T07:28:05.416 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:05.423 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:05.423 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:05.423 [Cloud] Queued cloud request. 2026-04-21T07:28:05.423 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:05.423 [Cloud] Dequeued cloud request. 2026-04-21T07:28:05.423 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:05.431 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:05.431 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:05.431 [Cloud] Queued cloud request. 2026-04-21T07:28:05.431 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:05.431 [Cloud] Dequeued cloud request. 2026-04-21T07:28:05.431 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:05.486 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T07:28:05.696 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d181c9c68a5c760657d05fd355f829eb17dfd89e Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:05.706 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:05.706 [Cloud] End of cloud request. Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a18f70d260ee13916f059b52cd5c5d04ae794ad Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:05.706 Dynamic signature received 2026-04-21T07:28:05.706 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:05.706 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 2026-04-21T07:28:05.756 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:05.756 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:05.756 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:05.756 [Cloud] Queued cloud request. 2026-04-21T07:28:05.756 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:05.756 [Cloud] Dequeued cloud request. 2026-04-21T07:28:05.756 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:05.936 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f62e090107b04d9f5367cba829a7d55546b75dc3 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:06 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:05.936 [Cloud] End of cloud request. 2026-04-21T07:28:05.936 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:06.046 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9920e681a469146a76a702bf87deb6e4b50c18d2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:06 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:06.056 [Cloud] End of cloud request. 2026-04-21T07:28:06.056 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:06.446 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e 2026-04-21T07:28:06.936 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:06.936 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:06.936 [Cloud] Queued cloud request. 2026-04-21T07:28:06.936 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:06.936 [Cloud] Dequeued cloud request. 2026-04-21T07:28:06.936 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3d7e5716dfacfdcb913a3a51c0a9dd801620d7c9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:07.126 Dynamic signature received 2026-04-21T07:28:07.126 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:07.131 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc 2026-04-21T07:28:07.176 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:07.176 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:07.176 [Cloud] Queued cloud request. 2026-04-21T07:28:07.176 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:07.176 [Cloud] Dequeued cloud request. 2026-04-21T07:28:07.176 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:07.406 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\15024a8c62ebf2193da273f303376ebb5e192f59 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:07.406 [Cloud] End of cloud request. 2026-04-21T07:28:07.406 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf 2026-04-21T07:28:07.466 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:07.466 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:07.466 [Cloud] Queued cloud request. 2026-04-21T07:28:07.466 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:07.466 [Cloud] Dequeued cloud request. 2026-04-21T07:28:07.466 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:07.646 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7eaa491246cf324fbf0488e302c5c78fd3237ff2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:07.816 Dynamic signature received 2026-04-21T07:28:07.816 [Cloud] End of cloud request. 2026-04-21T07:28:07.816 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a 2026-04-21T07:28:07.866 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:07.866 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:07.866 [Cloud] Queued cloud request. 2026-04-21T07:28:07.866 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:07.866 [Cloud] Dequeued cloud request. 2026-04-21T07:28:07.866 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:08.086 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31a56b54b6c64dcee619761ff13da2b8fb84ebcb Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:08.086 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:08.086 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab 2026-04-21T07:28:08.146 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:08.146 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:08.146 [Cloud] Queued cloud request. 2026-04-21T07:28:08.146 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:08.146 [Cloud] Dequeued cloud request. 2026-04-21T07:28:08.146 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:08.326 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f9cc16be50890da474b4833fcea11dc0e8ee7f7f Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:08.376 Dynamic signature received 2026-04-21T07:28:08.376 [Cloud] End of cloud request. 2026-04-21T07:28:08.376 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc 2026-04-21T07:28:08.426 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:08.426 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:08.426 [Cloud] Queued cloud request. 2026-04-21T07:28:08.426 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:08.426 [Cloud] Dequeued cloud request. 2026-04-21T07:28:08.426 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:08.747 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f763419f84cf610e7382ebcd5d132093a8b5cf42 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:08.747 [Cloud] End of cloud request. 2026-04-21T07:28:08.747 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 2026-04-21T07:28:08.796 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:08.796 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:08.796 [Cloud] Queued cloud request. 2026-04-21T07:28:08.796 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:08.796 [Cloud] Dequeued cloud request. 2026-04-21T07:28:08.796 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:08.886 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:09.076 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\761f0eb4add16d497c66cbc7ce62353afbcd8edc Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:09.076 [Cloud] End of cloud request. 2026-04-21T07:28:09.076 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 2026-04-21T07:28:09.138 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:09.138 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:09.138 [Cloud] Queued cloud request. 2026-04-21T07:28:09.138 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:09.138 [Cloud] Dequeued cloud request. 2026-04-21T07:28:09.138 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:09.316 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5d495e773a9c3f5df5b2885f0ac9a8ccae9104b2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:09.316 [Cloud] End of cloud request. 2026-04-21T07:28:09.316 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 2026-04-21T07:28:09.371 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:09.371 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:09.371 [Cloud] Queued cloud request. 2026-04-21T07:28:09.371 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:09.371 [Cloud] Dequeued cloud request. 2026-04-21T07:28:09.371 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:09.566 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e323afb58aa9eda56bbe42e9ffa629ad7529e5f6 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:09.566 [Cloud] End of cloud request. 2026-04-21T07:28:09.566 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:09.586 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a 2026-04-21T07:28:09.626 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:09.626 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:09.626 [Cloud] Queued cloud request. 2026-04-21T07:28:09.626 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:09.626 [Cloud] Dequeued cloud request. 2026-04-21T07:28:09.626 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\28c3a498fd3d13b0703ffd2c428b01ea9ac00fac Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:09.806 Dynamic signature received 2026-04-21T07:28:09.806 [Cloud] End of cloud request. 2026-04-21T07:28:09.806 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f 2026-04-21T07:28:09.856 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:09.856 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:09.856 [Cloud] Queued cloud request. 2026-04-21T07:28:09.856 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:09.856 [Cloud] Dequeued cloud request. 2026-04-21T07:28:09.856 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:10.226 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b34aa7643004a4868d9f83f57f75b05c9729e5f2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:10 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:10.226 [Cloud] End of cloud request. 2026-04-21T07:28:10.226 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed 2026-04-21T07:28:10.286 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:10.286 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:10.286 [Cloud] Queued cloud request. 2026-04-21T07:28:10.286 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:10.286 [Cloud] Dequeued cloud request. 2026-04-21T07:28:10.286 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:10.316 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:10.477 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\93cc53a14baa40346794971c0fa29dc81f169c4c Dynamic Signature Compilation Timestamp:04-21-2026 07:28:10 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:10.486 [Cloud] End of cloud request. 2026-04-21T07:28:10.486 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c 2026-04-21T07:28:10.536 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:10.536 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:10.536 [Cloud] Queued cloud request. 2026-04-21T07:28:10.536 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:10.536 [Cloud] Dequeued cloud request. 2026-04-21T07:28:10.536 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:10.877 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c67e08f2055b41f7f6eecbd04adaa57a45ca3987 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:10.877 [Cloud] End of cloud request. 2026-04-21T07:28:10.877 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 2026-04-21T07:28:10.946 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:10.946 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:10.946 [Cloud] Queued cloud request. 2026-04-21T07:28:10.946 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:10.946 [Cloud] Dequeued cloud request. 2026-04-21T07:28:10.946 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:10.996 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d54da2a146381dbf49405864bdd6933278629821 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:11.166 Dynamic signature received 2026-04-21T07:28:11.166 [Cloud] End of cloud request. 2026-04-21T07:28:11.166 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 2026-04-21T07:28:11.226 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:11.226 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:11.226 [Cloud] Queued cloud request. 2026-04-21T07:28:11.226 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:11.226 [Cloud] Dequeued cloud request. 2026-04-21T07:28:11.226 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6569becc09b660c62b7406aae1b1760d432d9c1 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:11.426 Dynamic signature received 2026-04-21T07:28:11.426 [Cloud] End of cloud request. 2026-04-21T07:28:11.426 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce 2026-04-21T07:28:11.486 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:11.486 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:11.486 [Cloud] Queued cloud request. 2026-04-21T07:28:11.486 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:11.486 [Cloud] Dequeued cloud request. 2026-04-21T07:28:11.486 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:11.678 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:11.776 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bd4e2dfca6e14202b350f7a62516dc3f924cfa3f Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:11.776 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:11.776 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 2026-04-21T07:28:11.826 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:11.826 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:11.826 [Cloud] Queued cloud request. 2026-04-21T07:28:11.826 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:11.836 [Cloud] Dequeued cloud request. 2026-04-21T07:28:11.836 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:12.136 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d917b8debc8178763db6db50a485c64ff770cb38 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:12.136 [Cloud] End of cloud request. 2026-04-21T07:28:12.136 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c 2026-04-21T07:28:12.191 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:12.191 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:12.191 [Cloud] Queued cloud request. 2026-04-21T07:28:12.191 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:12.191 [Cloud] Dequeued cloud request. 2026-04-21T07:28:12.191 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:12.286 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:12.456 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\454f04897f28bd6e2611538a7dd0133a9b2424b5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:12.456 [Cloud] End of cloud request. 2026-04-21T07:28:12.456 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 2026-04-21T07:28:12.521 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:12.521 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:12.521 [Cloud] Queued cloud request. 2026-04-21T07:28:12.521 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:12.521 [Cloud] Dequeued cloud request. 2026-04-21T07:28:12.521 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:12.761 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\463be1d96f9a93839e0cc41871ef06bd13685f93 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:12.765 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:12.765 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb 2026-04-21T07:28:12.843 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:12.843 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:12.843 [Cloud] Queued cloud request. 2026-04-21T07:28:12.843 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:12.843 [Cloud] Dequeued cloud request. 2026-04-21T07:28:12.843 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:12.986 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:13.076 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46da5baedc7d9cf8658891d4084e8c6e633acdf3 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:13.076 [Cloud] End of cloud request. 2026-04-21T07:28:13.076 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 2026-04-21T07:28:13.166 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:13.166 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:13.166 [Cloud] Queued cloud request. 2026-04-21T07:28:13.166 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:13.166 [Cloud] Dequeued cloud request. 2026-04-21T07:28:13.166 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:13.376 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f031d4de0a781abe85d0a0a0f303a52bcda75439 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:13.380 [Cloud] End of cloud request. 2026-04-21T07:28:13.380 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 2026-04-21T07:28:13.441 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:13.441 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:13.441 [Cloud] Queued cloud request. 2026-04-21T07:28:13.441 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:13.441 [Cloud] Dequeued cloud request. 2026-04-21T07:28:13.441 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:13.591 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:13.666 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\20df2342d5821e5b3f518c2f3f7e8e8b93aaa05d Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:13.666 [Cloud] End of cloud request. 2026-04-21T07:28:13.666 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 2026-04-21T07:28:13.726 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:13.726 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:13.726 [Cloud] Queued cloud request. 2026-04-21T07:28:13.726 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:13.726 [Cloud] Dequeued cloud request. 2026-04-21T07:28:13.726 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:13.966 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48fe992a4c92c3c5bae304cb28692ca44215a931 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:13.966 [Cloud] End of cloud request. 2026-04-21T07:28:13.966 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 2026-04-21T07:28:14.031 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:14.031 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:14.031 [Cloud] Queued cloud request. 2026-04-21T07:28:14.031 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:14.031 [Cloud] Dequeued cloud request. 2026-04-21T07:28:14.031 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:14.181 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:14.246 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9f2c7d38e3af20f0bc434cf53f17c7d8a0b29be9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:14.246 [Cloud] End of cloud request. 2026-04-21T07:28:14.246 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 2026-04-21T07:28:14.306 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:14.306 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:14.306 [Cloud] Queued cloud request. 2026-04-21T07:28:14.306 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:14.306 [Cloud] Dequeued cloud request. 2026-04-21T07:28:14.316 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:14.646 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\220a9ae07083a25a19b5ebe4c919847b6d9d4700 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:14.646 [Cloud] End of cloud request. 2026-04-21T07:28:14.646 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd 2026-04-21T07:28:14.706 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:14.706 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:14.706 [Cloud] Queued cloud request. 2026-04-21T07:28:14.706 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:14.706 [Cloud] Dequeued cloud request. 2026-04-21T07:28:14.706 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:14.756 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:14.956 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62a7befa6ff9122ba3b2b0ee3ff2bb4f19658302 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:14.956 [Cloud] End of cloud request. 2026-04-21T07:28:14.956 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b 2026-04-21T07:28:15.016 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:15.016 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:15.016 [Cloud] Queued cloud request. 2026-04-21T07:28:15.016 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:15.016 [Cloud] Dequeued cloud request. 2026-04-21T07:28:15.016 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\59f81675cb32d990c32f79d387ff81cf077abeb9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:15.216 Dynamic signature received 2026-04-21T07:28:15.216 [Cloud] End of cloud request. 2026-04-21T07:28:15.216 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 2026-04-21T07:28:15.286 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:15.286 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:15.286 [Cloud] Queued cloud request. 2026-04-21T07:28:15.286 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:15.286 [Cloud] Dequeued cloud request. 2026-04-21T07:28:15.286 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:15.476 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:15.506 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\06bc47c7dca5da5812d723739503084c984cd8af Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:15.506 [Cloud] End of cloud request. 2026-04-21T07:28:15.506 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 2026-04-21T07:28:15.566 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:15.566 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:15.566 [Cloud] Queued cloud request. 2026-04-21T07:28:15.566 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:15.566 [Cloud] Dequeued cloud request. 2026-04-21T07:28:15.566 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:15.996 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\80a679da9de4bdeefc14d0433befdab62ceb9c5d Dynamic Signature Compilation Timestamp:04-21-2026 07:28:16 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:15.996 [Cloud] End of cloud request. 2026-04-21T07:28:15.996 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:16.026 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 2026-04-21T07:28:16.067 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:16.067 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:16.067 [Cloud] Queued cloud request. 2026-04-21T07:28:16.067 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:16.067 [Cloud] Dequeued cloud request. 2026-04-21T07:28:16.067 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:26.087 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\apache\modules\mod_rewrite.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-04-21T07:28:26.096 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e 2026-04-21T07:28:26.146 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:26.146 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:26.146 [Cloud] Queued cloud request. 2026-04-21T07:28:26.146 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:26.146 [Cloud] Dequeued cloud request. 2026-04-21T07:28:26.146 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:26.347 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9cce68d7fc65b3a5ffdedcc9756b0c1d66c018b8 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:26 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:26.347 [Cloud] End of cloud request. 2026-04-21T07:28:26.347 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb 2026-04-21T07:28:26.406 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:26.406 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:26.406 [Cloud] Queued cloud request. 2026-04-21T07:28:26.406 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:26.406 [Cloud] Dequeued cloud request. 2026-04-21T07:28:26.406 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:26.606 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:26.656 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\455a92b509e470d2871948a21bb27f0e1535e62a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:26 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:26.656 [Cloud] End of cloud request. 2026-04-21T07:28:26.656 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b 2026-04-21T07:28:26.726 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:26.726 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:26.726 [Cloud] Queued cloud request. 2026-04-21T07:28:26.726 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:26.726 [Cloud] Dequeued cloud request. 2026-04-21T07:28:26.726 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:27.166 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ac1a57b452e752ec23ce739a0b96f5aca98d7f5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:27 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:27.336 Dynamic signature received 2026-04-21T07:28:27.336 [Cloud] End of cloud request. 2026-04-21T07:28:27.336 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x37cc51ff 2026-04-21T07:28:27.416 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:27.416 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:27.416 [Cloud] Queued cloud request. 2026-04-21T07:28:27.416 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:27.416 [Cloud] Dequeued cloud request. 2026-04-21T07:28:27.416 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8c217a73d98084f95a5bb6df43055cc1126115e5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:27 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:27.636 Dynamic signature received 2026-04-21T07:28:27.646 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:27.646 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d 2026-04-21T07:28:27.706 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:27.706 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:27.706 [Cloud] Queued cloud request. 2026-04-21T07:28:27.706 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:27.706 [Cloud] Dequeued cloud request. 2026-04-21T07:28:27.706 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:27.846 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:27.927 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3f4d4f37bbb5995ee48a1579d64d1e8e671f5ae8 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:28 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:27.927 [Cloud] End of cloud request. 2026-04-21T07:28:27.927 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x96e53194 2026-04-21T07:28:28.456 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:28.568 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:28.568 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:28.568 [Cloud] Queued cloud request. 2026-04-21T07:28:28.568 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:28.568 [Cloud] Dequeued cloud request. 2026-04-21T07:28:28.568 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:28.856 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4e542b0bef7638a504a86ae42a203e87b98785d2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:29 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:28.856 [Cloud] End of cloud request. 2026-04-21T07:28:28.856 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7bfe971b 2026-04-21T07:28:29.018 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:29.018 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:29.018 [Cloud] Queued cloud request. 2026-04-21T07:28:29.018 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:29.018 [Cloud] Dequeued cloud request. 2026-04-21T07:28:29.018 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:29.266 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a8ad41ae71d79e3a58729435761047af005d690a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:29 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:29.266 [Cloud] End of cloud request. 2026-04-21T07:28:29.266 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:29.371 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a883020 2026-04-21T07:28:29.840 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:29.840 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:29.840 [Cloud] Queued cloud request. 2026-04-21T07:28:29.840 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:29.840 [Cloud] Dequeued cloud request. 2026-04-21T07:28:29.840 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:30.036 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdd2ff34e20bfc31834279846c4d740f89c0e426 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:30 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:30.036 [Cloud] End of cloud request. 2026-04-21T07:28:30.036 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ccbb36f 2026-04-21T07:28:30.136 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:30.136 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:30.136 [Cloud] Queued cloud request. 2026-04-21T07:28:30.136 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:30.136 [Cloud] Dequeued cloud request. 2026-04-21T07:28:30.136 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:30.466 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\961da9ff43b1d7ce4b44f691fe51862cd40f1cea Dynamic Signature Compilation Timestamp:04-21-2026 07:28:30 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:30.466 [Cloud] End of cloud request. 2026-04-21T07:28:30.466 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 2026-04-21T07:28:30.561 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfb0260af 2026-04-21T07:28:30.704 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:30.704 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:30.704 [Cloud] Queued cloud request. 2026-04-21T07:28:30.704 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:30.704 [Cloud] Dequeued cloud request. 2026-04-21T07:28:30.704 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:30.971 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7843de7e3717c4c1147095caeb09ef70e079f0a9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:30.971 [Cloud] End of cloud request. 2026-04-21T07:28:30.971 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c25bb8 2026-04-21T07:28:31.036 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:31.036 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:31.036 [Cloud] Queued cloud request. 2026-04-21T07:28:31.036 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:31.036 [Cloud] Dequeued cloud request. 2026-04-21T07:28:31.036 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\410d57215d0bb71340881e0ee21cf27161989f52 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:31.286 Dynamic signature received 2026-04-21T07:28:31.286 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:31.286 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6ab8889 2026-04-21T07:28:31.431 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:31.431 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:31.431 [Cloud] Queued cloud request. 2026-04-21T07:28:31.431 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:31.431 [Cloud] Dequeued cloud request. 2026-04-21T07:28:31.431 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:31.496 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:31.647 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\16eaa6e2dc20e9ea768e538fd280daff156d5fbc Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:31.647 [Cloud] End of cloud request. 2026-04-21T07:28:31.647 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf20873eb 2026-04-21T07:28:31.706 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:31.706 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:31.706 [Cloud] Queued cloud request. 2026-04-21T07:28:31.706 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:31.706 [Cloud] Dequeued cloud request. 2026-04-21T07:28:31.706 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:31.967 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3c5ed6b8853a6dd3e0fee7dad9e575182c9045ee Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:31.967 [Cloud] End of cloud request. 2026-04-21T07:28:31.967 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06b38ace 2026-04-21T07:28:32.036 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:32.036 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:32.036 [Cloud] Queued cloud request. 2026-04-21T07:28:32.036 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:32.036 [Cloud] Dequeued cloud request. 2026-04-21T07:28:32.036 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:32.176 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:32.246 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d9f0115c553a3736ba55b7547fdd68e74762fe8e Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:32.246 [Cloud] End of cloud request. 2026-04-21T07:28:32.246 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb934f277 2026-04-21T07:28:32.318 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:32.318 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:32.318 [Cloud] Queued cloud request. 2026-04-21T07:28:32.318 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:32.318 [Cloud] Dequeued cloud request. 2026-04-21T07:28:32.318 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:32.636 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\72eb101c9777fa8e1faac8bff01e0718aaf2f7d5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:32.636 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:32.636 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe4e9c3ef 2026-04-21T07:28:32.726 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:32.726 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:32.726 [Cloud] Queued cloud request. 2026-04-21T07:28:32.726 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:32.726 [Cloud] Dequeued cloud request. 2026-04-21T07:28:32.726 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:32.756 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d6db0a31747ca71d702be172edb58e75803cfe7a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:33 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:33.071 [Cloud] End of cloud request. 2026-04-21T07:28:33.071 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:33.076 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9cab2c6 2026-04-21T07:28:33.201 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:33.201 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:33.201 [Cloud] Queued cloud request. 2026-04-21T07:28:33.201 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:33.201 [Cloud] Dequeued cloud request. 2026-04-21T07:28:33.201 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\481501cd0a2dc402571573be260a536e7151ce59 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:33 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:33.412 [Cloud] End of cloud request. 2026-04-21T07:28:33.412 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:33.412 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7c337a01 2026-04-21T07:28:33.496 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T07:28:33.496 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T07:28:33.496 [Cloud] Queued cloud request. 2026-04-21T07:28:33.496 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T07:28:33.496 [Cloud] Dequeued cloud request. 2026-04-21T07:28:33.496 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T07:28:33.596 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:28:34.266 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\26527814d606f5b1fbaf207bc874b91c7d41cfa7 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:34 Persistence Type:Duration Time remaining:50065408 2026-04-21T07:28:34.266 [Cloud] End of cloud request. 2026-04-21T07:28:34.266 RTSD:RTSD recieved, rescanning impacted resources 2026-04-21T07:28:34.776 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T07:30:28.776 Bm signature throttled:0x00002db31bed458f 2026-04-21T07:43:10.507 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T07:58:15.479 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T07:58:44.183 Bm signature throttled:0x00002db31bed458f 2026-04-21T07:58:45.678 Bm signature throttled:0x00002db31bed458f 2026-04-21T08:06:01.132 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #17875, FileId: 0x1d0000000b76b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T08:10:34.228 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18543, FileId: 0x130000000b7c43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T08:13:20.488 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T08:16:40.813 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18592, FileId: 0x290000000b72f7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T08:28:25.488 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T08:34:45.938 Bm signature throttled:0x00002db31bed458f 2026-04-21T08:38:35.008 Bm signature throttled:0x00002db31bed458f 2026-04-21T08:40:05.948 ProcessImageName: geek64.exe, Pid: 2776, TotalTime: 7757, Count: 568, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 4% 2026-04-21T08:40:05.948 ProcessImageName: explorer.exe, Pid: 7784, TotalTime: 4486, Count: 171, MaxTime: 421, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\FileZilla_Server_1.12.5_win64-setup.exe, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: httpd.exe, Pid: 7660, TotalTime: 4182, Count: 77, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php5ts.dll, EstimatedImpact: 14% 2026-04-21T08:40:05.948 ProcessImageName: mmc.exe, Pid: 5916, TotalTime: 1680, Count: 198, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\ARIALN.TTF, EstimatedImpact: 70% 2026-04-21T08:40:05.948 ProcessImageName: filezilla-server.exe, Pid: 9200, TotalTime: 1480, Count: 10, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 100% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 1248, Count: 4, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\FileZilla_Server_1.12.5_win64-setup.exe, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: filezilla-server-gui.exe, Pid: 13424, TotalTime: 1093, Count: 3, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\wxmsw32u_core_gcc_custom.dll, EstimatedImpact: 100% 2026-04-21T08:40:05.948 ProcessImageName: FileZilla_Server_1.12.5_win64-setup.exe, Pid: 6004, TotalTime: 1068, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 8208, TotalTime: 623, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: winvnc.exe, Pid: 6644, TotalTime: 467, Count: 1425, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: httpd.exe, Pid: 7376, TotalTime: 301, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 19% 2026-04-21T08:40:05.948 ProcessImageName: xampp-control.exe, Pid: 12152, TotalTime: 248, Count: 5, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 1% 2026-04-21T08:40:05.948 ProcessImageName: mmc.exe, Pid: 13336, TotalTime: 199, Count: 12, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\3N7TXZ6E\views[1], EstimatedImpact: 1% 2026-04-21T08:40:05.948 ProcessImageName: brynhildr.exe, Pid: 3040, TotalTime: 171, Count: 3, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: mmc.exe, Pid: 4636, TotalTime: 123, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 10% 2026-04-21T08:40:05.948 ProcessImageName: Un.exe, Pid: 11288, TotalTime: 106, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsc6020.tmp\System.dll, EstimatedImpact: 2% 2026-04-21T08:40:05.948 ProcessImageName: xampp-control.exe, Pid: 12044, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: cmd.exe, Pid: 3324, TotalTime: 105, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: FileCoAuth.exe, Pid: 10068, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-21.0805.10068.1.aodl, EstimatedImpact: 1% 2026-04-21T08:40:05.948 ProcessImageName: SDXHelper.exe, Pid: 7136, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\7a1f4e2c-c917-4b76-8457-046a5feca859, EstimatedImpact: 6% 2026-04-21T08:40:05.948 ProcessImageName: OfficeC2RClient.exe, Pid: 1548, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1016.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-21T08:40:05.948 ProcessImageName: OfficeC2RClient.exe, Pid: 8216, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 2% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: xampp-control.exe, Pid: 6424, TotalTime: 46, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 1868, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6, EstimatedImpact: 28% 2026-04-21T08:40:05.948 ProcessImageName: OfficeC2RClient.exe, Pid: 2356, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1010.log, EstimatedImpact: 2% 2026-04-21T08:40:05.948 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyhbd.ttc, EstimatedImpact: 11% 2026-04-21T08:40:05.948 ProcessImageName: dllhost.exe, Pid: 5652, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-52479406.pf, EstimatedImpact: 27% 2026-04-21T08:40:05.948 ProcessImageName: AggregatorHost.exe, Pid: 5276, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: cmd.exe, Pid: 2068, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: mmc.exe, Pid: 13472, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-21T08:40:05.948 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\metadata\Synchronizer, EstimatedImpact: 0% 2026-04-21T08:43:30.488 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T08:53:11.488 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18871, FileId: 0x3e0000000b5bcc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T08:58:35.499 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T09:03:53.349 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18951, FileId: 0x110000000b7c84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T09:13:39.823 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19071, FileId: 0x1a0000000b814f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T09:13:40.499 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T09:24:09.399 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19131, FileId: 0x4e0000000b818e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T09:28:45.489 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T09:43:50.495 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T09:44:47.679 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19213, FileId: 0x1b0000000b81c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T09:52:35.370 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19502, FileId: 0x250000000b8206, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{3B08A85B-2A2D-5F92-1632-1FD9D6D96AEE} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:7660 ProcessCreationTime:134212300852416825 SessionID:1 CreationTime:04-21-2026 09:58:22 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-21T09:58:23.183 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-21T09:58:23.183 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T09:58:23.183 [Cloud] Queued cloud request. 2026-04-21T09:58:23.183 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-21T09:58:23.183 [Cloud] Dequeued cloud request. 2026-04-21T09:58:23.183 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T09:58:23.193 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-21T09:58:23.193 [Cloud] Start of cloud request. Passive mode: 0 2026-04-21T09:58:23.193 [Cloud] Queued cloud request. 2026-04-21T09:58:23.193 [Cloud] Dequeued cloud request. 2026-04-21T09:58:23.193 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-21T09:58:23.473 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-21T09:58:23.473 [Cloud] End of cloud request. 2026-04-21T09:58:23.563 [Cloud] End of cloud request. 2026-04-21T09:58:23.983 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T09:58:55.555 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T10:03:47.420 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19530, FileId: 0x140000000b8311, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:14:00.589 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T10:29:05.623 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T10:40:06.123 ProcessImageName: geek64.exe, Pid: 2776, TotalTime: 7757, Count: 568, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 4% 2026-04-21T10:40:06.123 ProcessImageName: explorer.exe, Pid: 7784, TotalTime: 4486, Count: 171, MaxTime: 421, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\FileZilla_Server_1.12.5_win64-setup.exe, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: httpd.exe, Pid: 7660, TotalTime: 4182, Count: 77, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php5ts.dll, EstimatedImpact: 14% 2026-04-21T10:40:06.123 ProcessImageName: mmc.exe, Pid: 5916, TotalTime: 1680, Count: 198, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\ARIALN.TTF, EstimatedImpact: 70% 2026-04-21T10:40:06.123 ProcessImageName: filezilla-server.exe, Pid: 9200, TotalTime: 1480, Count: 10, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\libstdc++-6.dll, EstimatedImpact: 100% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 1248, Count: 4, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\FileZilla_Server_1.12.5_win64-setup.exe, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: filezilla-server-gui.exe, Pid: 13424, TotalTime: 1093, Count: 3, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\wxmsw32u_core_gcc_custom.dll, EstimatedImpact: 100% 2026-04-21T10:40:06.123 ProcessImageName: FileZilla_Server_1.12.5_win64-setup.exe, Pid: 6004, TotalTime: 1068, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\FileZilla Server\filezilla-server-gui.exe, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 8208, TotalTime: 623, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: winvnc.exe, Pid: 6644, TotalTime: 467, Count: 1425, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\ultravnc.ini, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: httpd.exe, Pid: 7376, TotalTime: 301, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 19% 2026-04-21T10:40:06.123 ProcessImageName: xampp-control.exe, Pid: 12152, TotalTime: 248, Count: 5, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: mmc.exe, Pid: 13336, TotalTime: 199, Count: 12, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\3N7TXZ6E\views[1], EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: brynhildr.exe, Pid: 3040, TotalTime: 171, Count: 3, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: mmc.exe, Pid: 4636, TotalTime: 123, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 10% 2026-04-21T10:40:06.123 ProcessImageName: Un.exe, Pid: 11288, TotalTime: 106, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsc6020.tmp\System.dll, EstimatedImpact: 2% 2026-04-21T10:40:06.123 ProcessImageName: xampp-control.exe, Pid: 12044, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: cmd.exe, Pid: 3324, TotalTime: 105, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: FileCoAuth.exe, Pid: 10068, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-21.0805.10068.1.aodl, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: SDXHelper.exe, Pid: 7136, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\7a1f4e2c-c917-4b76-8457-046a5feca859, EstimatedImpact: 6% 2026-04-21T10:40:06.123 ProcessImageName: PhoneExperienceHost.exe, Pid: 11920, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 1548, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1016.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 8216, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 2% 2026-04-21T10:40:06.123 ProcessImageName: dllhost.exe, Pid: 5176, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: AggregatorHost.exe, Pid: 5276, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: httpd.exe, Pid: 8760, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\error\include\top.html, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: xampp-control.exe, Pid: 6424, TotalTime: 46, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 1868, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BF89E52F8D681360E6B84941BD2F9BC0093309F6, EstimatedImpact: 28% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 2356, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1010.log, EstimatedImpact: 2% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 2680, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1113.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: svchost.exe, Pid: 2664, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyhbd.ttc, EstimatedImpact: 11% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 6568, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1053.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: SDXHelper.exe, Pid: 8780, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 11% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 5308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1152.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 3704, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1124.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 5412, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1144.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 9068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1203.log, EstimatedImpact: 1% 2026-04-21T10:40:06.123 ProcessImageName: dllhost.exe, Pid: 5652, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-52479406.pf, EstimatedImpact: 27% 2026-04-21T10:40:06.123 ProcessImageName: OfficeC2RClient.exe, Pid: 12300, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1103.log, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: cmd.exe, Pid: 2068, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\CMD.EXE-0BD30981.pf, EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: mmc.exe, Pid: 13472, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\views[1], EstimatedImpact: 0% 2026-04-21T10:40:06.123 ProcessImageName: AdobeCollabSync.exe, Pid: 6836, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Reader\Synchronizer\metadata\Synchronizer, EstimatedImpact: 0% 2026-04-21T10:44:10.660 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T10:54:39.697 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19994, FileId: 0x8f000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.697 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19996, FileId: 0xc400000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.697 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19995, FileId: 0xc300000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.715 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20000, FileId: 0x92000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.720 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19997, FileId: 0x90000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.720 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20002, FileId: 0xc700000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.720 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20004, FileId: 0x95000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.725 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20005, FileId: 0xc900000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.739 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20003, FileId: 0xc800000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.739 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20010, FileId: 0xcc00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.739 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20009, FileId: 0x99000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:39.739 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20008, FileId: 0x97000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:40.109 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20043, FileId: 0xcf00000001a0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:54:40.126 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\14761246-3e90-4178-a6b7-3d4c1cba2365. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #20045, FileId: 0x7a00000003a739, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T10:59:15.680 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T10:59:34.091 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20081, FileId: 0x4700000008f521, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-21-2026 12:15:39 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/21/2026 12:15:39.985265100 UTC (14703 ms since boot) 2026-04-21T12:15:39.998 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-21T12:15:40.003 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T12:15:40.006 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T12:15:40.063 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260421-121540-00000003-fffffffeffffffff.bin ... 2026-04-21T12:15:40.133 [WPP] Trace session started - MpWppTracing-20260421-121540-00000003-fffffffeffffffff.bin 2026-04-21T12:15:40.133 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-21T12:15:40.138 [RbM] Rollback manager succesfully initialized. 2026-04-21T12:15:40.138 [RbM] Rollback manager EnableRollbackManager called. 2026-04-21T12:15:40.143 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-21T12:15:40.148 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-21T12:15:40.149 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-21T12:15:40.149 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-21T12:15:40.149 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-21T12:15:40.149 MdCoreSvc is supported in this platform and OS 2026-04-21T12:15:40.149 MdCoreSvc is supported in this platform and OS 2026-04-21T12:15:40.149 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-21T12:15:40.149 [PlatUpd] Starting MdCoreSvc service 2026-04-21T12:15:40.181 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-21T12:15:46.058 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-21T12:15:46.058 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-21T12:15:46.058 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-21T12:15:46.058 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-21T12:15:46.058 [PlatUpd] CSP platform update started 2026-04-21T12:15:46.058 [PlatUpd] Defender MDM CSP platform update not required 2026-04-21T12:15:46.058 [PlatUpd] WMI/PS provider platform update started 2026-04-21T12:15:46.058 [PlatUpd] WMI/PS provider platform update not required 2026-04-21T12:15:46.058 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-21T12:15:46.058 MdCoreSvc is supported in this platform and OS 2026-04-21T12:15:46.058 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-21T12:15:46.058 [PlatUpd] Starting MdCoreSvc service 2026-04-21T12:15:46.058 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-21T12:15:46.058 [TS] Troublshooting mode is not available! 2026-04-21T12:15:46.058 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-21T12:15:46.058 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-21T12:15:46.105 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-21T12:15:46.105 [Service] Enabling AutoLoggers ... 2026-04-21T12:15:46.105 [Service] Enabling AMSI registration ... 2026-04-21T12:15:46.105 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-21T12:15:46.136 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52310 Number of invalid entries is 0 Number of inserts issued is 1573203 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6398 Number of lookups is 107016803 Number of lookup misses is 5125477 Number of fast lookup misses is 54599540 Number of false fast lookups is 5125472 Number of invalidations is 729192 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-21T12:15:46.136 Verifying license file... 2026-04-21T12:15:46.136 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-21T12:15:46.152 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-21T12:15:46.152 Loaded module#0 MpComServer. 2026-04-21T12:15:46.168 Loaded module#1 StartupPolicies. 2026-04-21T12:15:46.168 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-21T12:15:46.168 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-21T12:15:46.168 COM server initialized successfully. 2026-04-21T12:15:46.183 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-21T12:15:46.199 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-21T12:15:46.199 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-21T12:15:46.214 [RTP] [RTP] FilterCommunicator object 0x0000020F04C9B9A0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-21T12:15:46.214 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-21T12:15:46.214 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-21T12:15:46.214 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-21T12:15:46.214 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-21T12:15:46.214 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-21T12:15:46.214 [RTP] [RTP] FilterCommunicator object 0x0000020F04C9BBB0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-21T12:15:46.214 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-21T12:15:46.214 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-21T12:15:46.230 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-21T12:15:46.230 [RTP] [RTP] StartCommunication 0x0000020F04C9B9A0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-21T12:15:46.230 [init][RTP] RTPPlugin initialization completed 2026-04-21T12:15:46.230 OS boot count = 2 2026-04-21T12:15:46.230 OS Install = 0 2026-04-21T12:15:46.308 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-21T12:15:46.324 [KSL] Entering CKSLEngine::Initialize. 2026-04-21T12:15:46.324 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-21T12:15:46.324 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-21T12:15:46.324 [KSL] MpInstallKslD: hr=0x1 2026-04-21T12:15:46.324 [KSL] MpRegisterKslD: hr=0 2026-04-21T12:15:46.340 [KSL] MpStartKslD: hr=0 2026-04-21T12:15:46.340 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-21T12:15:46.340 Loading engine... 2026-04-21T12:15:46.355 Verifying engine and signature files (source: 1) ... 2026-04-21T12:15:46.355 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpengine.dll] due to PPL. 2026-04-21T12:15:46.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasbase.vdm] (file in cache) 2026-04-21T12:15:46.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasdlta.vdm] (file in cache) 2026-04-21T12:15:46.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpavbase.vdm] (file in cache) 2026-04-21T12:15:46.355 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpavdlta.vdm] (file in cache) 2026-04-21T12:15:46.418 [Engine] IsHybridMode: 0 2026-04-21T12:15:46.418 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-21T12:15:46.449 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2FA66DC1C98F91BAC40F37765BBFB64A3E730B0D.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-21T12:16:02.540 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-21T12:16:02.542 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-21T12:16:02.542 [Engine] New active engine 00007FFA7EF18020 (no old engine). Number of active engines: 1 2026-04-21T12:16:02.559 EngineInit:Global ASOC is enabled 2026-04-21T12:16:02.559 EngineInit:ASOO is enabled for developer volumes 2026-04-21T12:16:02.686 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-21T12:16:02.686 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.686 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.687 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.688 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.689 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.689 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.690 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:16:02.781 MpWriteUupSignatureVersion 1.449.222.0, hr = 0 2026-04-21T12:16:02.783 [SigStatUpd] CSignatureStatus: back to good 2026-04-21T12:16:02.783 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-21T12:16:02.823 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-21T12:16:02.823 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T12:16:02.823 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-21T12:16:02.823 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-21T12:16:02.823 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-21T12:16:02.852 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-21T12:16:02.852 [Plugin] Initializing RTP plugin state... 2026-04-21T12:16:02.852 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3639 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18240 TotalHits:0 InstanceCacheInserts:34 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3885 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-21T12:16:02.852 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-21T12:16:02.853 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621} 2026-04-21T12:16:02.854 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:16:02.854 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:16:02.854 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:16:02.854 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-21T12:16:02.855 MdCoreSvc is supported in this platform and OS 2026-04-21T12:16:02.855 Engine loaded! 2026-04-21T12:16:02.856 [DLP] Create FeatureControlState instance 2026-04-21T12:16:02.868 RegisterSModeChangeListener: hr = 0x1 2026-04-21T12:16:02.868 RegisterHybridModeChangeListener: hr = 0 2026-04-21T12:16:02.895 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-21T12:16:02.895 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-21T12:16:02.908 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-21T12:16:02.908 [SigReleaseHb] Initialized with Stage 0 2026-04-21T12:16:02.908 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-21T12:16:02.910 [SCC][CID=37625_5496] Initializing ... 2026-04-21T12:16:02.910 [SCC][CID=37625_5496] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-21T12:16:02.914 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-21T12:16:02.914 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-21T12:16:02.917 [NRI] Stopping NIS service ... 2026-04-21T12:16:02.920 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-21T12:16:02.920 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.222.0 AV Signature Version: 1.449.222.0 ************************************************************ 2026-04-21T12:16:02.921 Resource usage Monitoring is enabled 2026-04-21T12:16:02.923 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-21T12:16:02.924 Job Notification: New process added to job (4424) 2026-04-21T12:16:02.944 Job Notification: New process added to job (10364) 2026-04-21T12:16:02.945 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-21T12:16:02.965 Job Notification: New process added to job (8564) 2026-04-21T12:16:02.983 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:10364] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8564]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-21T12:16:03.094 Job Notification: Process exited from job (10364) 2026-04-21T12:16:03.096 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-21T12:16:03.096 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-21T12:16:03.100 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-21T12:16:03.101 Job Notification: Process exited from job (8564) 2026-04-21T12:16:03.107 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-21T12:16:03.107 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-21T12:16:03.107 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-21T12:16:03.107 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-21T12:16:03.107 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-21T12:16:03.107 [RTP] Generating the base plugin configuration ... 2026-04-21T12:16:03.108 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-21T12:16:03.108 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T12:16:03.108 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-21T12:16:03.112 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-21T12:16:03.112 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T12:16:03.112 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-21T12:16:03.117 [RTP] [RTP] StartCommunication 0x0000020F04C9BBB0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-21T12:16:03.120 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-21T12:16:03.123 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-21T12:16:03.317 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-21T12:16:03.317 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-21T12:16:03.317 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-21T12:16:03.507 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T12:16:06.055 [RTP] Duplicating the current plugin configuration object... 2026-04-21T12:16:06.055 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T12:16:06.055 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-21T12:16:06.055 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-21T12:16:06.056 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-21T12:16:06.510 Bm signature throttled:0x00002db31bed458f 2026-04-21T12:16:14.782 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #1044, FileId: 0xe0000000b8563, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:16:46.153 Process scan (poststartupscan) started. 2026-04-21T12:16:46.153 Process scan (poststartupscan) completed. 2026-04-21T12:16:46.669 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-21T12:16:46.684 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-21T12:16:49.263 [RTP] Duplicating the current plugin configuration object... 2026-04-21T12:16:49.263 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T12:16:49.263 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-21T12:16:49.263 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-21T12:16:49.263 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-21T12:17:13.855 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2759, FileId: 0x140000000bd09f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:17:42.432 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T12:17:42.432 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-21T12:17:42.432 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T12:20:45.434 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #3752, FileId: 0xb0000000bd0a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:21:02.600 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-21T12:21:02.912 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T12:22:09.017 Bm signature throttled:0x00002db31bed458f 2026-04-21T12:22:27.150 Bm signature throttled:0x00002db31bed458f 2026-04-21T12:23:07.442 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-21T12:23:07.442 [RTP] Duplicating the current plugin configuration object... 2026-04-21T12:23:07.442 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T12:23:07.442 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-21T12:23:07.442 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-21T12:23:07.442 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\htdocs\0_\08_PHP - Verknüpfung.lnk 2026-04-21T12:23:07.442 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-21T12:26:02.911 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-21T12:26:02.911 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-21T12:26:02.942 Job Notification: New process added to job (10908) 2026-04-21T12:26:02.957 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-21T12:26:02.957 Job Notification: New process added to job (13252) 2026-04-21T12:26:02.973 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:10908] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:13252]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-21T12:26:03.020 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 45209313(ms) from now at 02:59 (00:59 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-21T12:26:03.067 Job Notification: New process added to job (6012) 2026-04-21T12:26:03.067 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-21T12:26:03.082 Job Notification: New process added to job (6024) 2026-04-21T12:26:03.082 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6012] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6024]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-21T12:26:14.504 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\710F82F2-EFDF-4896-85A8-00CC316572281b80.1dcd18a0a70f6fd 2026-04-21T12:26:14.598 Verifying engine and signature files (source: 0) ... 2026-04-21T12:26:14.598 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpengine.dll] due to PPL. 2026-04-21T12:26:14.598 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpasbase.vdm] (file in cache) 2026-04-21T12:26:14.598 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-21T12:26:14.614 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpasdlta.vdm] 2026-04-21T12:26:14.614 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpavbase.vdm] (file in cache) 2026-04-21T12:26:14.614 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-21T12:26:14.629 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908}\mpavdlta.vdm] 2026-04-21T12:26:14.785 [Engine] IsHybridMode: 0 2026-04-21T12:26:14.785 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-21T12:26:14.785 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1B87C35D711AF3EAB87E44799AB763E4510B3F91.bin): 0x00000002 2026-04-21T12:26:14.801 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1B87C35D711AF3EAB87E44799AB763E4510B3F91.bin) 2026-04-21T12:26:14.801 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-21T12:26:14.801 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-21T12:26:14.801 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-21T12:26:14.801 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-21T12:26:27.487 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-21T12:26:27.487 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-21T12:26:27.503 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFA7EF18020, lRefCount: 5, hr=0 2026-04-21T12:26:27.503 [Engine] New active engine 00007FFA217F8020 replacing engine 00007FFA7EF18020. Number of active engines: 2 2026-04-21T12:26:27.503 EngineInit:Global ASOC is enabled 2026-04-21T12:26:27.503 EngineInit:ASOO is enabled for developer volumes 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.565 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T12:26:27.581 MpWriteUupSignatureVersion 1.449.225.0, hr = 0 2026-04-21T12:26:27.581 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-21T12:26:27.597 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-21T12:26:27.597 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T12:26:27.597 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-21T12:26:27.597 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-21T12:26:27.597 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-21T12:26:27.628 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-21T12:26:27.628 [Plugin] Initializing RTP plugin state... 2026-04-21T12:26:27.628 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-21T12:26:27.628 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎21‎-‎2026 14:16:03 Last Perf:‎04‎-‎21‎-‎2026 14:16:02 First RTP Scan:‎04‎-‎21‎-‎2026 14:16:03 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1943 Misses:2219 BM Queue:0,303,0 Proc:0,138,0 File:0,165,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:4375 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:12297296 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6488 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:26702 TotalHits:15681 InstanceCacheInserts:290 InstanceCacheUpdates:0 InstanceCacheDeletes:253 InstanceCacheHits:0 InstanceCacheMisses:7288 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (422/147) Success: 147, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-21T12:26:27.628 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9D79EB2E-5C35-4861-ADC0-CB64F7241908} 2026-04-21T12:26:27.628 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14A7F220-1EB8-4DA3-81D6-6798CFED922B} removed 2026-04-21T12:26:27.628 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621}\mpasbase.vdm in use, hr=0x80070020 2026-04-21T12:26:27.628 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-21T12:26:27.628 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.628 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.628 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.628 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.628 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-21-2026 12:26:27 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-21-2026 12:26:27 2026-04-21T12:26:27.628 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-21T12:26:27.628 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-21T12:26:27.643 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-21T12:26:27.643 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.643 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.643 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.643 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-21T12:26:27.643 MdCoreSvc is supported in this platform and OS 2026-04-21T12:26:27.643 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T12:26:27.643 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. Signature updated on 04-21-2026 12:26:27 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.225.0 AV Signature Version: 1.449.225.0 ************************************************************ 2026-04-21T12:26:27.643 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-21T12:26:27.643 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\710F82F2-EFDF-4896-85A8-00CC316572281b80.1dcd18a0a70f6fd 2026-04-21T12:26:27.737 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-21T12:26:27.737 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-21-2026 12:26:27 ************************************************************ 2026-04-21T12:26:27.753 Job Notification: Process exited from job (6012) 2026-04-21T12:26:27.753 Job Notification: Process exited from job (6024) 2026-04-21T12:26:27.831 Job Notification: Process exited from job (10908) 2026-04-21T12:26:27.831 Job Notification: Process exited from job (13252) 2026-04-21T12:26:28.065 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-21T12:26:28.065 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-21T12:26:28.065 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-21T12:26:28.065 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-21T12:26:28.065 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-21T12:26:28.065 [Engine] Engine 00007FFA7EF18020 no longer in use. Number of active engines: 1 2026-04-21T12:26:28.065 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-21T12:26:28.065 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-21T12:26:28.081 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-21T12:26:28.081 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-21T12:26:28.081 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-21T12:26:28.175 ProcessImageName: CCC.exe, Pid: 13412, TotalTime: 27608, Count: 388, MaxTime: 1796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 43% 2026-04-21T12:26:28.175 ProcessImageName: explorer.exe, Pid: 6192, TotalTime: 3529, Count: 46, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-21T12:26:28.175 ProcessImageName: AsPowerBar.exe, Pid: 13264, TotalTime: 3006, Count: 18, MaxTime: 1140, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 42% 2026-04-21T12:26:28.175 ProcessImageName: MOM.exe, Pid: 13300, TotalTime: 1850, Count: 30, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 45% 2026-04-21T12:26:28.175 ProcessImageName: AISuite3.exe, Pid: 6300, TotalTime: 1337, Count: 23, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 7% 2026-04-21T12:26:28.175 ProcessImageName: DipAwayMode.exe, Pid: 6276, TotalTime: 961, Count: 24, MaxTime: 312, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-04-21T12:26:28.175 ProcessImageName: websockify.exe, Pid: 11368, TotalTime: 912, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\_ssl.pyd, EstimatedImpact: 41% 2026-04-21T12:26:28.175 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2468, TotalTime: 420, Count: 63, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\ListSync\Common\microsoftNucleusTelemetryCache.otc-wal, EstimatedImpact: 7% 2026-04-21T12:26:28.175 ProcessImageName: WhatsApp.Root.exe, Pid: 12068, TotalTime: 240, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\5319275A.WhatsAppDesktop_2.2613.101.0_x64__cv1g1gvanyjgm\ActivationStore.dat.LOG1, EstimatedImpact: 0% 2026-04-21T12:26:28.175 ProcessImageName: brynhildr.exe, Pid: 3256, TotalTime: 186, Count: 4, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-21T12:26:28.175 ProcessImageName: PhoneExperienceHost.exe, Pid: 11560, TotalTime: 136, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 0% 2026-04-21T12:26:28.175 ProcessImageName: svchost.exe, Pid: 2020, TotalTime: 122, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 86% 2026-04-21T12:26:28.175 ProcessImageName: FileCoAuth.exe, Pid: 1508, TotalTime: 121, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-04-21T12:26:28.175 ProcessImageName: FileCoAuth.exe, Pid: 14032, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-04-21T12:26:28.206 [Engine] RSIG_UNLOADENGINE, 00007FFA7EF18020, err=0x0 2026-04-21T12:26:28.206 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F0B180FB-2EE3-40C7-8D68-850BD155C621} removed 2026-04-21T12:26:29.643 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T12:26:29.643 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-21T12:26:29.659 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-21T12:26:46.176 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-21T12:27:04.758 Process scan (postsignatureupdatescan) completed. 2026-04-21T12:27:45.285 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj08CEA59AA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4852, FileId: 0x100000000bd118, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.289 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFDFE2E90E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4856, FileId: 0x120000000bd118, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.302 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4918DC9E7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4854, FileId: 0xb0000000bd122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.353 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj38B44591A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4866, FileId: 0xa0000000bd123, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.413 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6279FA917. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4873, FileId: 0x130000000bd12e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.856 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7B6177975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4905, FileId: 0xd0000000bd123, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:45.884 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj000ED3977. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4906, FileId: 0xe0000000bd123, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:46.072 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC68A6D904. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #4922, FileId: 0xb0000000bd135, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:47.201 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7D98729A9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5014, FileId: 0xd0000000bd135, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:47.268 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj242A679CF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5015, FileId: 0xe0000000bd135, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:47.327 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF2664B96E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5018, FileId: 0xf0000000bd135, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:47.344 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5FF6209A6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5019, FileId: 0x100000000bd135, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:59.880 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5153, FileId: 0x140000000bd077, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:27:59.980 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5155, FileId: 0x120000000bd0c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:28:00.162 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5161, FileId: 0x150000000bd0f3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:29:00.244 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5461, FileId: 0x8500000000d6a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:30:46.104 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #5544, FileId: 0x24000000013ed1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:31:27.537 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-21T12:32:26.964 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6315, FileId: 0xf0000000bd0ea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:36:07.924 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T12:38:00.204 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6422, FileId: 0xf0000000bd0c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:38:00.224 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6424, FileId: 0xf0000000bd0ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:42:44.349 Bm signature throttled:0x00002db31bed458f 2026-04-21T12:49:05.709 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7038, FileId: 0x9e000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.709 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7037, FileId: 0x320000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.714 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7039, FileId: 0x9f000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.739 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7044, FileId: 0x360000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.739 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7041, FileId: 0x330000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.749 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7047, FileId: 0xa5000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.749 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7046, FileId: 0x380000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.754 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7049, FileId: 0x3a0000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.754 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7050, FileId: 0xa7000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.754 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7051, FileId: 0x3b0000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.759 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7052, FileId: 0xa8000000010087, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:05.774 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7048, FileId: 0x390000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:49:06.139 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\138a3d93-ec4b-4121-b516-66f7a1b4c4ec. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #7083, FileId: 0x14c000000002a38, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T12:51:12.925 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T13:01:44.695 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7288, FileId: 0xc0000000bd26f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T13:06:17.925 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T13:09:25.031 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-21T13:09:25.031 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-21T13:09:25.031 [RTP] Duplicating the current plugin configuration object... 2026-04-21T13:09:25.031 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-21T13:09:25.031 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-21T13:09:25.031 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-21T13:09:25.031 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-21T13:09:26.595 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Windows\Prefetch\MMC.EXE-A3710740.pf. Process: \Device\HarddiskVolume3\Windows\System32\mmc.exe, Status: 0xc000004b, State: 0, ScanRequest #7379, FileId: 0x7e000000004a4d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T13:13:23.630 Bm signature throttled:0x00002db31bed458f 2026-04-21T13:16:02.921 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-21T13:21:22.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T13:31:15.725 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9081, FileId: 0xb5000000004118, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T13:36:27.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T13:40:13.675 Bm signature throttled:0x00002db31bed458f 2026-04-21T13:46:41.216 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9415, FileId: 0x190000000bd296, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T13:51:32.925 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T13:52:12.685 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9437, FileId: 0x130000000bd2a7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:06:37.926 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T14:21:42.916 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T14:26:27.507 ProcessImageName: AcroCEF.exe, Pid: 11796, TotalTime: 4582, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 35% 2026-04-21T14:26:27.507 ProcessImageName: explorer.exe, Pid: 6192, TotalTime: 1975, Count: 56, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: mmc.exe, Pid: 7864, TotalTime: 1878, Count: 218, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Mff1be75b#\5cd7b68fb293600df1fbeeed175b22c4\Microsoft.ManagementConsole.ni.dll, EstimatedImpact: 49% 2026-04-21T14:26:27.507 ProcessImageName: svchost.exe, Pid: 476, TotalTime: 1780, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T14:26:27.507 ProcessImageName: xampp-control.exe, Pid: 6648, TotalTime: 1468, Count: 4, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 5% 2026-04-21T14:26:27.507 ProcessImageName: mysqld.exe, Pid: 960, TotalTime: 841, Count: 92, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 64% 2026-04-21T14:26:27.507 ProcessImageName: firefox.exe, Pid: 1036, TotalTime: 497, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07368, EstimatedImpact: 36% 2026-04-21T14:26:27.507 ProcessImageName: httpd.exe, Pid: 13976, TotalTime: 301, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 20% 2026-04-21T14:26:27.507 ProcessImageName: backgroundTaskHost.exe, Pid: 7944, TotalTime: 225, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-21T14:26:27.507 ProcessImageName: mysqld.exe, Pid: 4624, TotalTime: 225, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql\db.MAI, EstimatedImpact: 77% 2026-04-21T14:26:27.507 ProcessImageName: AdobeCollabSync.exe, Pid: 1212, TotalTime: 211, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\collab_low\6bda834a-dce5-4d6e-8ce5-7bc8b1ee801e_temp.zip, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: Notepad.exe, Pid: 11360, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8798426f-49af-4c5e-960d-c26db8da228e.1.bin, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: mmc.exe, Pid: 240, TotalTime: 185, Count: 7, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 1% 2026-04-21T14:26:27.507 ProcessImageName: Acrobat.exe, Pid: 2032, TotalTime: 153, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 7% 2026-04-21T14:26:27.507 ProcessImageName: SDXHelper.exe, Pid: 6464, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 3% 2026-04-21T14:26:27.507 ProcessImageName: SDXHelper.exe, Pid: 7840, TotalTime: 122, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0D313E3-E137-411E-AF44-E7B38EF7163E, EstimatedImpact: 7% 2026-04-21T14:26:27.507 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 93, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: OfficeC2RClient.exe, Pid: 14108, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 3% 2026-04-21T14:26:27.507 ProcessImageName: xampp-control.exe, Pid: 7652, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: cmd.exe, Pid: 3216, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\WF.msc, EstimatedImpact: 4% 2026-04-21T14:26:27.507 ProcessImageName: xampp-control.exe, Pid: 1356, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\locale\de\LC_MESSAGES\xampp_control.mo, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: Acrobat.exe, Pid: 8408, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-04-21T14:26:27.507 ProcessImageName: OfficeC2RClient.exe, Pid: 9900, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 1% 2026-04-21T14:26:27.507 ProcessImageName: AcroCEF.exe, Pid: 11520, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0, EstimatedImpact: 11% 2026-04-21T14:26:27.507 ProcessImageName: OfficeC2RClient.exe, Pid: 3636, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1552.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 3468, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\StaticCache.dat, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: PhoneExperienceHost.exe, Pid: 11560, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: OfficeC2RClient.exe, Pid: 10172, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1546.log, EstimatedImpact: 1% 2026-04-21T14:26:27.507 ProcessImageName: AdobeARM.exe, Pid: 14016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 3% 2026-04-21T14:26:27.507 ProcessImageName: dllhost.exe, Pid: 6052, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: SDXHelper.exe, Pid: 9136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 3% 2026-04-21T14:26:27.507 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10904, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-21T14:26:27.507 ProcessImageName: OfficeC2RClient.exe, Pid: 14328, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1501.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2468, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: Notepad.exe, Pid: 4588, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\194337c4-3904-4e2d-aeb6-7eaac4af04a4.bin, EstimatedImpact: 2% 2026-04-21T14:26:27.507 ProcessImageName: xampp-control.exe, Pid: 5464, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 8216, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: AggregatorHost.exe, Pid: 5404, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: svchost.exe, Pid: 2224, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: dllhost.exe, Pid: 6620, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-38.pri, EstimatedImpact: 13% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 2060, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: cmd.exe, Pid: 5240, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 11048, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 8260, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 6884, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 1872, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: svchost.exe, Pid: 8280, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: Notepad.exe, Pid: 4344, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-04-21T14:26:27.507 ProcessImageName: FileZilla Server Interface.exe, Pid: 11520, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T14:31:48.696 Bm signature throttled:0x00002db31bed458f 2026-04-21T14:34:08.610 Bm signature throttled:0x00002db31bed458f 2026-04-21T14:36:47.926 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T14:38:15.326 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10124, FileId: 0x110000000bd2a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:48:22.267 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php798.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10349, FileId: 0x6c0000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:49:12.097 Bm signature throttled:0x00002db31bed458f 2026-04-21T14:51:52.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T14:53:14.517 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7D23.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10441, FileId: 0x6e0000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:53:17.867 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8A34.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10443, FileId: 0x6f0000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:53:26.287 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAB1B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10446, FileId: 0x700000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:55:04.757 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2BC1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10451, FileId: 0xf0000000bd2b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:55:08.237 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php396E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10453, FileId: 0x100000000bd2b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:55:10.037 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4074.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10455, FileId: 0x110000000bd2b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T14:55:19.927 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php66F8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10457, FileId: 0x720000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:00:40.677 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4BFB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10716, FileId: 0x770000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:00:47.687 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6763.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10724, FileId: 0x780000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:01:44.953 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4706.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10731, FileId: 0xf0000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:01:50.107 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5B3B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10733, FileId: 0x100000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:10.297 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAA18.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10737, FileId: 0x110000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:10.497 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAAE4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10739, FileId: 0x120000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:12.137 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB12E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10740, FileId: 0x130000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:12.417 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB268.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10742, FileId: 0x7a0000000038cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:17.147 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC4D7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10743, FileId: 0x370000000b84ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:17.467 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC620.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10745, FileId: 0x380000000b84ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:02:52.817 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5022.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10746, FileId: 0x390000000b84ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:34.147 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF1A2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10750, FileId: 0x1a00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:37.647 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFF4F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10752, FileId: 0x1b00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:40.517 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA8B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10754, FileId: 0x1c00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:45.407 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1DA7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10756, FileId: 0x1d00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:53.907 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3EDC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10758, FileId: 0x1e00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:56.787 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A18.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10760, FileId: 0x1f00000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:03:59.517 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php54C7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10762, FileId: 0x2000000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:04:05.127 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6AB2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10764, FileId: 0x2100000001aad0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:04:38.717 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10776, FileId: 0x150000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:05:26.847 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA9E9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #10780, FileId: 0x160000000bd2c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:06:57.927 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T15:10:20.007 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10788, FileId: 0xa0000000b85c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:22:02.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T15:24:34.167 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10855, FileId: 0xe0000000b85cd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T15:37:07.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T15:52:12.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T15:57:43.423 [RTP] [Mini-filter] OpenWithoutRead notification (1481, 10142, ) sent successfully. 2026-04-21T16:07:17.918 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T16:22:22.908 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T16:26:27.518 ProcessImageName: AcroCEF.exe, Pid: 11796, TotalTime: 4582, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 35% 2026-04-21T16:26:27.518 ProcessImageName: notepad++.exe, Pid: 5760, TotalTime: 3921, Count: 324, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_105.php, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: explorer.exe, Pid: 6192, TotalTime: 2337, Count: 87, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: mmc.exe, Pid: 7864, TotalTime: 1878, Count: 218, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Mff1be75b#\5cd7b68fb293600df1fbeeed175b22c4\Microsoft.ManagementConsole.ni.dll, EstimatedImpact: 49% 2026-04-21T16:26:27.518 ProcessImageName: svchost.exe, Pid: 476, TotalTime: 1780, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T16:26:27.518 ProcessImageName: xampp-control.exe, Pid: 6648, TotalTime: 1468, Count: 4, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 5% 2026-04-21T16:26:27.518 ProcessImageName: httpd.exe, Pid: 3712, TotalTime: 1147, Count: 105, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_105.php->(SCRIPT0044), EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: mysqld.exe, Pid: 960, TotalTime: 841, Count: 92, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 64% 2026-04-21T16:26:27.518 ProcessImageName: notepad++.exe, Pid: 6196, TotalTime: 800, Count: 51, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 7% 2026-04-21T16:26:27.518 ProcessImageName: firefox.exe, Pid: 1036, TotalTime: 497, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07368, EstimatedImpact: 36% 2026-04-21T16:26:27.518 ProcessImageName: httpd.exe, Pid: 13976, TotalTime: 301, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 20% 2026-04-21T16:26:27.518 ProcessImageName: backgroundTaskHost.exe, Pid: 7944, TotalTime: 225, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-21T16:26:27.518 ProcessImageName: mysqld.exe, Pid: 4624, TotalTime: 225, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql\db.MAI, EstimatedImpact: 77% 2026-04-21T16:26:27.518 ProcessImageName: AdobeCollabSync.exe, Pid: 1212, TotalTime: 211, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\collab_low\6bda834a-dce5-4d6e-8ce5-7bc8b1ee801e_temp.zip, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: Notepad.exe, Pid: 11360, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8798426f-49af-4c5e-960d-c26db8da228e.1.bin, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: mmc.exe, Pid: 240, TotalTime: 185, Count: 7, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: Acrobat.exe, Pid: 2032, TotalTime: 153, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 7% 2026-04-21T16:26:27.518 ProcessImageName: SDXHelper.exe, Pid: 6464, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 3% 2026-04-21T16:26:27.518 ProcessImageName: SDXHelper.exe, Pid: 7840, TotalTime: 122, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0D313E3-E137-411E-AF44-E7B38EF7163E, EstimatedImpact: 7% 2026-04-21T16:26:27.518 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 93, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 14108, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 3% 2026-04-21T16:26:27.518 ProcessImageName: xampp-control.exe, Pid: 7652, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: cmd.exe, Pid: 3216, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\WF.msc, EstimatedImpact: 4% 2026-04-21T16:26:27.518 ProcessImageName: xampp-control.exe, Pid: 1356, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\locale\de\LC_MESSAGES\xampp_control.mo, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 5140, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1724.log, EstimatedImpact: 2% 2026-04-21T16:26:27.518 ProcessImageName: Acrobat.exe, Pid: 8408, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 9900, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2468, TotalTime: 45, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 3468, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\StaticCache.dat, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: AcroCEF.exe, Pid: 11520, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0, EstimatedImpact: 11% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 3636, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1552.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-21T16:26:27.518 ProcessImageName: dllhost.exe, Pid: 6052, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: PhoneExperienceHost.exe, Pid: 11560, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: AggregatorHost.exe, Pid: 5404, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: dasHost.exe, Pid: 5412, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 3% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 10172, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1546.log, EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 780, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1638.log, EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: AdobeARM.exe, Pid: 14016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 3% 2026-04-21T16:26:27.518 ProcessImageName: SDXHelper.exe, Pid: 9136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 3% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 9664, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1710.log, EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10904, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 14328, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1501.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: Notepad.exe, Pid: 4588, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\194337c4-3904-4e2d-aeb6-7eaac4af04a4.bin, EstimatedImpact: 2% 2026-04-21T16:26:27.518 ProcessImageName: xampp-control.exe, Pid: 5464, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: OfficeC2RClient.exe, Pid: 11628, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1704.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 8216, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: svchost.exe, Pid: 2224, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: dllhost.exe, Pid: 6620, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-38.pri, EstimatedImpact: 13% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 2060, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 6884, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 1872, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: cmd.exe, Pid: 5240, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 8260, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 11520, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: FileZilla Server Interface.exe, Pid: 11048, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: Notepad.exe, Pid: 4344, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-04-21T16:26:27.518 ProcessImageName: svchost.exe, Pid: 8280, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T16:28:24.867 Bm signature throttled:0x00002db31bed458f 2026-04-21T16:28:26.052 Bm signature throttled:0x00002db31bed458f 2026-04-21T16:28:26.371 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #11969, FileId: 0xe0000000b8bb2, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T16:28:26.581 Engine:Process 692 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-21T16:28:30.432 Bm signature throttled:0x00002db31bed458f 2026-04-21T16:34:13.156 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13002, FileId: 0xc0000000b8acb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T16:37:27.911 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T16:39:06.400 Bm signature throttled:0x00002db31bed458f 2026-04-21T16:51:20.288 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Windows\Prefetch\PARTITIONWIZARD.EXE-74ED46E5.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\PartitionWizard.exe, Status: 0xc000004b, State: 0, ScanRequest #13241, FileId: 0x2a000000003e33, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T16:51:34.129 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume1\EFI\Microsoft\Boot\BCD.LOG 2026-04-21T16:52:32.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T16:56:21.163 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13388, FileId: 0x240000000bd4e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T16:56:56.241 Bm signature throttled:0x00002db31bed458f 2026-04-21T17:07:25.980 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php583F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13660, FileId: 0x340000000bcf38, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:07:37.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T17:11:11.585 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC98A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13763, FileId: 0x319000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:11:16.615 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDD22.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13765, FileId: 0x31a000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:12:53.816 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php58D7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13777, FileId: 0x31c000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:12:55.754 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6079.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13779, FileId: 0x31d000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:13:00.506 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php72F8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13783, FileId: 0x31e000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:13:02.368 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7A4C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13785, FileId: 0x31f000000004cd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:22:42.919 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T17:25:52.327 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php39EE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14616, FileId: 0x33000000040079, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:25:55.192 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php451B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14620, FileId: 0x34000000040079, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:26:00.583 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5A2A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14622, FileId: 0x36000000040079, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:34:33.732 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2E81.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14719, FileId: 0x140000000b89c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:34:56.332 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php86D3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14725, FileId: 0x1d0000000b89c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:34:58.266 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8E56.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14727, FileId: 0x1e0000000b89c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:34:59.966 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php94FE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14729, FileId: 0x160000000b89c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:35:04.414 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA654.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14731, FileId: 0x170000000b89c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:35:06.356 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAE06.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14733, FileId: 0x180000000b89c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:35:22.442 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpECE5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14739, FileId: 0x190000000b89c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:37:47.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T17:47:09.489 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14836, FileId: 0xb0000000bcb2f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:52:52.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T17:54:40.148 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14914, FileId: 0x420000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.148 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14911, FileId: 0x410000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.150 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14915, FileId: 0x430000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.151 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14916, FileId: 0x87000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.152 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14913, FileId: 0x86000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.166 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14919, FileId: 0x460000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.167 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14921, FileId: 0x470000000333e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:54:40.169 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14920, FileId: 0x8a000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T17:57:34.118 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3EDF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15125, FileId: 0x190000000bcb25, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T18:00:36.107 Bm signature throttled:0x00002db31bed458f 2026-04-21T18:07:57.916 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T18:13:02.739 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6A4B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15391, FileId: 0x650000000383f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T18:16:14.517 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #15461, FileId: 0xc0000000bd0a4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-21T18:23:02.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T18:26:27.530 ProcessImageName: notepad++.exe, Pid: 5760, TotalTime: 6397, Count: 543, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_105.php, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: explorer.exe, Pid: 6192, TotalTime: 5972, Count: 251, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: AcroCEF.exe, Pid: 11796, TotalTime: 4582, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 35% 2026-04-21T18:26:27.530 ProcessImageName: httpd.exe, Pid: 3712, TotalTime: 2050, Count: 202, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_105.php->(SCRIPT0044), EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: mmc.exe, Pid: 7864, TotalTime: 1878, Count: 218, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Mff1be75b#\5cd7b68fb293600df1fbeeed175b22c4\Microsoft.ManagementConsole.ni.dll, EstimatedImpact: 49% 2026-04-21T18:26:27.530 ProcessImageName: svchost.exe, Pid: 476, TotalTime: 1780, Count: 3, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-21T18:26:27.530 ProcessImageName: PartitionWizard.exe, Pid: 2200, TotalTime: 1604, Count: 14, MaxTime: 765, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 11% 2026-04-21T18:26:27.530 ProcessImageName: xampp-control.exe, Pid: 6648, TotalTime: 1468, Count: 4, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 5% 2026-04-21T18:26:27.530 ProcessImageName: mysqld.exe, Pid: 960, TotalTime: 841, Count: 92, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 64% 2026-04-21T18:26:27.530 ProcessImageName: notepad++.exe, Pid: 6196, TotalTime: 800, Count: 51, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 7% 2026-04-21T18:26:27.530 ProcessImageName: WmiPrvSE.exe, Pid: 13972, TotalTime: 601, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 86% 2026-04-21T18:26:27.530 ProcessImageName: firefox.exe, Pid: 1036, TotalTime: 497, Count: 50, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07368, EstimatedImpact: 36% 2026-04-21T18:26:27.530 ProcessImageName: firefox.exe, Pid: 1476, TotalTime: 450, Count: 46, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa00372, EstimatedImpact: 59% 2026-04-21T18:26:27.530 ProcessImageName: httpd.exe, Pid: 13976, TotalTime: 301, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 20% 2026-04-21T18:26:27.530 ProcessImageName: backgroundTaskHost.exe, Pid: 7944, TotalTime: 225, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-21T18:26:27.530 ProcessImageName: mysqld.exe, Pid: 4624, TotalTime: 225, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql\db.MAI, EstimatedImpact: 77% 2026-04-21T18:26:27.530 ProcessImageName: AdobeCollabSync.exe, Pid: 1212, TotalTime: 211, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\collab_low\6bda834a-dce5-4d6e-8ce5-7bc8b1ee801e_temp.zip, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: Notepad.exe, Pid: 11360, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8798426f-49af-4c5e-960d-c26db8da228e.1.bin, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: mmc.exe, Pid: 240, TotalTime: 185, Count: 7, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\views[1], EstimatedImpact: 1% 2026-04-21T18:26:27.530 ProcessImageName: TabTip.exe, Pid: 256, TotalTime: 155, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 93% 2026-04-21T18:26:27.530 ProcessImageName: Acrobat.exe, Pid: 2032, TotalTime: 153, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 7% 2026-04-21T18:26:27.530 ProcessImageName: SDXHelper.exe, Pid: 6464, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 3% 2026-04-21T18:26:27.530 ProcessImageName: , Pid: 4, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdspio.sys, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: SDXHelper.exe, Pid: 7840, TotalTime: 122, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\C0D313E3-E137-411E-AF44-E7B38EF7163E, EstimatedImpact: 7% 2026-04-21T18:26:27.530 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 121, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: FileCoAuth.exe, Pid: 5784, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-21T18:26:27.530 ProcessImageName: svchost.exe, Pid: 2100, TotalTime: 93, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 14108, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71BF7B49-5BB7-4EBF-A201-C8BD7F5EFD7A, EstimatedImpact: 3% 2026-04-21T18:26:27.530 ProcessImageName: xampp-control.exe, Pid: 7652, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: cmd.exe, Pid: 3216, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\WF.msc, EstimatedImpact: 4% 2026-04-21T18:26:27.530 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2468, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: SecurityHealthHost.exe, Pid: 9712, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 6% 2026-04-21T18:26:27.530 ProcessImageName: AggregatorHost.exe, Pid: 5404, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: xampp-control.exe, Pid: 1356, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\locale\de\LC_MESSAGES\xampp_control.mo, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 7732, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 2% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 5140, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1724.log, EstimatedImpact: 2% 2026-04-21T18:26:27.530 ProcessImageName: Acrobat.exe, Pid: 8408, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 9900, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 1% 2026-04-21T18:26:27.530 ProcessImageName: FileZilla Server Interface.exe, Pid: 3468, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\StaticCache.dat, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 3636, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1552.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-21T18:26:27.530 ProcessImageName: AcroCEF.exe, Pid: 11520, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0, EstimatedImpact: 11% 2026-04-21T18:26:27.530 ProcessImageName: dllhost.exe, Pid: 6052, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 6208, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1834.log, EstimatedImpact: 2% 2026-04-21T18:26:27.530 ProcessImageName: PhoneExperienceHost.exe, Pid: 11560, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 4304, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-2000.log, EstimatedImpact: 2% 2026-04-21T18:26:27.530 ProcessImageName: dasHost.exe, Pid: 5412, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 3% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 10172, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1546.log, EstimatedImpact: 1% 2026-04-21T18:26:27.530 ProcessImageName: OfficeC2RClient.exe, Pid: 780, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1638.log, EstimatedImpact: 1% 2026-04-21T18:26:27.530 ProcessImageName: AdobeARM.exe, Pid: 14016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 3% 2026-04-21T18:26:27.531 ProcessImageName: SDXHelper.exe, Pid: 9136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 3% 2026-04-21T18:26:27.531 ProcessImageName: OfficeC2RClient.exe, Pid: 10192, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1947.log, EstimatedImpact: 1% 2026-04-21T18:26:27.531 ProcessImageName: OfficeC2RClient.exe, Pid: 9664, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1710.log, EstimatedImpact: 1% 2026-04-21T18:26:27.531 ProcessImageName: SDXHelper.exe, Pid: 3028, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 8% 2026-04-21T18:26:27.531 ProcessImageName: atieclxx.exe, Pid: 8740, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\oem2.PNF, EstimatedImpact: 10% 2026-04-21T18:26:27.531 ProcessImageName: FileZillaServer.exe, Pid: 11020, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\02_FTP\06_Technische Bearbeitung\PVI\01_Dokumentation_Myportal\B\B330\Behälter_B330_Zeichnung_O814.pdf, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 10904, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-21T18:26:27.531 ProcessImageName: OfficeC2RClient.exe, Pid: 14328, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1501.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: Notepad.exe, Pid: 4588, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\194337c4-3904-4e2d-aeb6-7eaac4af04a4.bin, EstimatedImpact: 2% 2026-04-21T18:26:27.531 ProcessImageName: OfficeC2RClient.exe, Pid: 11628, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-1704.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: OfficeC2RClient.exe, Pid: 4776, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260421-2016.log, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: xampp-control.exe, Pid: 5464, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: dllhost.exe, Pid: 6620, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.26.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-38.pri, EstimatedImpact: 13% 2026-04-21T18:26:27.531 ProcessImageName: svchost.exe, Pid: 2224, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 8216, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: TeamViewer.exe, Pid: 6512, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 5% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 2060, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: cmd.exe, Pid: 5240, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 6884, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 8260, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 11520, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 1872, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: FileZilla Server Interface.exe, Pid: 11048, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZilla Server Interface.xml, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: svchost.exe, Pid: 8280, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat, EstimatedImpact: 0% 2026-04-21T18:26:27.531 ProcessImageName: Notepad.exe, Pid: 4344, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-04-21T18:38:07.915 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-21T18:47:22.543 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\4A04D1E9-41D9-4325-AD57-4D63BAF9BE5B36bc.1dcd1bf48cd0636 2026-04-21T18:47:22.632 Verifying engine and signature files (source: 0) ... 2026-04-21T18:47:22.632 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpengine.dll] due to PPL. 2026-04-21T18:47:22.632 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasbase.vdm] (file in cache) 2026-04-21T18:47:22.632 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-21T18:47:22.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasdlta.vdm] 2026-04-21T18:47:22.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpavbase.vdm] (file in cache) 2026-04-21T18:47:22.648 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-21T18:47:22.663 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpavdlta.vdm] 2026-04-21T18:47:22.818 [Engine] IsHybridMode: 0 2026-04-21T18:47:22.818 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-21T18:47:22.824 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3C62C8FBBED15C7A354E7969D8DDE78E174B0866.bin): 0x00000002 2026-04-21T18:47:22.831 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3C62C8FBBED15C7A354E7969D8DDE78E174B0866.bin) 2026-04-21T18:47:22.831 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-21T18:47:22.831 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-21T18:47:22.831 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-21T18:47:22.831 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-21T18:47:34.711 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-21T18:47:34.712 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-21T18:47:34.731 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFA217F8020, lRefCount: 5, hr=0 2026-04-21T18:47:34.731 [Engine] New active engine 00007FFA0CD08020 replacing engine 00007FFA217F8020. Number of active engines: 2 2026-04-21T18:47:34.737 EngineInit:Global ASOC is enabled 2026-04-21T18:47:34.737 EngineInit:ASOO is enabled for developer volumes 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.801 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.802 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-21T18:47:34.811 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d82c0f9ac9458f091392a5850ee343cbbd1537c0 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:864000000 2026-04-21T18:47:34.816 MpWriteUupSignatureVersion 1.449.230.0, hr = 0 2026-04-21T18:47:34.817 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-21T18:47:34.834 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-21T18:47:34.835 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-21T18:47:34.835 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-21T18:47:34.835 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-21T18:47:34.835 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-21T18:47:34.856 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-21T18:47:34.857 [Plugin] Initializing RTP plugin state... 2026-04-21T18:47:34.857 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-21T18:47:34.857 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎21‎-‎2026 14:26:28 Last Perf:‎04‎-‎21‎-‎2026 14:26:27 First RTP Scan:‎04‎-‎21‎-‎2026 14:26:28 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1608 Misses:8380 BM Queue:0,426,0 Proc:0,263,0 File:0,346,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:15916 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:237168340 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:12712 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:60194 TotalHits:285447 InstanceCacheInserts:1572 InstanceCacheUpdates:0 InstanceCacheDeletes:291 InstanceCacheHits:159 InstanceCacheMisses:18837 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (2087/825) Success: 825, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-22-2026 05:55:53 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/22/2026 05:55:53.419838500 UTC (15140 ms since boot) 2026-04-22T05:55:53.458 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-22T05:55:53.463 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-22T05:55:53.463 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-22T05:55:53.548 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260422-055553-00000003-fffffffeffffffff.bin ... 2026-04-22T05:55:53.677 [WPP] Trace session started - MpWppTracing-20260422-055553-00000003-fffffffeffffffff.bin 2026-04-22T05:55:53.687 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-22T05:55:53.687 [RbM] Rollback manager succesfully initialized. 2026-04-22T05:55:53.687 [RbM] Rollback manager EnableRollbackManager called. 2026-04-22T05:55:53.697 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-22T05:55:53.697 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-22T05:55:53.697 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-22T05:55:53.697 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-22T05:55:53.697 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-22T05:55:53.703 MdCoreSvc is supported in this platform and OS 2026-04-22T05:55:53.703 MdCoreSvc is supported in this platform and OS 2026-04-22T05:55:53.703 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-22T05:55:53.703 [PlatUpd] Starting MdCoreSvc service 2026-04-22T05:55:53.747 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-22T05:55:58.932 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-22T05:55:58.932 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-22T05:55:58.932 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-22T05:55:58.932 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-22T05:55:58.932 [PlatUpd] CSP platform update started 2026-04-22T05:55:58.932 [PlatUpd] Defender MDM CSP platform update not required 2026-04-22T05:55:58.932 [PlatUpd] WMI/PS provider platform update started 2026-04-22T05:55:58.932 [PlatUpd] WMI/PS provider platform update not required 2026-04-22T05:55:58.932 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-22T05:55:58.932 MdCoreSvc is supported in this platform and OS 2026-04-22T05:55:58.932 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-22T05:55:58.932 [PlatUpd] Starting MdCoreSvc service 2026-04-22T05:55:58.932 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-22T05:55:58.932 [TS] Troublshooting mode is not available! 2026-04-22T05:55:58.932 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-22T05:55:58.932 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-22T05:55:58.963 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-22T05:55:58.963 [Service] Enabling AutoLoggers ... 2026-04-22T05:55:58.963 [Service] Enabling AMSI registration ... 2026-04-22T05:55:58.963 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-22T05:55:58.979 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52325 Number of invalid entries is 0 Number of inserts issued is 1573238 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6412 Number of lookups is 107066798 Number of lookup misses is 5126815 Number of fast lookup misses is 54612574 Number of false fast lookups is 5126810 Number of invalidations is 729212 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-22T05:55:58.979 Verifying license file... 2026-04-22T05:55:58.979 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-22T05:55:58.995 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-22T05:55:58.995 Loaded module#0 MpComServer. 2026-04-22T05:55:58.995 Loaded module#1 StartupPolicies. 2026-04-22T05:55:58.995 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-22T05:55:58.995 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-22T05:55:59.010 COM server initialized successfully. 2026-04-22T05:55:59.010 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-22T05:55:59.026 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-22T05:55:59.026 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-22T05:55:59.041 [RTP] [RTP] FilterCommunicator object 0x000001F2FC849DB0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-22T05:55:59.057 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-22T05:55:59.057 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-22T05:55:59.057 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-22T05:55:59.057 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-22T05:55:59.057 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-22T05:55:59.057 [RTP] [RTP] FilterCommunicator object 0x000001F2FC80DF70 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-22T05:55:59.057 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-22T05:55:59.057 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-22T05:55:59.057 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-22T05:55:59.057 [RTP] [RTP] StartCommunication 0x000001F2FC849DB0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-22T05:55:59.057 [init][RTP] RTPPlugin initialization completed 2026-04-22T05:55:59.057 OS boot count = 2 2026-04-22T05:55:59.057 OS Install = 0 2026-04-22T05:55:59.135 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-22T05:55:59.135 [KSL] Entering CKSLEngine::Initialize. 2026-04-22T05:55:59.135 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-22T05:55:59.135 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-22T05:55:59.135 [KSL] MpInstallKslD: hr=0x1 2026-04-22T05:55:59.135 [KSL] MpRegisterKslD: hr=0 2026-04-22T05:55:59.151 [KSL] MpStartKslD: hr=0 2026-04-22T05:55:59.151 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-22T05:55:59.151 Loading engine... 2026-04-22T05:55:59.166 Verifying engine and signature files (source: 1) ... 2026-04-22T05:55:59.166 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpengine.dll] due to PPL. 2026-04-22T05:55:59.166 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasbase.vdm] (file in cache) 2026-04-22T05:55:59.166 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasdlta.vdm] (file in cache) 2026-04-22T05:55:59.166 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpavbase.vdm] (file in cache) 2026-04-22T05:55:59.166 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpavdlta.vdm] (file in cache) 2026-04-22T05:55:59.229 [Engine] IsHybridMode: 0 2026-04-22T05:55:59.229 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-22T05:55:59.276 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3C62C8FBBED15C7A354E7969D8DDE78E174B0866.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-22T05:56:14.224 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-22T05:56:14.224 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-22T05:56:14.224 [Engine] New active engine 00007FFC00CB8020 (no old engine). Number of active engines: 1 2026-04-22T05:56:14.239 EngineInit:Global ASOC is enabled 2026-04-22T05:56:14.239 EngineInit:ASOO is enabled for developer volumes 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.349 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T05:56:14.427 MpWriteUupSignatureVersion 1.449.230.0, hr = 0 2026-04-22T05:56:14.427 [SigStatUpd] CSignatureStatus: back to good 2026-04-22T05:56:14.427 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-22T05:56:14.458 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-22T05:56:14.458 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-22T05:56:14.458 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-22T05:56:14.458 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-22T05:56:14.458 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-22T05:56:14.489 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-22T05:56:14.489 [Plugin] Initializing RTP plugin state... 2026-04-22T05:56:14.489 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3687 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18647 TotalHits:0 InstanceCacheInserts:29 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3914 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-22T05:56:14.489 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-22T05:56:14.489 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C} 2026-04-22T05:56:14.489 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T05:56:14.489 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T05:56:14.489 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T05:56:14.489 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T05:56:14.489 MdCoreSvc is supported in this platform and OS 2026-04-22T05:56:14.489 Engine loaded! 2026-04-22T05:56:14.489 [DLP] Create FeatureControlState instance 2026-04-22T05:56:14.505 RegisterSModeChangeListener: hr = 0x1 2026-04-22T05:56:14.505 RegisterHybridModeChangeListener: hr = 0 2026-04-22T05:56:14.505 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-22T05:56:14.505 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-22T05:56:14.505 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-22T05:56:14.505 [SigReleaseHb] Initialized with Stage 0 2026-04-22T05:56:14.505 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-22T05:56:14.521 [SCC][CID=36234_5452] Initializing ... 2026-04-22T05:56:14.521 [SCC][CID=36234_5452] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-22T05:56:14.521 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-22T05:56:14.521 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-22T05:56:14.521 [NRI] Stopping NIS service ... 2026-04-22T05:56:14.521 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-22T05:56:14.521 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.230.0 AV Signature Version: 1.449.230.0 ************************************************************ 2026-04-22T05:56:14.521 Resource usage Monitoring is enabled 2026-04-22T05:56:14.521 Job Notification: New process added to job (4616) 2026-04-22T05:56:14.521 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-22T05:56:14.536 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-22T05:56:14.552 Job Notification: New process added to job (6068) 2026-04-22T05:56:14.552 Job Notification: New process added to job (5648) 2026-04-22T05:56:14.567 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6068] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5648]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-22T05:56:14.646 Job Notification: Process exited from job (6068) 2026-04-22T05:56:14.646 Job Notification: Process exited from job (5648) 2026-04-22T05:56:14.646 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-22T05:56:14.646 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-22T05:56:14.661 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-22T05:56:14.661 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-22T05:56:14.661 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-22T05:56:14.661 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-22T05:56:14.661 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-22T05:56:14.661 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-22T05:56:14.661 [RTP] Generating the base plugin configuration ... 2026-04-22T05:56:14.661 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-22T05:56:14.661 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T05:56:14.661 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-22T05:56:14.661 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-22T05:56:14.661 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T05:56:14.661 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-22T05:56:14.661 [RTP] [RTP] StartCommunication 0x000001F2FC80DF70 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-22T05:56:14.677 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-22T05:56:14.677 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\Version\AppSetup.ini 2026-04-22T05:56:14.941 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-22T05:56:14.941 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-22T05:56:14.941 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-22T05:56:15.004 [AutoPurge] Verification Routine tasks have started. 2026-04-22T05:56:15.004 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-22T05:56:15.019 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:15.285 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-22T05:56:15.301 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-22T05:56:15.332 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-22T05:56:15.738 Job Notification: New process added to job (11408) 2026-04-22T05:56:15.738 Task(GetDeviceTicket -AccessKey A52E2439-913E-FD64-4B22-3DCFD85268ED ) launched as network service 2026-04-22T05:56:16.207 Job Notification: Process exited from job (11408) 2026-04-22T05:56:16.804 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-22T05:56:16.837 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:16.845 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:16.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:16.866 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:16.870 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:16.875 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-22T05:56:16.875 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-22T05:56:16.875 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-22T05:56:16.875 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-22T05:56:16.875 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-22T05:56:16.876 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-22T05:56:16.876 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-22T05:56:16.876 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-22T05:56:16.876 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-22T05:56:16.876 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-22T05:56:16.876 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-22T05:56:16.877 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-22T05:56:16.877 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-22T05:56:16.877 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-22T05:56:16.877 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-22T05:56:16.877 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-22T05:56:16.877 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-22T05:56:16.878 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-22T05:56:16.878 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-22T05:56:16.878 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-22T05:56:17.419 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-22T05:56:17.422 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T05:56:17.422 [Cloud] Queued cloud request. 2026-04-22T05:56:17.423 [Cloud] Dequeued cloud request. 2026-04-22T05:56:17.428 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T05:56:17.446 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-22T05:56:17.450 [AutoPurge] Verification Routine tasks have ended. 2026-04-22T05:56:17.612 [RTP] Duplicating the current plugin configuration object... 2026-04-22T05:56:17.612 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-22T05:56:17.612 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-04-22T05:56:17.613 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T05:56:17.613 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-22T05:56:17.613 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-04-22T05:56:17.756 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-22T05:56:17.769 [Cloud] End of cloud request. 2026-04-22T05:56:17.941 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T05:56:30.114 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #1097, FileId: 0x110000000398ab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T05:56:58.992 Process scan (poststartupscan) started. 2026-04-22T05:56:58.992 Process scan (poststartupscan) completed. 2026-04-22T05:57:08.762 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-04-22T05:57:08.762 [RTP] Duplicating the current plugin configuration object... 2026-04-22T05:57:08.762 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-22T05:57:08.762 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-22T05:57:08.762 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-22T05:57:08.778 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-22T05:57:08.872 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-22T05:57:09.575 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-22T05:57:27.162 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2965, FileId: 0xa0000000b8ab4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T05:57:55.766 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T05:57:55.766 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-22T05:57:55.766 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:00:56.431 Bm signature throttled:0x00002db31bed458f 2026-04-22T06:00:59.446 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #3966, FileId: 0x72000000007f1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:01:14.283 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-22T06:01:14.518 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T06:02:05.952 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4134, FileId: 0x20400000000035c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4141, FileId: 0x185000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4139, FileId: 0x20500000000035c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4142, FileId: 0x20900000000035c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:05.967 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4140, FileId: 0x182000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.014 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4135, FileId: 0x181000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.014 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4145, FileId: 0x186000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.014 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4146, FileId: 0x187000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.014 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4144, FileId: 0x20a00000000035c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.530 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4180, FileId: 0x94000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.546 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4182, FileId: 0x191000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.546 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4179, FileId: 0x190000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.546 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4181, FileId: 0x95000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.561 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4185, FileId: 0x99000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.592 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4192, FileId: 0x197000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.592 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4191, FileId: 0x9b000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.608 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4188, FileId: 0x9a000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.639 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4198, FileId: 0x9d000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.639 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4202, FileId: 0x19a000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.639 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4201, FileId: 0x9e000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.655 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4205, FileId: 0x19c000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.905 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4240, FileId: 0x3930000000001f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.905 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4242, FileId: 0x3940000000001f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.905 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4241, FileId: 0x19d000000001360, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:06.921 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4239, FileId: 0x3920000000001f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:07.905 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4354, FileId: 0x1330000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:02:08.952 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4477, FileId: 0x2300000003361c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:06:14.511 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-22T06:06:14.511 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-22T06:06:14.527 Job Notification: New process added to job (6720) 2026-04-22T06:06:14.527 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-22T06:06:14.527 Aggressive catchup quick scan threshold: 1044806819147 / 25920000000000 2026-04-22T06:06:14.527 Job Notification: New process added to job (13900) 2026-04-22T06:06:14.542 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6720] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:13900]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-22T06:06:14.605 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 76439327(ms) from now at 05:20 (03:20 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-22T06:06:14.657 Job Notification: New process added to job (6088) 2026-04-22T06:06:14.657 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-22T06:06:14.657 Job Notification: New process added to job (2448) 2026-04-22T06:06:14.673 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6088] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2448]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-22T06:06:15.048 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-22T06:06:15.048 [RTP] Duplicating the current plugin configuration object... 2026-04-22T06:06:15.048 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-22T06:06:15.048 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-22T06:06:15.048 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T06:06:15.048 [RTP] No config change detected. Not updating plugin configuration. 2026-04-22T06:06:15.048 [RTP] No config changes found. No configuration switch. 2026-04-22T06:06:15.048 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-22T06:06:16.626 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-22T06:06:16.626 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-22T06:06:16.626 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-22T06:06:16.626 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-22T06:06:16.626 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-22T06:06:16.720 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-04-22T06:06:16.766 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:63DFE1DE-D22F-4CDF-B073-0F3BC03C9284, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-22T06:06:16.766 Scheduled scan with Id 63DFE1DE-D22F-4CDF-B073-0F3BC03C9284 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-22T06:06:16.766 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-22T06:06:16.766 [SFC] System file cache build is not needed (already completed) 2026-04-22T06:06:16.845 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-04-22T06:06:16.860 Engine:Setting original file name "System.Printing" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\system.printing.dll", hr=0x800710da 2026-04-22T06:06:16.876 [AutoPurge] Cleanup Routine tasks have started. 2026-04-22T06:06:16.891 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-22T06:06:16.907 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-22T06:06:16.907 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-22-2026 06:06:16 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-22-2026 06:06:16 2026-04-22T06:06:16.907 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-22T06:06:16.907 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-22T06:06:16.907 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-22T06:06:16.907 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-22T06:06:16.923 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-22T06:06:17.048 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-04-22T06:06:17.173 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:17.985 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-04-22T06:06:18.516 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7631, FileId: 0x19000000041ddc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:06:18.641 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-04-22T06:06:18.673 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-04-22T06:06:18.782 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:06:18.798 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-22T06:06:18.798 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:06:18.813 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-04-22T06:06:18.829 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-04-22T06:06:19.313 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-04-22T06:06:19.391 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-04-22T06:06:19.657 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-22T06:06:19.673 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-04-22T06:06:19.860 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-04-22T06:06:19.907 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-04-22T06:06:19.970 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-04-22T06:06:20.126 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-04-22T06:06:20.329 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-04-22T06:06:20.485 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-04-22T06:06:20.673 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-22T06:06:20.688 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:20.720 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-04-22T06:06:20.907 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-04-22T06:06:20.985 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-04-22T06:06:21.376 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-04-22T06:06:21.626 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-04-22T06:06:21.673 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-04-22T06:06:22.048 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-04-22T06:06:22.079 Engine:Setting original file name "vcamp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-22T06:06:22.251 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-04-22T06:06:22.813 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:22.829 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-22T06:06:22.907 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:23.157 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-22T06:06:23.282 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-22T06:06:23.438 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-04-22T06:06:23.673 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-04-22T06:06:23.766 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-04-22T06:06:23.782 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-04-22T06:06:23.829 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-22T06:06:24.063 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-04-22T06:06:24.141 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-22T06:06:24.313 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-04-22T06:06:24.485 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-04-22T06:06:25.110 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-04-22T06:06:25.126 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-04-22T06:06:25.391 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-22T06:06:25.485 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-04-22T06:06:26.048 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-04-22T06:06:26.110 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-04-22T06:06:26.110 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-04-22T06:06:26.110 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-04-22T06:06:26.188 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-04-22T06:06:26.251 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-04-22T06:06:26.376 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-04-22T06:06:26.720 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-04-22T06:06:26.860 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-04-22T06:06:27.032 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-04-22T06:06:27.048 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:27.063 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-04-22T06:06:27.110 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-04-22T06:06:27.235 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-22T06:06:27.298 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-04-22T06:06:27.329 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-04-22T06:06:27.345 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-04-22T06:06:27.626 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-04-22T06:06:27.798 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-22T06:06:27.813 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-04-22T06:06:28.079 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-22T06:06:28.458 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-04-22T06:06:28.630 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-04-22T06:06:28.630 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-04-22T06:06:28.693 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-22T06:06:29.115 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-04-22T06:06:29.130 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-04-22T06:06:29.490 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-04-22T06:06:29.568 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-04-22T06:06:29.568 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-04-22T06:06:29.646 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-04-22T06:06:29.662 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-22T06:06:29.708 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-04-22T06:06:30.115 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-04-22T06:06:30.177 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-22T06:06:30.271 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-04-22T06:06:30.302 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-04-22T06:06:30.458 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-04-22T06:06:30.615 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-04-22T06:06:30.677 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-04-22T06:06:30.708 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-04-22T06:06:30.849 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-04-22T06:06:31.146 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:31.818 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-04-22T06:06:31.880 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-04-22T06:06:31.880 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:31.958 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:32.646 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:32.755 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:33.099 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-04-22T06:06:33.162 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-04-22T06:06:33.302 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-04-22T06:06:33.412 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-04-22T06:06:33.458 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-04-22T06:06:33.474 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-04-22T06:06:33.849 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-04-22T06:06:33.943 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-04-22T06:06:34.021 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-04-22T06:06:34.115 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-04-22T06:06:34.130 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-04-22T06:06:34.271 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-04-22T06:06:34.412 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-04-22T06:06:34.537 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-04-22T06:06:34.635 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-04-22T06:06:34.666 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-04-22T06:06:34.666 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-04-22T06:06:34.932 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-04-22T06:06:34.932 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-04-22T06:06:35.103 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-04-22T06:06:35.728 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-04-22T06:06:35.963 Engine:Setting original file name "accbdc.dll" for "c:\program files\microsoft office\root\vfs\windows\assembly\gac_64\microsoft.office.access.businessdatacatalog\16.0.0.0__71e9bce111e9429c\microsoft.office.access.businessdatacatalog.dll", hr=0x800710da 2026-04-22T06:06:35.978 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-04-22T06:06:36.057 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-04-22T06:06:36.541 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-04-22T06:06:36.619 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-04-22T06:06:36.697 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-04-22T06:06:36.775 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-04-22T06:06:36.885 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-22T06:06:36.885 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-22T06:06:37.057 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-04-22T06:06:37.182 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-22T06:06:37.307 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-04-22T06:06:37.322 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-04-22T06:06:37.650 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-04-22T06:06:37.775 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-04-22T06:06:37.869 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-22T06:06:38.119 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-04-22T06:06:38.228 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-22T06:06:38.369 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-04-22T06:06:38.775 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-04-22T06:06:38.869 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-04-22T06:06:38.900 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-04-22T06:06:39.213 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-04-22T06:06:39.228 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-22T06:06:39.353 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-04-22T06:06:39.416 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-04-22T06:06:39.603 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-04-22T06:06:39.713 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-04-22T06:06:39.728 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:40.025 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-04-22T06:06:40.322 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-04-22T06:06:40.353 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-04-22T06:06:40.385 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-22T06:06:40.572 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-04-22T06:06:40.885 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-04-22T06:06:40.963 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:40.978 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-04-22T06:06:41.119 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:41.682 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-04-22T06:06:41.822 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-04-22T06:06:41.932 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-04-22T06:06:42.338 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-04-22T06:06:42.369 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-04-22T06:06:42.385 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-04-22T06:06:42.697 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-04-22T06:06:42.978 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-04-22T06:06:43.025 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-04-22T06:06:43.166 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-04-22T06:06:43.338 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-04-22T06:06:43.353 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-04-22T06:06:43.588 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-04-22T06:06:43.760 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-04-22T06:06:43.791 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-04-22T06:06:43.885 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-22T06:06:44.338 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-04-22T06:06:44.400 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-04-22T06:06:44.400 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-04-22T06:06:44.650 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-04-22T06:06:45.182 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-04-22T06:06:45.322 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-04-22T06:06:45.400 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-04-22T06:06:45.432 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-04-22T06:06:45.603 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-04-22T06:06:45.697 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-04-22T06:06:45.775 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-22T06:06:45.916 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:06:46.057 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-04-22T06:06:46.228 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-04-22T06:06:46.353 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-22T06:06:46.603 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-04-22T06:06:46.869 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-04-22T06:06:46.885 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-04-22T06:06:46.994 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-04-22T06:06:47.744 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-04-22T06:06:48.182 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-04-22T06:06:48.275 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-22T06:06:48.353 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-04-22T06:06:48.572 Engine:Setting original file name "MSPPT12.OLB" for "c:\program files\microsoft office\root\office16\msppt.olb", hr=0x800710da 2026-04-22T06:06:48.603 Engine:Setting original file name "Microsoft Office Policy Tips" for "c:\program files\microsoft office\root\office16\microsoft.office.policytips.dll", hr=0x800710da 2026-04-22T06:06:49.010 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-04-22T06:06:49.447 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-04-22T06:06:49.510 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-04-22T06:06:49.713 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-04-22T06:06:49.947 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-04-22T06:06:49.994 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-04-22T06:06:50.322 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-04-22T06:06:50.432 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-04-22T06:06:50.494 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-04-22T06:06:50.525 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-04-22T06:06:50.650 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-04-22T06:06:51.103 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-04-22T06:06:51.182 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-04-22T06:06:51.510 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-04-22T06:06:51.572 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-04-22T06:06:52.353 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-22T06:06:52.416 Engine:Setting original file name "libcrypto" for "c:\program files\microsoft onedrive\26.055.0323.0004\libcrypto-3-x64.dll", hr=0x800710da 2026-04-22T06:06:52.760 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-04-22T06:06:52.932 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-04-22T06:06:53.166 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-04-22T06:06:53.260 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:53.307 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-04-22T06:06:53.307 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:53.353 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-04-22T06:06:53.385 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\2E5C8554-45D8-4BA0-83E8-8DDAA40CD14Eb1c.1dcd21e361c2706 2026-04-22T06:06:53.478 Verifying engine and signature files (source: 0) ... 2026-04-22T06:06:53.478 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpengine.dll] due to PPL. 2026-04-22T06:06:53.478 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpasbase.vdm] (file in cache) 2026-04-22T06:06:53.478 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-22T06:06:53.494 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpasdlta.vdm] 2026-04-22T06:06:53.494 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpavbase.vdm] (file in cache) 2026-04-22T06:06:53.494 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-22T06:06:53.510 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-04-22T06:06:53.525 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpavdlta.vdm] 2026-04-22T06:06:53.588 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-04-22T06:06:53.650 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-04-22T06:06:53.760 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-04-22T06:06:53.775 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-04-22T06:06:53.791 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-04-22T06:06:53.807 [Engine] IsHybridMode: 0 2026-04-22T06:06:53.807 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-22T06:06:53.807 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2067F5F06019D9519FE0D59C22557CA14C895F97.bin): 0x00000002 2026-04-22T06:06:53.822 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-2067F5F06019D9519FE0D59C22557CA14C895F97.bin) 2026-04-22T06:06:53.822 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-22T06:06:53.822 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-22T06:06:53.822 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-22T06:06:53.822 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-04-22T06:06:53.822 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-04-22T06:06:53.838 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-04-22T06:06:54.103 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-22T06:06:54.119 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-22T06:06:54.166 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-04-22T06:06:54.260 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-04-22T06:06:54.385 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-04-22T06:06:54.697 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-04-22T06:06:54.978 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-04-22T06:06:55.244 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-04-22T06:06:55.369 Engine:Setting original file name "VisioUtils.dll" for "c:\program files\microsoft office\root\office16\visutils.dll", hr=0x800710da 2026-04-22T06:06:55.432 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-04-22T06:06:55.510 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-04-22T06:06:55.713 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-04-22T06:06:55.838 Engine:Setting original file name "msvcp140_atomic_wait_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_atomic_wait_app.dll", hr=0x800710da 2026-04-22T06:06:55.978 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-04-22T06:06:56.057 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-04-22T06:06:56.228 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-04-22T06:06:56.353 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-04-22T06:06:56.572 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-04-22T06:06:56.682 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-04-22T06:06:56.744 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-04-22T06:06:56.791 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-04-22T06:06:56.807 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-04-22T06:06:56.807 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-04-22T06:06:56.869 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-04-22T06:06:57.166 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-04-22T06:06:57.182 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-04-22T06:06:57.400 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-04-22T06:06:57.764 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-22T06:06:57.842 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-04-22T06:06:58.545 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-04-22T06:06:58.561 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-22T06:06:58.889 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-04-22T06:06:58.967 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-04-22T06:06:59.030 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-04-22T06:06:59.561 Engine:Setting original file name "metrocnv.dll" for "c:\program files\microsoft office\root\office16\wordcnv.dll", hr=0x800710da 2026-04-22T06:06:59.670 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-22T06:06:59.999 Engine:Setting original file name "PRODUCT_NAME .DLL" for "c:\program files\microsoft office\root\vfs\system\fm20.dll", hr=0x800710da 2026-04-22T06:07:00.061 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-04-22T06:07:00.467 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-04-22T06:07:00.561 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-04-22T06:07:00.795 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-04-22T06:07:01.342 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-22T06:07:01.405 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-04-22T06:07:01.514 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-04-22T06:07:01.592 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-04-22T06:07:01.624 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-04-22T06:07:01.749 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-04-22T06:07:02.108 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-04-22T06:07:02.139 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-04-22T06:07:03.051 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-04-22T06:07:03.316 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-04-22T06:07:03.426 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:07:03.566 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-04-22T06:07:03.973 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-04-22T06:07:04.066 Engine:Setting original file name "PPINTL.DLL" for "c:\program files\microsoft office\root\office16\ppintl.common.dll", hr=0x800710da 2026-04-22T06:07:04.113 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-04-22T06:07:04.160 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-04-22T06:07:04.191 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-04-22T06:07:04.270 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-04-22T06:07:04.504 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:07:04.645 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-22T06:07:04.707 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-22T06:07:04.832 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-04-22T06:07:04.895 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-04-22T06:07:04.957 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-04-22T06:07:05.066 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-04-22T06:07:05.395 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-04-22T06:07:05.488 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-04-22T06:07:05.707 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-04-22T06:07:05.957 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-04-22T06:07:06.410 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-22T06:07:06.520 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-04-22T06:07:07.160 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-04-22T06:07:07.598 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-04-22T06:07:07.957 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-04-22T06:07:08.020 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-04-22T06:07:08.082 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-04-22T06:07:08.410 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-04-22T06:07:08.535 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-04-22T06:07:08.645 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-04-22T06:07:09.113 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-04-22T06:07:09.504 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-04-22T06:07:09.520 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-22T06:07:09.645 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-22T06:07:09.660 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-04-22T06:07:09.676 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-04-22T06:07:10.051 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-04-22T06:07:10.238 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-04-22T06:07:10.285 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-04-22T06:07:10.363 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-04-22T06:07:10.613 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-04-22T06:07:10.879 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-04-22T06:07:10.957 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-22T06:07:11.004 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-04-22T06:07:11.191 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-04-22T06:07:11.332 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-04-22T06:07:11.942 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-22T06:07:12.004 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-22T06:07:12.004 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-22T06:07:12.035 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFC00CB8020, lRefCount: 8, hr=0 2026-04-22T06:07:12.035 [Engine] New active engine 00007FFBD4D18020 replacing engine 00007FFC00CB8020. Number of active engines: 2 2026-04-22T06:07:12.035 EngineInit:Global ASOC is enabled 2026-04-22T06:07:12.035 EngineInit:ASOO is enabled for developer volumes 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.129 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T06:07:12.145 MpWriteUupSignatureVersion 1.449.237.0, hr = 0 2026-04-22T06:07:12.145 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-22T06:07:12.160 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-22T06:07:12.160 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-22T06:07:12.160 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-22T06:07:12.160 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-22T06:07:12.160 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-22T06:07:12.191 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-22T06:07:12.191 [Plugin] Initializing RTP plugin state... 2026-04-22T06:07:12.191 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎22‎-‎2026 07:56:14 Last Perf:‎04‎-‎22‎-‎2026 07:56:14 First RTP Scan:‎04‎-‎22‎-‎2026 07:56:14 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2842 Misses:4781 BM Queue:0,305,0 Proc:0,125,0 File:0,180,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:8209 Pending:0 RegSize:307406 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:16861442 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:12826 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:61875 TotalHits:26589 InstanceCacheInserts:1882 InstanceCacheUpdates:0 InstanceCacheDeletes:33 InstanceCacheHits:329 InstanceCacheMisses:16983 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:6ms (1671/264) Success: 264, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-22T06:07:12.191 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-22T06:07:12.191 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269} 2026-04-22T06:07:12.191 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{264E84D6-B59E-4AE3-8F86-162558F10357} removed 2026-04-22T06:07:12.191 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C}\mpasbase.vdm in use, hr=0x80070020 2026-04-22T06:07:12.191 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-22T06:07:12.191 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.191 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.191 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.191 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.191 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-22-2026 06:07:12 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-22-2026 06:07:12 2026-04-22T06:07:12.191 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-22T06:07:12.191 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-22T06:07:12.207 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T06:07:12.207 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.207 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.207 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.207 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T06:07:12.207 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T06:07:12.207 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-22T06:07:12.207 MdCoreSvc is supported in this platform and OS Signature updated on 04-22-2026 06:07:12 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.237.0 AV Signature Version: 1.449.237.0 ************************************************************ 2026-04-22T06:07:12.207 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-22T06:07:12.207 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\2E5C8554-45D8-4BA0-83E8-8DDAA40CD14Eb1c.1dcd21e361c2706 2026-04-22T06:07:12.223 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-04-22T06:07:12.223 Process scan (postsignatureupdatescan) started. 2026-04-22T06:07:12.238 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-04-22T06:07:12.301 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-04-22T06:07:12.332 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-22T06:07:12.348 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-22-2026 06:07:12 ************************************************************ 2026-04-22T06:07:12.395 Job Notification: Process exited from job (6088) 2026-04-22T06:07:12.395 Job Notification: Process exited from job (2448) 2026-04-22T06:07:12.457 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2603.1001.18.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-22T06:07:12.473 Job Notification: Process exited from job (6720) 2026-04-22T06:07:12.473 Job Notification: Process exited from job (13900) 2026-04-22T06:07:12.551 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-04-22T06:07:12.660 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-22T06:07:12.660 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-22T06:07:12.660 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-22T06:07:12.676 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-04-22T06:07:12.801 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-22T06:07:12.801 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-22T06:07:12.816 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-22T06:07:12.816 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-22T06:07:12.816 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-22T06:07:12.816 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T06:07:12.816 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-22T06:07:12.816 Engine:Setting original file name "Gantt Chart.DLL" for "c:\program files\microsoft office\root\office16\gantt.dll", hr=0x800710da 2026-04-22T06:07:13.160 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-04-22T06:07:13.176 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-04-22T06:07:13.176 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-04-22T06:07:13.473 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-04-22T06:07:13.582 Engine:Setting original file name "ProjectModel.dll" for "c:\program files\microsoft office\root\office16\projmodl.dll", hr=0x800710da 2026-04-22T06:07:13.660 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-04-22T06:07:13.770 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.220.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-04-22T06:07:14.004 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-04-22T06:07:14.082 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-22T06:07:14.129 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.806.2252.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-22T06:07:14.160 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-04-22T06:07:14.223 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:07:14.223 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-22T06:07:14.223 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:07:14.488 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-04-22T06:07:14.566 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-04-22T06:07:14.613 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-04-22T06:07:14.691 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-04-22T06:07:15.629 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-04-22T06:07:15.801 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-04-22T06:07:15.848 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-04-22T06:07:16.066 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-04-22T06:07:16.129 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-04-22T06:07:16.223 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-04-22T06:07:16.285 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-04-22T06:07:16.379 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-04-22T06:07:16.410 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-04-22T06:07:16.426 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-04-22T06:07:16.645 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-04-22T06:07:16.691 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-22T06:07:16.754 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-04-22T06:07:16.770 OriginalFileName Maintenance::10736 files in Moac, 264 skipped (cached), 1 filename set 2026-04-22T06:07:16.770 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-22T06:07:32.436 Process scan (postsignatureupdatescan) completed. Internal signature match:subtype=Lowfi, sigseq=0x0000B77859487154, sigsha=b5063f9ba9f5be806d35212cc733d642c9219aef, cached=false, source=0, resourceid=0x466a3311 Internal signature match:subtype=Lowfi, sigseq=0x0000B77859487154, sigsha=b5063f9ba9f5be806d35212cc733d642c9219aef, cached=false, source=0, resourceid=0x7feaa923 2026-04-22T06:07:55.200 Engine:Triggered AR EMS scan 2026-04-22T06:07:55.215 Engine:EMS scan for process: lsass pid: 752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.278 Engine:EMS scan for process: svchost pid: 964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.309 Engine:EMS scan for process: svchost pid: 684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.325 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.325 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.356 Engine:EMS scan for process: svchost pid: 1284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.372 Engine:EMS scan for process: svchost pid: 1344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.372 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.387 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.387 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.403 Engine:EMS scan for process: svchost pid: 1480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.403 Engine:EMS scan for process: svchost pid: 1536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.418 Engine:EMS scan for process: svchost pid: 1580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.434 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.434 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.450 Engine:EMS scan for process: svchost pid: 1700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.450 Engine:EMS scan for process: svchost pid: 1972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.450 Engine:EMS scan for process: svchost pid: 2016, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.465 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.465 Engine:EMS scan for process: svchost pid: 2124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.481 Engine:EMS scan for process: svchost pid: 2192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.481 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.497 Engine:EMS scan for process: svchost pid: 2396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.497 Engine:EMS scan for process: svchost pid: 2404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.497 Engine:EMS scan for process: svchost pid: 2424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.512 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.512 Engine:EMS scan for process: svchost pid: 2656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.512 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.512 Engine:EMS scan for process: svchost pid: 2756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.528 Engine:EMS scan for process: svchost pid: 2796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.528 Engine:EMS scan for process: svchost pid: 3012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.559 Engine:EMS scan for process: svchost pid: 1948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.590 Engine:EMS scan for process: svchost pid: 2572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.622 Engine:EMS scan for process: svchost pid: 3444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.622 Engine:EMS scan for process: svchost pid: 3452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.622 Engine:EMS scan for process: svchost pid: 3508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.684 Engine:EMS scan for process: svchost pid: 3516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.700 Engine:EMS scan for process: svchost pid: 3820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.731 Engine:EMS scan for process: svchost pid: 3868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.747 Engine:EMS scan for process: svchost pid: 3964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.747 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.762 Engine:EMS scan for process: svchost pid: 3176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.778 Engine:EMS scan for process: svchost pid: 4136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.793 Engine:EMS scan for process: svchost pid: 4152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.809 Engine:EMS scan for process: svchost pid: 4180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.840 Engine:EMS scan for process: svchost pid: 4468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.856 Engine:EMS scan for process: svchost pid: 4520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.856 Engine:EMS scan for process: svchost pid: 4604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.872 Engine:EMS scan for process: svchost pid: 5168, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.872 Engine:EMS scan for process: dllhost pid: 5880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.872 Engine:EMS scan for process: svchost pid: 5944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.887 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.887 Engine:EMS scan for process: svchost pid: 6592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.887 Engine:EMS scan for process: svchost pid: 6600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.903 Engine:EMS scan for process: svchost pid: 6692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.903 Engine:EMS scan for process: svchost pid: 6708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:55.950 Engine:EMS scan for process: svchost pid: 6788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.043 Engine:EMS scan for process: svchost pid: 6880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.059 Engine:EMS scan for process: svchost pid: 7072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.075 Engine:EMS scan for process: svchost pid: 3300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.075 Engine:EMS scan for process: explorer pid: 7248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.668 Engine:EMS scan for process: svchost pid: 7532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.684 Engine:EMS scan for process: svchost pid: 7576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.715 Engine:EMS scan for process: svchost pid: 7920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.731 Engine:EMS scan for process: svchost pid: 4308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.778 Engine:EMS scan for process: svchost pid: 8280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.778 Engine:EMS scan for process: svchost pid: 8316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.793 Engine:EMS scan for process: svchost pid: 9168, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.793 Engine:EMS scan for process: dllhost pid: 9320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.793 Engine:EMS scan for process: svchost pid: 10112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.793 Engine:EMS scan for process: svchost pid: 11188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.809 Engine:EMS scan for process: svchost pid: 10480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.825 Engine:EMS scan for process: svchost pid: 11456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.825 Engine:EMS scan for process: svchost pid: 14188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.856 Engine:EMS scan for process: svchost pid: 11700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:56.934 Engine:EMS scan for process: svchost pid: 14160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.012 Engine:EMS scan for process: svchost pid: 3528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.059 Engine:EMS scan for process: svchost pid: 11764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.075 Engine:EMS scan for process: svchost pid: 13920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.106 Engine:EMS scan for process: svchost pid: 10644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.106 Engine:EMS scan for process: svchost pid: 14296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.122 Engine:EMS scan for process: svchost pid: 7860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:07:57.122 Engine:EMS scan for process: svchost pid: 11008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-22T06:08:00.356 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE109AB9F3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9728, FileId: 0x1500000003944c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.387 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB132979C3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9734, FileId: 0x6f000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.387 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBDB761911. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9737, FileId: 0x96000000037387, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.543 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4590A09DD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9756, FileId: 0x70000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.575 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj07B8B1987. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9758, FileId: 0x71000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.606 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF339CE932. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9761, FileId: 0x72000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.653 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBA1A8B902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9765, FileId: 0x73000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.823 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD5FD8790E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9785, FileId: 0x75000000039447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:00.933 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB9A4E8973. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9806, FileId: 0xa2000000037387, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.027 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA1F1F495F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9812, FileId: 0x59000000039457, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.818 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8097D89E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9895, FileId: 0x370000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.826 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEE7A19947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9896, FileId: 0x300000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.886 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9827CA9BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9897, FileId: 0x310000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.956 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj240B64962. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9899, FileId: 0x320000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.958 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCD707F9B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9903, FileId: 0x3c0000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.959 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB6C38491F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9900, FileId: 0x330000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:01.968 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj17CC7D90F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9904, FileId: 0x340000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.106 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8E0A00932. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9913, FileId: 0x3f0000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.106 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBFF9F295E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9914, FileId: 0x400000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.122 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E84B09A9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9917, FileId: 0x410000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.163 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj569D699F3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9929, FileId: 0x420000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.179 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFBEF329CE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9932, FileId: 0x430000000488bf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.211 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj62E4FA961. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9936, FileId: 0x360000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.230 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9A89C5909. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9941, FileId: 0x370000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.270 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDE0E6F96B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9942, FileId: 0x380000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.293 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8A9CE397F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9943, FileId: 0x390000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.304 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26851C9D2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9944, FileId: 0x3a0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.506 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70915B90F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9950, FileId: 0x3b0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.506 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAE9A3E928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9951, FileId: 0x3c0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.538 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDE46DC988. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9954, FileId: 0x3d0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.553 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8BC6F89D7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9957, FileId: 0x3e0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.569 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj03FD72945. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9964, FileId: 0x3f0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.584 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D4C87999. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9965, FileId: 0xb3000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.756 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA4FF3C934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10005, FileId: 0x27000000048c1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.803 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEF7ED29BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10010, FileId: 0x28000000048c1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.819 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5255B7999. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10013, FileId: 0x440000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.897 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3CDA6590C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10023, FileId: 0x450000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.907 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD52BC29C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10025, FileId: 0x460000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.923 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFDC7CD9E8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10026, FileId: 0x470000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.938 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4FE91D9F0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10029, FileId: 0x480000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:02.982 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj90FB179CA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10031, FileId: 0x29000000048c1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.154 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDE2BC7968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10051, FileId: 0x4e0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.170 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFA329E9E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10053, FileId: 0x4f0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.201 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD1CDA69C9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10055, FileId: 0x510000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.233 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8112B29E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10057, FileId: 0x520000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.248 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3FEDB390D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10058, FileId: 0x530000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.264 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9D81B091E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10060, FileId: 0x540000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.279 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFDB43E9B3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10061, FileId: 0x550000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.295 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3545BB918. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10063, FileId: 0x560000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.342 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5016C2924. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10067, FileId: 0x580000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.373 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE3E9569F0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10075, FileId: 0x590000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.404 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E3AA599F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10079, FileId: 0x5b0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.420 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA01168984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10080, FileId: 0x5c0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.451 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDB69A99CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10087, FileId: 0x5e0000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.451 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj152A6596F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10086, FileId: 0x3e000000041d2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.690 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj48019091D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10108, FileId: 0x44000000041d2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.721 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj877FE79F8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10113, FileId: 0x2d000000048c1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.737 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB9F2649E7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10114, FileId: 0x610000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.753 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC8C0C593A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10118, FileId: 0x620000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.815 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj58284798B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10125, FileId: 0x2e000000048c1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.815 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4912D597A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10127, FileId: 0x640000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:03.893 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA85A27909. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10134, FileId: 0x660000000488c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:15.000 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10401, FileId: 0x7d000000013011, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:15.125 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10420, FileId: 0x420000000370d3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:08:15.250 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10448, FileId: 0x36000000039436, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:09:08.228 [RTP] [Mini-filter] OpenWithoutRead notification (2777, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 2026-04-22T06:09:15.359 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12231, FileId: 0x69000000003b03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 Internal signature match:subtype=Lowfi, sigseq=0x0000108766DC1975, sigsha=aecef3f845b0f2d07826ff984849c077aad0fd76, cached=false, source=0, resourceid=0x5a8a74c6 2026-04-22T06:11:01.415 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #12497, FileId: 0x8900000000d6a9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:12:01.067 QuickScan:ScanID:63DFE1DE-D22F-4CDF-B073-0F3BC03C9284: Quick scan finished with error 0 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x70548d8c7ffffffe 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb53f05e7ffffffe 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x32d36a6c7ffffffe 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x70548d8c7ffffffe 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb53f05e7ffffffe 2026-04-22T06:12:01.082 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x32d36a6c7ffffffe 2026-04-22T06:12:01.098 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 7 resources, RtpIoavOnly: FALSE 2026-04-22T06:12:01.098 [Engine] Engine 00007FFC00CB8020 no longer in use. Number of active engines: 1 2026-04-22T06:12:01.223 ProcessImageName: CCC.exe, Pid: 14032, TotalTime: 29123, Count: 572, MaxTime: 1812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-22T06:12:01.223 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 5259, Count: 90, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-04-22T06:12:01.223 ProcessImageName: AsPowerBar.exe, Pid: 12328, TotalTime: 3098, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 47% 2026-04-22T06:12:01.223 ProcessImageName: firefox.exe, Pid: 7448, TotalTime: 2269, Count: 195, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07320, EstimatedImpact: 49% 2026-04-22T06:12:01.223 ProcessImageName: MOM.exe, Pid: 13632, TotalTime: 1836, Count: 30, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 40% 2026-04-22T06:12:01.223 ProcessImageName: AISuite3.exe, Pid: 6964, TotalTime: 1802, Count: 22, MaxTime: 812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-22T06:12:01.223 ProcessImageName: DeviceCensus.exe, Pid: 7668, TotalTime: 1732, Count: 5, MaxTime: 937, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 43% 2026-04-22T06:12:01.223 ProcessImageName: DipAwayMode.exe, Pid: 6948, TotalTime: 1536, Count: 24, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 1% 2026-04-22T06:12:01.223 ProcessImageName: websockify.exe, Pid: 13648, TotalTime: 910, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 48% 2026-04-22T06:12:01.223 ProcessImageName: WmiPrvSE.exe, Pid: 6828, TotalTime: 755, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-22T06:12:01.223 ProcessImageName: WmiPrvSE.exe, Pid: 9844, TotalTime: 451, Count: 58, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 20% 2026-04-22T06:12:01.223 ProcessImageName: powershell.exe, Pid: 4704, TotalTime: 370, Count: 24, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 31% 2026-04-22T06:12:01.223 ProcessImageName: backgroundTaskHost.exe, Pid: 12692, TotalTime: 195, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1776496858, EstimatedImpact: 20% 2026-04-22T06:12:01.223 ProcessImageName: WhatsApp.Root.exe, Pid: 1316, TotalTime: 180, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-04-22T06:12:01.223 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\PushToInstall\Registration, EstimatedImpact: 0% 2026-04-22T06:12:01.301 [Engine] RSIG_UNLOADENGINE, 00007FFC00CB8020, err=0x0 2026-04-22T06:12:01.317 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3BB689BD-9C57-4BC8-856D-3C8FF4148D4C} removed 2026-04-22T06:12:01.582 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-22T06:12:01.582 [RTP] Duplicating the current plugin configuration object... 2026-04-22T06:12:01.582 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-22T06:12:01.582 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-22T06:12:01.582 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T06:12:01.582 [RTP] No config change detected. Not updating plugin configuration. 2026-04-22T06:12:01.582 [RTP] No config changes found. No configuration switch. 2026-04-22T06:12:01.582 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-22T06:12:03.087 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:12:03.087 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-22T06:12:03.102 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T06:12:12.056 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-22T06:13:06.514 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #12556, FileId: 0x10e000000008373, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:13:08.534 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-04-22T06:13:08.534 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-04-22T06:13:08.534 [RTP] Duplicating the current plugin configuration object... 2026-04-22T06:13:08.534 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-22T06:13:08.534 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-22T06:13:08.534 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-22T06:13:08.550 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-22T06:13:09.909 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-04-22T06:13:10.003 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-04-22T06:13:21.809 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\pagefile.sys 2026-04-22T06:13:22.465 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\pagefile.sys 2026-04-22T06:15:40.937 Bm signature throttled:0x00002db31bed458f 2026-04-22T06:15:42.173 Bm signature throttled:0x00002db31bed458f 2026-04-22T06:16:19.518 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T06:18:15.315 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14606, FileId: 0x1d000000032901, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:18:15.315 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14608, FileId: 0x20000000032907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:19:47.768 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Windows\Prefetch\PARTITIONWIZARD.EXE-74ED46E5.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\PartitionWizard.exe, Status: 0xc000004b, State: 0, ScanRequest #14841, FileId: 0x2a000000003e33, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:19:50.081 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume1\EFI\Microsoft\Boot\BCD.LOG 2026-04-22T06:21:15.967 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15109, FileId: 0xa70000000046bb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:26:25.653 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15905, FileId: 0x1c000000032c2f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:31:24.517 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T06:46:29.512 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T06:54:06.758 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16324, FileId: 0x20000000032901, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T06:56:14.507 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-22T06:59:55.776 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16446, FileId: 0x17000000039de7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:00:36.143 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16596, FileId: 0x109000000004f8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:01:32.151 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:01:32.916 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:01:33.021 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:01:34.077 Engine:Process 680 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-22T07:01:34.552 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T07:03:52.997 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #17655, FileId: 0x140000000b9cba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:03:52.998 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #17656, FileId: 0x130000000b9cbc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:11:52.636 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18142, FileId: 0x110000000b9cbd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:16:39.508 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T07:24:58.629 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:24:59.044 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18527, FileId: 0x110000000b9e60, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:31:44.519 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T07:34:08.239 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:37:20.939 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18640, FileId: 0x1c0000000b9c95, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:46:49.513 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T07:54:18.781 Bm signature throttled:0x00002db31bed458f 2026-04-22T07:54:39.761 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18798, FileId: 0x1390000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.762 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18797, FileId: 0x55000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.764 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18799, FileId: 0x56000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.766 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18802, FileId: 0x57000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.768 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18801, FileId: 0x13a0000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.781 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18805, FileId: 0x13c0000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.782 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18807, FileId: 0x5a000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.784 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18808, FileId: 0x13e0000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.794 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18806, FileId: 0x59000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.795 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18810, FileId: 0x1400000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.797 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18812, FileId: 0x5d000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.798 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18811, FileId: 0x5c000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.811 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18815, FileId: 0x1420000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.813 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18817, FileId: 0x1430000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:39.828 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18816, FileId: 0x60000000046bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T07:54:40.192 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13cefe48-4eb4-4d9e-a22f-53b88832b374. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #18850, FileId: 0xd60000000051c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T08:01:54.514 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T08:07:12.041 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 14635, Count: 161, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T08:07:12.041 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T08:07:12.041 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T08:07:12.041 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T08:07:12.041 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T08:07:12.041 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T08:07:12.041 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T08:07:12.041 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T08:07:12.041 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T08:07:12.041 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T08:07:12.041 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T08:07:12.041 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T08:07:12.041 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T08:07:12.041 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T08:07:12.041 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T08:07:12.041 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T08:07:12.041 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 61, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T08:07:12.041 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T08:07:12.041 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T08:07:12.041 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T08:16:59.518 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T08:32:04.513 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T08:34:37.655 Bm signature throttled:0x00002db31bed458f 2026-04-22T08:37:29.294 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #19489, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T08:44:55.188 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19877, FileId: 0xa0000000bbf19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T08:47:09.518 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T08:58:31.981 Bm signature throttled:0x00002db31bed458f 2026-04-22T09:02:14.508 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T09:17:19.518 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T09:31:14.294 Bm signature throttled:0x00002db31bed458f 2026-04-22T09:31:15.609 Bm signature throttled:0x00002db31bed458f 2026-04-22T09:32:24.512 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{DEB15223-74A0-686A-FB99-F3DE53739CA8} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:2008 ProcessCreationTime:134213207195279826 SessionID:1 CreationTime:04-22-2026 09:33:00 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-22T09:33:01.550 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-22T09:33:01.550 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T09:33:01.550 [Cloud] Queued cloud request. 2026-04-22T09:33:01.550 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-22T09:33:01.550 [Cloud] Dequeued cloud request. 2026-04-22T09:33:01.551 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T09:33:01.563 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-22T09:33:01.563 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T09:33:01.563 [Cloud] Queued cloud request. 2026-04-22T09:33:01.563 [Cloud] Dequeued cloud request. 2026-04-22T09:33:01.566 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T09:33:01.821 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-22T09:33:01.821 [Cloud] End of cloud request. 2026-04-22T09:33:01.914 [Cloud] End of cloud request. 2026-04-22T09:33:02.344 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T09:38:48.192 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20513, FileId: 0xe0000000be407, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T09:47:29.507 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T09:47:54.960 Bm signature throttled:0x00002db31bed458f 2026-04-22T09:49:04.533 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20581, FileId: 0x14e0000000046d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T10:02:34.512 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T10:07:12.046 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15192, Count: 177, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T10:07:12.046 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T10:07:12.046 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T10:07:12.046 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T10:07:12.046 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T10:07:12.046 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T10:07:12.046 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T10:07:12.046 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T10:07:12.046 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T10:07:12.046 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T10:07:12.046 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T10:07:12.046 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T10:07:12.046 ProcessImageName: httpd.exe, Pid: 3656, TotalTime: 438, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 31% 2026-04-22T10:07:12.046 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: xampp-control.exe, Pid: 11220, TotalTime: 216, Count: 8, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 4% 2026-04-22T10:07:12.046 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T10:07:12.046 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 195, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T10:07:12.046 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T10:07:12.046 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T10:07:12.046 ProcessImageName: PhoneExperienceHost.exe, Pid: 10280, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T10:07:12.046 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T10:07:12.046 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T10:07:12.046 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T10:07:12.046 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T10:07:12.046 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T10:07:12.046 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T10:07:12.046 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T10:07:12.046 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T10:07:12.047 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 9936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1201.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1138.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1044.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T10:07:12.047 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\favicon.ico, EstimatedImpact: 0% 2026-04-22T10:07:12.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T10:07:12.047 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T10:07:12.047 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T10:17:39.516 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T10:29:53.782 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21719, FileId: 0x110000000be428, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T10:32:44.510 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T10:47:49.506 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T11:02:54.520 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T11:12:43.647 Bm signature throttled:0x00002db31bed458f 2026-04-22T11:17:59.520 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T11:25:10.586 Bm signature throttled:0x00002db31bed458f 2026-04-22T11:33:04.515 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T11:48:09.509 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T11:55:59.508 Bm signature throttled:0x00002db31bed458f 2026-04-22T12:03:14.516 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T12:07:12.054 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15557, Count: 213, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T12:07:12.054 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T12:07:12.054 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T12:07:12.054 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T12:07:12.054 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T12:07:12.054 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T12:07:12.054 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T12:07:12.054 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T12:07:12.054 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T12:07:12.054 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T12:07:12.054 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T12:07:12.054 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T12:07:12.054 ProcessImageName: httpd.exe, Pid: 3656, TotalTime: 438, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 31% 2026-04-22T12:07:12.054 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2788, TotalTime: 376, Count: 57, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 6% 2026-04-22T12:07:12.054 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: xampp-control.exe, Pid: 11220, TotalTime: 216, Count: 8, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 4% 2026-04-22T12:07:12.054 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T12:07:12.054 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 195, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 170, Count: 10, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T12:07:12.054 ProcessImageName: FileCoAuth.exe, Pid: 3660, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-22T12:07:12.054 ProcessImageName: RuntimeBroker.exe, Pid: 9176, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{D4556F2B-6C98-46BA-9A40-A182C1BE5B52}.json, EstimatedImpact: 0% 2026-04-22T12:07:12.054 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T12:07:12.054 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T12:07:12.056 ProcessImageName: PhoneExperienceHost.exe, Pid: 10280, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T12:07:12.056 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T12:07:12.056 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T12:07:12.056 ProcessImageName: svchost.exe, Pid: 14216, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITE112.tmp, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 7952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1244.log, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1044.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 9936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1201.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1138.log, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T12:07:12.056 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T12:07:12.056 ProcessImageName: OfficeC2RClient.exe, Pid: 8488, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1229.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T12:07:12.056 ProcessImageName: SDXHelper.exe, Pid: 9452, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-22T12:18:19.548 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T12:32:54.457 Bm signature throttled:0x00002db31bed458f 2026-04-22T12:33:24.509 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T12:48:29.534 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T12:58:14.215 Bm signature throttled:0x00002db31bed458f 2026-04-22T13:03:34.514 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T13:18:39.507 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T13:22:57.361 Bm signature throttled:0x00002db31bed458f 2026-04-22T13:33:44.509 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T13:40:49.440 Bm signature throttled:0x00002db31bed458f 2026-04-22T13:48:49.516 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T13:55:39.057 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php76E6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #24390, FileId: 0xd0000000bfba9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T14:00:44.791 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2156.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #24894, FileId: 0x78000000039514, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T14:03:18.165 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php786F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #25008, FileId: 0xa500000000ca7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T14:03:54.506 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T14:04:27.391 Bm signature throttled:0x00002db31bed458f 2026-04-22T14:07:12.062 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15798, Count: 234, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T14:07:12.062 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T14:07:12.062 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T14:07:12.062 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T14:07:12.062 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T14:07:12.062 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T14:07:12.062 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T14:07:12.062 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T14:07:12.062 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 925, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T14:07:12.062 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T14:07:12.062 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T14:07:12.062 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T14:07:12.062 ProcessImageName: httpd.exe, Pid: 3656, TotalTime: 438, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 31% 2026-04-22T14:07:12.062 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2788, TotalTime: 376, Count: 57, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 6% 2026-04-22T14:07:12.062 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 302, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: xampp-control.exe, Pid: 11220, TotalTime: 216, Count: 8, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 4% 2026-04-22T14:07:12.062 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T14:07:12.062 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: RuntimeBroker.exe, Pid: 9176, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{D4556F2B-6C98-46BA-9A40-A182C1BE5B52}.json, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T14:07:12.062 ProcessImageName: FileCoAuth.exe, Pid: 3660, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-22T14:07:12.062 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 106, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T14:07:12.062 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T14:07:12.062 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: PhoneExperienceHost.exe, Pid: 10280, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-22T14:07:12.062 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 77, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6E89C0C2-6DCD-4662-B511-B44168A24FA7, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T14:07:12.063 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T14:07:12.063 ProcessImageName: svchost.exe, Pid: 14216, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITE112.tmp, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 60, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 7952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1244.log, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: dllhost.exe, Pid: 6800, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-3B1A8152.pf, EstimatedImpact: 10% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1138.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1044.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 9936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1201.log, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 4824, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-04-22T14:07:12.063 ProcessImageName: FileZillaServer.exe, Pid: 2008, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\tmp\cache\fmCont1\c35b5724b852219a5a3b93d58ac45615.pdf, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13300, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 8488, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1229.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: OfficeC2RClient.exe, Pid: 6824, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1503.log, EstimatedImpact: 0% 2026-04-22T14:07:12.063 ProcessImageName: SDXHelper.exe, Pid: 9452, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-22T14:18:59.516 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T14:22:57.351 Bm signature throttled:0x00002db31bed458f 2026-04-22T14:34:04.517 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T14:49:09.519 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T14:54:39.603 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26341, FileId: 0x130000000ba8c7, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T15:04:14.505 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T15:19:19.513 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T15:34:24.477 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{63A2F934-ECE0-119B-137C-C6657C6781B7} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:3656 ProcessCreationTime:134213207243249057 SessionID:1 CreationTime:04-22-2026 15:38:14 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-22T15:38:15.200 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-22T15:38:15.200 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T15:38:15.200 [Cloud] Queued cloud request. 2026-04-22T15:38:15.200 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-22T15:38:15.200 [Cloud] Dequeued cloud request. 2026-04-22T15:38:15.200 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T15:38:15.215 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-22T15:38:15.215 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T15:38:15.215 [Cloud] Queued cloud request. 2026-04-22T15:38:15.215 [Cloud] Dequeued cloud request. 2026-04-22T15:38:15.215 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T15:38:15.451 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-22T15:38:15.451 [Cloud] End of cloud request. 2026-04-22T15:38:15.514 [Cloud] End of cloud request. 2026-04-22T15:38:15.954 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T15:49:29.448 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T16:04:34.422 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T16:07:11.971 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15798, Count: 234, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T16:07:11.971 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T16:07:11.971 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T16:07:11.971 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T16:07:11.971 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T16:07:11.971 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T16:07:11.971 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 1060, Count: 111, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T16:07:11.971 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T16:07:11.971 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T16:07:11.971 ProcessImageName: firefox.exe, Pid: 1340, TotalTime: 481, Count: 44, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07612, EstimatedImpact: 62% 2026-04-22T16:07:11.971 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T16:07:11.971 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T16:07:11.971 ProcessImageName: httpd.exe, Pid: 3656, TotalTime: 438, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 31% 2026-04-22T16:07:11.971 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2788, TotalTime: 376, Count: 57, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 6% 2026-04-22T16:07:11.971 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 362, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: xampp-control.exe, Pid: 11220, TotalTime: 216, Count: 8, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 4% 2026-04-22T16:07:11.971 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T16:07:11.971 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: RuntimeBroker.exe, Pid: 9176, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{D4556F2B-6C98-46BA-9A40-A182C1BE5B52}.json, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T16:07:11.971 ProcessImageName: FileCoAuth.exe, Pid: 3660, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 105, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T16:07:11.971 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T16:07:11.971 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: PhoneExperienceHost.exe, Pid: 10280, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 77, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6E89C0C2-6DCD-4662-B511-B44168A24FA7, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T16:07:11.971 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T16:07:11.971 ProcessImageName: svchost.exe, Pid: 14216, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITE112.tmp, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 7952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1244.log, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: dllhost.exe, Pid: 6800, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-3B1A8152.pf, EstimatedImpact: 10% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1138.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 9936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1201.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1044.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 7644, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1623.log, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: FileZillaServer.exe, Pid: 2008, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\tmp\cache\fmCont1\c35b5724b852219a5a3b93d58ac45615.pdf, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 4824, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-04-22T16:07:11.971 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13300, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 8488, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1229.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: OfficeC2RClient.exe, Pid: 6824, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1503.log, EstimatedImpact: 0% 2026-04-22T16:07:11.971 ProcessImageName: SDXHelper.exe, Pid: 9452, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-22T16:19:39.406 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T16:34:44.397 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T16:42:01.348 [NRI] Successfully updated NIS service with platform settings for enforcement level Log IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_DC_DisableAadDeviceIdQuery new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-22T16:42:01.380 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-22T16:42:01.380 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-22T16:42:01.380 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-22T16:42:01.380 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T16:42:01.380 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T16:42:01.380 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T16:42:01.380 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T16:42:01.380 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T16:42:01.380 MdCoreSvc is supported in this platform and OS 2026-04-22T16:42:01.867 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-22T16:42:01.867 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-22T16:42:01.867 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-22T16:49:04.487 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27574, FileId: 0x210000000ba8c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T16:49:04.502 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27585, FileId: 0x290000000ba8c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T16:49:49.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T17:04:54.375 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T17:06:05.472 Bm signature throttled:0x00002db31bed458f 2026-04-22T17:06:05.479 Bm signature throttled:0x00002db31bed458f 2026-04-22T17:06:06.573 [RTP] [Mini-filter] Unsuccessful scan status(#190): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #27801, FileId: 0xe0000000b8bb2, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-22T17:19:59.364 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T17:35:04.372 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T17:50:09.365 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T18:05:14.366 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T18:07:11.928 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15798, Count: 234, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T18:07:11.928 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T18:07:11.928 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T18:07:11.928 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T18:07:11.928 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T18:07:11.928 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T18:07:11.928 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 1105, Count: 114, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T18:07:11.928 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T18:07:11.928 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T18:07:11.928 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T18:07:11.928 ProcessImageName: firefox.exe, Pid: 1340, TotalTime: 481, Count: 44, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07612, EstimatedImpact: 62% 2026-04-22T18:07:11.928 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T18:07:11.928 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T18:07:11.928 ProcessImageName: httpd.exe, Pid: 3656, TotalTime: 438, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 31% 2026-04-22T18:07:11.928 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2788, TotalTime: 391, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: firefox.exe, Pid: 8060, TotalTime: 390, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07816, EstimatedImpact: 50% 2026-04-22T18:07:11.928 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 362, Count: 32, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 240, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-22.log, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: xampp-control.exe, Pid: 11220, TotalTime: 216, Count: 8, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 4% 2026-04-22T18:07:11.928 ProcessImageName: backgroundTaskHost.exe, Pid: 2460, TotalTime: 210, Count: 35, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 9% 2026-04-22T18:07:11.928 ProcessImageName: TabTip.exe, Pid: 13752, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-04-22T18:07:11.928 ProcessImageName: brynhildr.exe, Pid: 3164, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: RuntimeBroker.exe, Pid: 9176, TotalTime: 168, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{D4556F2B-6C98-46BA-9A40-A182C1BE5B52}.json, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 151, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: firefox.exe, Pid: 13544, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: dasHost.exe, Pid: 5372, TotalTime: 135, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: Acrobat.exe, Pid: 2096, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 3% 2026-04-22T18:07:11.928 ProcessImageName: FileCoAuth.exe, Pid: 3660, TotalTime: 120, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-22T18:07:11.928 ProcessImageName: SecurityHealthHost.exe, Pid: 2820, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 10% 2026-04-22T18:07:11.928 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 92, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: updater.exe, Pid: 7344, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: AcroCEF.exe, Pid: 2136, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 76% 2026-04-22T18:07:11.928 ProcessImageName: PhoneExperienceHost.exe, Pid: 10280, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 77, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6E89C0C2-6DCD-4662-B511-B44168A24FA7, EstimatedImpact: 2% 2026-04-22T18:07:11.928 ProcessImageName: OfficeC2RClient.exe, Pid: 4200, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\79236E1B-AADB-45C2-9DAC-F71CDC572D4A, EstimatedImpact: 3% 2026-04-22T18:07:11.928 ProcessImageName: SDXHelper.exe, Pid: 2740, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 2% 2026-04-22T18:07:11.928 ProcessImageName: SDXHelper.exe, Pid: 2000, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-04-22T18:07:11.928 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy3\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: atieclxx.exe, Pid: 4980, TotalTime: 62, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 25% 2026-04-22T18:07:11.928 ProcessImageName: AdobeARM.exe, Pid: 3156, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 4% 2026-04-22T18:07:11.928 ProcessImageName: svchost.exe, Pid: 14216, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITE112.tmp, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: dllhost.exe, Pid: 5880, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-22T18:07:11.928 ProcessImageName: OfficeC2RClient.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0859.log, EstimatedImpact: 2% 2026-04-22T18:07:11.929 ProcessImageName: FileCoAuth.exe, Pid: 10664, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 7952, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1244.log, EstimatedImpact: 2% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0900.log, EstimatedImpact: 2% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 12640, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1913.log, EstimatedImpact: 2% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0911.log->(UTF-16LE), EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: dllhost.exe, Pid: 6800, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-3B1A8152.pf, EstimatedImpact: 10% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 3512, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0924.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: Acrobat.exe, Pid: 4584, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1138.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 8220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0826.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 6740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0854.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: TeamViewer.exe, Pid: 7872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 9936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1201.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 7644, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1623.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: svchost.exe, Pid: 3500, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\fd2d194e34df628154f399ae89cd0748ffeab862\content.phf, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 768, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1044.log, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: SDXHelper.exe, Pid: 7380, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 5% 2026-04-22T18:07:11.929 ProcessImageName: SDXHelper.exe, Pid: 4824, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-04-22T18:07:11.929 ProcessImageName: brynhildr.exe, Pid: 10128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.ini, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: FileZillaServer.exe, Pid: 2008, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\tmp\cache\fmCont1\c35b5724b852219a5a3b93d58ac45615.pdf, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: helper.exe, Pid: 13056, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 2% 2026-04-22T18:07:11.929 ProcessImageName: SDXHelper.exe, Pid: 4476, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13300, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 8652, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-0937.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: SDXHelper.exe, Pid: 1596, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 8488, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1229.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: OfficeC2RClient.exe, Pid: 6824, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260422-1503.log, EstimatedImpact: 0% 2026-04-22T18:07:11.929 ProcessImageName: SDXHelper.exe, Pid: 9452, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-22T18:08:11.543 Bm signature throttled:0x00002db31bed458f 2026-04-22T18:20:19.357 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T18:31:50.734 Bm signature throttled:0x00002db31bed458f 2026-04-22T18:35:24.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T18:50:29.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T19:05:34.363 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T19:18:22.848 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\812EB6C5-F86E-477E-96C6-25FF4594366413dc.1dcd28cc80bd8bb 2026-04-22T19:18:22.939 Verifying engine and signature files (source: 0) ... 2026-04-22T19:18:22.939 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpengine.dll] due to PPL. 2026-04-22T19:18:22.939 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasbase.vdm] (file in cache) 2026-04-22T19:18:22.940 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-22T19:18:22.954 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasdlta.vdm] 2026-04-22T19:18:22.954 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpavbase.vdm] (file in cache) 2026-04-22T19:18:22.954 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-22T19:18:22.970 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpavdlta.vdm] 2026-04-22T19:18:23.129 [Engine] IsHybridMode: 0 2026-04-22T19:18:23.131 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-22T19:18:23.137 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-31B9C0353138497A2BF1D99FD0D93C51F33D1630.bin): 0x00000002 2026-04-22T19:18:23.141 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-31B9C0353138497A2BF1D99FD0D93C51F33D1630.bin) 2026-04-22T19:18:23.141 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-22T19:18:23.141 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-22T19:18:23.141 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-22T19:18:23.141 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-22T19:18:35.634 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-22T19:18:35.635 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_DC_DisableAadDeviceIdQuery new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-22T19:18:35.657 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFBD4D18020, lRefCount: 5, hr=0 2026-04-22T19:18:35.657 [Engine] New active engine 00007FFBCE4A8020 replacing engine 00007FFBD4D18020. Number of active engines: 2 2026-04-22T19:18:35.664 EngineInit:Global ASOC is enabled 2026-04-22T19:18:35.664 EngineInit:ASOO is enabled for developer volumes 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.735 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.736 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-22T19:18:35.751 MpWriteUupSignatureVersion 1.449.247.0, hr = 0 2026-04-22T19:18:35.752 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-22T19:18:35.769 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-22T19:18:35.771 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-22T19:18:35.771 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-22T19:18:35.771 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-22T19:18:35.771 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-22T19:18:35.793 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-22T19:18:35.793 [Plugin] Initializing RTP plugin state... 2026-04-22T19:18:35.793 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-22T19:18:35.793 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎22‎-‎2026 08:07:12 Last Perf:‎04‎-‎22‎-‎2026 08:07:12 First RTP Scan:‎04‎-‎22‎-‎2026 08:07:12 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:3590 Misses:15037 BM Queue:0,390,0 Proc:0,155,0 File:0,246,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:30464 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:400092176 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:13 TotalStreamCon:24509 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:133510 TotalHits:518565 InstanceCacheInserts:6958 InstanceCacheUpdates:0 InstanceCacheDeletes:1980 InstanceCacheHits:1437 InstanceCacheMisses:47917 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (2729/1381) Success: 1381, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-22T19:18:35.794 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB} 2026-04-22T19:18:35.794 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269}\mpasbase.vdm in use, hr=0x80070020 2026-04-22T19:18:35.796 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D334798B-4CCC-46C7-B473-4C701DAB8056} removed 2026-04-22T19:18:35.796 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-22T19:18:35.797 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.797 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.797 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.797 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.798 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-22-2026 19:18:35 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-22-2026 19:18:35 2026-04-22T19:18:35.802 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-22T19:18:35.803 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-22T19:18:35.804 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T19:18:35.804 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-22T19:18:35.806 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T19:18:35.807 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.807 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.807 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.808 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-22T19:18:35.808 MdCoreSvc is supported in this platform and OS Signature updated on 04-22-2026 19:18:35 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.247.0 AV Signature Version: 1.449.247.0 ************************************************************ 2026-04-22T19:18:35.812 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-22T19:18:35.812 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\812EB6C5-F86E-477E-96C6-25FF4594366413dc.1dcd28cc80bd8bb 2026-04-22T19:18:35.837 Process scan (postsignatureupdatescan) started. 2026-04-22T19:18:35.902 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-22T19:18:35.904 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-22T19:18:36.269 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-22T19:18:36.269 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-22T19:18:36.269 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-22T19:18:36.269 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-22T19:18:36.269 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-22T19:18:36.270 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-22T19:18:36.270 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-22T19:18:36.270 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-22T19:18:36.273 [Engine] Engine 00007FFBD4D18020 no longer in use. Number of active engines: 1 2026-04-22T19:18:36.273 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-22T19:18:36.273 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-22T19:18:36.577 ProcessImageName: explorer.exe, Pid: 7248, TotalTime: 15798, Count: 235, MaxTime: 1828, MaxTimeFile: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Contact.Conversion.Wizard_3.5.0.2.exe, EstimatedImpact: 0% 2026-04-22T19:18:36.577 ProcessImageName: AcroCEF.exe, Pid: 5240, TotalTime: 3992, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-04-22T19:18:36.577 ProcessImageName: helper.exe, Pid: 7864, TotalTime: 3381, Count: 74, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-04-22T19:18:36.577 ProcessImageName: SrTasks.exe, Pid: 8092, TotalTime: 2910, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 12% 2026-04-22T19:18:36.577 ProcessImageName: PartitionWizard.exe, Pid: 8760, TotalTime: 1495, Count: 14, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 71% 2026-04-22T19:18:36.577 ProcessImageName: xampp-control.exe, Pid: 10936, TotalTime: 1468, Count: 2, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 23% 2026-04-22T19:18:36.577 ProcessImageName: httpd.exe, Pid: 13460, TotalTime: 1166, Count: 120, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\index.html, EstimatedImpact: 0% 2026-04-22T19:18:36.577 ProcessImageName: taskhostw.exe, Pid: 1768, TotalTime: 1123, Count: 5, MaxTime: 546, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 31% 2026-04-22T19:18:36.577 ProcessImageName: mysqld.exe, Pid: 8440, TotalTime: 1006, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 65% 2026-04-22T19:18:36.577 ProcessImageName: notepad++.exe, Pid: 1372, TotalTime: 993, Count: 88, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-04-22T19:18:36.577 ProcessImageName: WmiPrvSE.exe, Pid: 1520, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T19:18:36.577 ProcessImageName: firefox.exe, Pid: 1604, TotalTime: 572, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 54% 2026-04-22T19:18:36.577 ProcessImageName: firefox.exe, Pid: 1340, TotalTime: 481, Count: 44, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07612, EstimatedImpact: 62% 2026-04-22T19:18:36.577 ProcessImageName: firefox.exe, Pid: 11108, TotalTime: 465, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11904, EstimatedImpact: 59% 2026-04-22T19:18:36.577 ProcessImageName: updater.exe, Pid: 3376, TotalTime: 453, Count: 41, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-04-22T19:18:36.627 [Engine] RSIG_UNLOADENGINE, 00007FFBD4D18020, err=0x0 2026-04-22T19:18:36.642 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C07DFBE9-C733-4090-85FB-2FFE6A60A269} removed 2026-04-22T19:18:37.826 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-22T19:18:37.833 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-22T19:18:37.835 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) BEGIN BM telemetry GUID:{5BC1743D-B4DA-57F2-0A40-22681A5A19DA} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:3656 ProcessCreationTime:134213207243249057 SessionID:1 CreationTime:04-22-2026 19:18:50 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-22T19:18:51.445 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-22T19:18:51.445 [Cloud] Start of cloud request. Passive mode: 0 2026-04-22T19:18:51.445 [Cloud] Queued cloud request. 2026-04-22T19:18:51.445 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-22T19:18:51.445 [Cloud] Dequeued cloud request. 2026-04-22T19:18:51.445 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-22T19:18:51.723 [Cloud] End of cloud request. 2026-04-22T19:18:52.242 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-22T19:18:58.631 Process scan (postsignatureupdatescan) completed. 2026-04-22T19:20:39.355 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T19:23:35.695 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-22T19:35:44.349 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T19:44:41.912 Bm signature throttled:0x00002db31bed458f 2026-04-22T19:50:49.357 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T20:05:54.348 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T20:20:59.351 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T20:36:04.348 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T20:51:09.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T21:06:14.358 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T21:18:35.662 ProcessImageName: WmiPrvSE.exe, Pid: 12100, TotalTime: 646, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 92% 2026-04-22T21:18:35.662 ProcessImageName: PhoneExperienceHost.exe, Pid: 10080, TotalTime: 241, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000014f.db, EstimatedImpact: 0% 2026-04-22T21:18:35.662 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-04-22T21:18:35.662 ProcessImageName: crashhelper.exe, Pid: 14228, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\mozglue.dll, EstimatedImpact: 4% 2026-04-22T21:18:35.662 ProcessImageName: AdobeCollabSync.exe, Pid: 3080, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-22T21:18:35.662 ProcessImageName: AdobeARM.exe, Pid: 2244, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-04-22T21:18:35.662 ProcessImageName: AggregatorHost.exe, Pid: 5424, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-22T21:21:19.360 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-22T21:36:24.353 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-23-2026 15:40:59 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/23/2026 15:40:59.402810200 UTC (14125 ms since boot) 2026-04-23T15:40:59.412 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-23T15:40:59.412 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-23T15:40:59.412 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-23T15:40:59.474 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260423-154059-00000003-fffffffeffffffff.bin ... 2026-04-23T15:40:59.631 [WPP] Trace session started - MpWppTracing-20260423-154059-00000003-fffffffeffffffff.bin 2026-04-23T15:40:59.662 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-23T15:40:59.662 [RbM] Rollback manager succesfully initialized. 2026-04-23T15:40:59.662 [RbM] Rollback manager EnableRollbackManager called. 2026-04-23T15:40:59.662 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-23T15:40:59.662 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-23T15:40:59.662 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-23T15:40:59.662 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-23T15:40:59.678 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-23T15:40:59.678 MdCoreSvc is supported in this platform and OS 2026-04-23T15:40:59.678 MdCoreSvc is supported in this platform and OS 2026-04-23T15:40:59.678 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-23T15:40:59.678 [PlatUpd] Starting MdCoreSvc service 2026-04-23T15:40:59.709 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-23T15:41:04.412 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-23T15:41:04.412 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-23T15:41:04.412 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-23T15:41:04.412 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-23T15:41:04.412 [PlatUpd] CSP platform update started 2026-04-23T15:41:04.412 [PlatUpd] Defender MDM CSP platform update not required 2026-04-23T15:41:04.412 [PlatUpd] WMI/PS provider platform update started 2026-04-23T15:41:04.412 [PlatUpd] WMI/PS provider platform update not required 2026-04-23T15:41:04.412 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-23T15:41:04.412 MdCoreSvc is supported in this platform and OS 2026-04-23T15:41:04.412 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-23T15:41:04.412 [PlatUpd] Starting MdCoreSvc service 2026-04-23T15:41:04.412 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-23T15:41:04.428 [TS] Troublshooting mode is not available! 2026-04-23T15:41:04.428 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-23T15:41:04.428 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-23T15:41:04.506 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-23T15:41:04.506 [Service] Enabling AutoLoggers ... 2026-04-23T15:41:04.506 [Service] Enabling AMSI registration ... 2026-04-23T15:41:04.506 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-23T15:41:04.521 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52494 Number of invalid entries is 0 Number of inserts issued is 1573690 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6426 Number of lookups is 107168351 Number of lookup misses is 5136221 Number of fast lookup misses is 54637558 Number of false fast lookups is 5136216 Number of invalidations is 729492 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-23T15:41:04.521 Verifying license file... 2026-04-23T15:41:04.521 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-23T15:41:04.537 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-23T15:41:04.537 Loaded module#0 MpComServer. 2026-04-23T15:41:04.537 Loaded module#1 StartupPolicies. 2026-04-23T15:41:04.537 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-23T15:41:04.553 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-23T15:41:04.553 COM server initialized successfully. 2026-04-23T15:41:04.568 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-23T15:41:04.584 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-23T15:41:04.584 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-23T15:41:04.599 [RTP] [RTP] FilterCommunicator object 0x0000015125895860 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-23T15:41:04.599 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-23T15:41:04.599 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-23T15:41:04.599 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-23T15:41:04.599 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-23T15:41:04.599 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-23T15:41:04.599 [RTP] [RTP] FilterCommunicator object 0x0000015125895A70 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-23T15:41:04.599 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-23T15:41:04.599 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-23T15:41:04.599 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-23T15:41:04.615 [RTP] [RTP] StartCommunication 0x0000015125895860 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-23T15:41:04.615 [init][RTP] RTPPlugin initialization completed 2026-04-23T15:41:04.615 OS boot count = 2 2026-04-23T15:41:04.615 OS Install = 0 2026-04-23T15:41:05.115 [init] MpAddMpUxRegistrationForToast succeeded 2026-04-23T15:41:05.131 [KSL] Entering CKSLEngine::Initialize. 2026-04-23T15:41:05.131 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-23T15:41:05.131 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-23T15:41:05.131 [KSL] MpInstallKslD: hr=0x1 2026-04-23T15:41:05.131 [KSL] MpRegisterKslD: hr=0 2026-04-23T15:41:05.146 [KSL] MpStartKslD: hr=0 2026-04-23T15:41:05.146 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-23T15:41:05.146 Loading engine... 2026-04-23T15:41:05.162 Verifying engine and signature files (source: 1) ... 2026-04-23T15:41:05.162 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpengine.dll] due to PPL. 2026-04-23T15:41:05.162 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasbase.vdm] (file in cache) 2026-04-23T15:41:05.162 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasdlta.vdm] (file in cache) 2026-04-23T15:41:05.162 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpavbase.vdm] (file in cache) 2026-04-23T15:41:05.162 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpavdlta.vdm] (file in cache) 2026-04-23T15:41:05.224 [Engine] IsHybridMode: 0 2026-04-23T15:41:05.224 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-23T15:41:05.256 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-31B9C0353138497A2BF1D99FD0D93C51F33D1630.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-23T15:41:24.068 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-23T15:41:24.069 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_DC_DisableAadDeviceIdQuery new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-23T15:41:24.073 [Engine] New active engine 00007FF887128020 (no old engine). Number of active engines: 1 2026-04-23T15:41:24.099 EngineInit:Global ASOC is enabled 2026-04-23T15:41:24.099 EngineInit:ASOO is enabled for developer volumes 2026-04-23T15:41:24.398 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-23T15:41:24.398 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.399 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-23T15:41:24.400 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-23T15:41:24.400 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-23T15:41:24.400 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.400 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.400 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.401 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-23T15:41:24.401 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.402 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.403 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.403 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:41:24.522 MpWriteUupSignatureVersion 1.449.247.0, hr = 0 2026-04-23T15:41:24.524 [SigStatUpd] CSignatureStatus: back to good 2026-04-23T15:41:24.524 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-23T15:41:24.654 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-23T15:41:24.654 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-23T15:41:24.654 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-23T15:41:24.654 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-23T15:41:24.738 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-23T15:41:24.738 [Plugin] Initializing RTP plugin state... 2026-04-23T15:41:24.739 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-23T15:41:24.739 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB} 2026-04-23T15:41:24.740 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:41:24.740 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:41:24.740 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:41:24.740 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-23T15:41:24.741 MdCoreSvc is supported in this platform and OS 2026-04-23T15:41:24.741 Engine loaded! 2026-04-23T15:41:24.742 [DLP] Create FeatureControlState instance 2026-04-23T15:41:24.751 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-23T15:41:24.752 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:2,2,0 SetEngine:1,1,0 SetState:1,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3777 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:18727 TotalHits:0 InstanceCacheInserts:30 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3950 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-23T15:41:24.759 RegisterSModeChangeListener: hr = 0x1 2026-04-23T15:41:24.759 RegisterHybridModeChangeListener: hr = 0 2026-04-23T15:41:24.787 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-23T15:41:24.787 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-23T15:41:24.870 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-23T15:41:24.870 [SigReleaseHb] Initialized with Stage 0 2026-04-23T15:41:24.871 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-23T15:41:24.872 [SCC][CID=39593_5624] Initializing ... 2026-04-23T15:41:24.872 [SCC][CID=39593_5624] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-23T15:41:24.874 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-23T15:41:24.875 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-23T15:41:24.878 [NRI] Stopping NIS service ... 2026-04-23T15:41:24.880 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-23T15:41:24.880 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.247.0 AV Signature Version: 1.449.247.0 ************************************************************ 2026-04-23T15:41:24.881 Resource usage Monitoring is enabled 2026-04-23T15:41:24.884 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-23T15:41:24.924 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-23T15:41:24.924 Job Notification: New process added to job (4596) 2026-04-23T15:41:24.986 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11416] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11428]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-23T15:41:25.267 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-23T15:41:25.267 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-23T15:41:25.267 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-23T15:41:25.426 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-23T15:41:25.468 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-23T15:41:25.491 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-23T15:41:25.491 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-23T15:41:25.491 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-23T15:41:25.491 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-23T15:41:25.491 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-23T15:41:25.491 [RTP] Generating the base plugin configuration ... 2026-04-23T15:41:25.491 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-23T15:41:25.492 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T15:41:25.492 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-23T15:41:25.527 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-23T15:41:25.527 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T15:41:25.527 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-23T15:41:25.531 [RTP] [RTP] StartCommunication 0x0000015125895A70 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-23T15:41:25.561 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-23T15:41:25.595 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsAppRuntime.1.7_7000.785.2325.0_x64__8wekyb3d8bbwe\Microsoft.WindowsAppRuntime.dll 2026-04-23T15:41:25.889 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-23T15:41:26.010 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T15:41:28.677 [RTP] Duplicating the current plugin configuration object... 2026-04-23T15:41:28.677 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-23T15:41:28.677 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-23T15:41:28.678 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-23T15:41:28.678 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-23T15:41:35.562 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.055.0323.0004\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #780, FileId: 0xc0000000bd691, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:41:57.068 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\ASUS\ASUSMINIBAR\ASUSMINIBAR.xml. Process: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe, Status: 0xc0000001, State: 0, ScanRequest #1956, FileId: 0x3e000000010001, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:42:04.537 Process scan (poststartupscan) started. 2026-04-23T15:42:04.538 Process scan (poststartupscan) completed. 2026-04-23T15:42:05.052 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-23T15:42:05.061 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-23T15:42:07.606 [RTP] Duplicating the current plugin configuration object... 2026-04-23T15:42:07.606 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-23T15:42:07.606 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-23T15:42:07.606 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-23T15:42:07.606 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-23T15:42:14.957 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\C23E4929-E6A0-4F6D-BC79-FE4C61C262932f14.1dcd337c0cb0d11 2026-04-23T15:42:15.066 Verifying engine and signature files (source: 0) ... 2026-04-23T15:42:15.066 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpengine.dll] due to PPL. 2026-04-23T15:42:15.066 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasbase.vdm] (file in cache) 2026-04-23T15:42:15.066 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-23T15:42:15.082 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasdlta.vdm] 2026-04-23T15:42:15.082 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpavbase.vdm] (file in cache) 2026-04-23T15:42:15.082 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-23T15:42:15.144 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpavdlta.vdm] 2026-04-23T15:42:15.441 [Engine] IsHybridMode: 0 2026-04-23T15:42:15.441 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-23T15:42:15.488 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0E7C28F85E653F6A9727130A3C39C28C8E584FCB.bin): 0x00000002 2026-04-23T15:42:15.519 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0E7C28F85E653F6A9727130A3C39C28C8E584FCB.bin) 2026-04-23T15:42:15.519 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-23T15:42:15.519 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-23T15:42:15.519 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-23T15:42:15.519 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-04-23T15:42:25.951 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-04-23T15:42:31.753 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 5187 units 2026-04-23T15:42:31.878 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3661, FileId: 0x3a0000000bd5cd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-23T15:42:35.019 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-23T15:42:35.019 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-23T15:42:35.035 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF887128020, lRefCount: 5, hr=0 2026-04-23T15:42:35.035 [Engine] New active engine 00007FF82F738020 replacing engine 00007FF887128020. Number of active engines: 2 2026-04-23T15:42:35.035 EngineInit:Global ASOC is enabled 2026-04-23T15:42:35.035 EngineInit:ASOO is enabled for developer volumes 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-23T15:42:35.113 MpWriteUupSignatureVersion 1.449.259.0, hr = 0 2026-04-23T15:42:35.128 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-23T15:42:35.144 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-23T15:42:35.144 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-23T15:42:35.144 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-23T15:42:35.144 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-23T15:42:35.144 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-23T15:42:35.160 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-23T15:42:35.160 [Plugin] Initializing RTP plugin state... 2026-04-23T15:42:35.160 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-23T15:42:35.160 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎23‎-‎2026 17:41:25 Last Perf:‎04‎-‎23‎-‎2026 17:41:24 First RTP Scan:‎04‎-‎23‎-‎2026 17:41:25 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1471 Misses:2055 BM Queue:0,329,0 Proc:0,231,0 File:0,174,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:3667 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:9230588 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:7977 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:26794 TotalHits:8368 InstanceCacheInserts:281 InstanceCacheUpdates:0 InstanceCacheDeletes:220 InstanceCacheHits:0 InstanceCacheMisses:10201 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:5ms (409/80) Success: 80, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-23T15:42:35.160 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790} 2026-04-23T15:42:35.175 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{89693A55-B547-4B83-B5DD-6D6F4F16C062} removed 2026-04-23T15:42:35.175 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-23T15:42:35.175 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB}\mpasbase.vdm in use, hr=0x80070020 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-23-2026 15:42:35 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-23-2026 15:42:35 2026-04-23T15:42:35.175 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-23T15:42:35.175 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-23T15:42:35.175 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T15:42:35.175 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-23T15:42:35.175 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-23T15:42:35.175 MdCoreSvc is supported in this platform and OS Signature updated on 04-23-2026 15:42:35 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.259.0 AV Signature Version: 1.449.259.0 ************************************************************ 2026-04-23T15:42:35.191 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-23T15:42:35.191 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\C23E4929-E6A0-4F6D-BC79-FE4C61C262932f14.1dcd337c0cb0d11 2026-04-23T15:42:35.269 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-23T15:42:35.285 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-23T15:42:35.613 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-23T15:42:35.613 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-23T15:42:35.613 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-23T15:42:35.644 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-23T15:42:35.644 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-23T15:42:35.644 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-23T15:42:35.644 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-23T15:42:35.644 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-23T15:42:35.644 [Engine] Engine 00007FF887128020 no longer in use. Number of active engines: 1 2026-04-23T15:42:35.644 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T15:42:35.644 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-23T15:42:35.759 ProcessImageName: CCC.exe, Pid: 13320, TotalTime: 22126, Count: 358, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 67% 2026-04-23T15:42:35.759 ProcessImageName: explorer.exe, Pid: 7548, TotalTime: 2760, Count: 13, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 5% 2026-04-23T15:42:35.759 ProcessImageName: AsPowerBar.exe, Pid: 692, TotalTime: 2741, Count: 18, MaxTime: 984, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 29% 2026-04-23T15:42:35.759 ProcessImageName: DipAwayMode.exe, Pid: 6832, TotalTime: 2630, Count: 28, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 39% 2026-04-23T15:42:35.759 ProcessImageName: MOM.exe, Pid: 14120, TotalTime: 2022, Count: 33, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 6% 2026-04-23T15:42:35.759 ProcessImageName: AISuite3.exe, Pid: 6844, TotalTime: 1774, Count: 22, MaxTime: 906, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 6% 2026-04-23T15:42:35.759 ProcessImageName: OneDriveUpdaterService.exe, Pid: 2820, TotalTime: 1655, Count: 3, MaxTime: 1625, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 8% 2026-04-23T15:42:35.759 ProcessImageName: websockify.exe, Pid: 14152, TotalTime: 928, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 41% 2026-04-23T15:42:35.759 ProcessImageName: WmiPrvSE.exe, Pid: 3816, TotalTime: 570, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 17% 2026-04-23T15:42:35.759 ProcessImageName: FileCoAuth.exe, Pid: 6840, TotalTime: 275, Count: 20, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-04-23T15:42:35.759 ProcessImageName: svchost.exe, Pid: 7404, TotalTime: 248, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD5FF.tmp, EstimatedImpact: 1% 2026-04-23T15:42:35.759 ProcessImageName: WhatsApp.Root.exe, Pid: 12116, TotalTime: 225, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini->(UTF-16LE), EstimatedImpact: 0% 2026-04-23T15:42:35.759 ProcessImageName: FileSyncConfig.exe, Pid: 12504, TotalTime: 182, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileSyncFS.dll, EstimatedImpact: 55% 2026-04-23T15:42:35.774 ProcessImageName: FileCoAuth.exe, Pid: 12032, TotalTime: 166, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-04-23T15:42:35.806 [Engine] RSIG_UNLOADENGINE, 00007FF887128020, err=0x0 2026-04-23T15:42:35.821 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CB9A4456-47BE-42E7-A49D-88AF7BAF70EB} removed 2026-04-23T15:42:52.096 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3930, FileId: 0x15000000039a26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:43:01.586 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T15:43:01.586 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-23T15:43:01.586 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T15:46:02.864 Bm signature throttled:0x00002db31bed458f 2026-04-23T15:46:06.786 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5071, FileId: 0x12000000039a2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0xcc2a6131 2026-04-23T15:46:22.297 Bm signature throttled:0x00002db31bed458f 2026-04-23T15:46:24.875 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T15:47:35.085 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-23T15:47:51.364 [RTP] [Mini-filter] OpenWithoutRead notification (659, 17617, \Device\HarddiskVolume3\Windows\System32\wbem\WMIADAP.exe) sent successfully. 2026-04-23T15:48:41.783 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20804, FileId: 0x26000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:41.795 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20805, FileId: 0x8500000003030a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:41.799 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20806, FileId: 0x31000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:41.814 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20797, FileId: 0x7900000003030a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:41.814 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20803, FileId: 0x7a00000003030a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.205 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20835, FileId: 0x1f000000096f02, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.236 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20834, FileId: 0x33000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.236 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20836, FileId: 0x34000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.283 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20841, FileId: 0x37000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.283 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20844, FileId: 0x18000000090b47, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.299 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20845, FileId: 0x38000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.345 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20852, FileId: 0x3d000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.345 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20849, FileId: 0x3c000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.361 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20854, FileId: 0x3f000000096dbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.361 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20853, FileId: 0x1e000000090b47, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.690 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20894, FileId: 0xf7000000032e7a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:42.690 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20893, FileId: 0x22000000090b47, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:43.737 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #21005, FileId: 0x25000000090b47, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:43.753 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #21004, FileId: 0x24000000090b47, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:48:44.784 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\7d4cfd16-2de2-4803-bbfd-7d4413e9d69a. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #21128, FileId: 0x111000000003a84, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:15.818 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD45A1F9A4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21711, FileId: 0x1b000000099622, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:15.849 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5D1BD5923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21712, FileId: 0x1c000000099622, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:15.849 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDDB2BC9B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21713, FileId: 0x27000000096f96, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:15.865 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDF338D93E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21715, FileId: 0x1d000000099622, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:15.880 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E343E999. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21716, FileId: 0x31000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.006 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBD4D8B949. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21720, FileId: 0x2a000000096f96, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.062 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD67BBF905. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21723, FileId: 0x2b000000096f96, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.265 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3AC720927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21737, FileId: 0x3a000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.281 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj50DAB29D1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21738, FileId: 0x3c000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.437 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE138AF941. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21742, FileId: 0x1e000000099fcb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:16.531 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7E318995C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21744, FileId: 0x22000000099fcb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.069 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj85175F97E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21779, FileId: 0x23000000099fc9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.116 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD376D9927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21784, FileId: 0x24000000099fc9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.142 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5D2E25927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21794, FileId: 0xc1000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.153 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4D597F9AF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21797, FileId: 0x25000000099fc9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.279 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC83C499A7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21817, FileId: 0x23000000099fcb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.295 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1D922393D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21818, FileId: 0xc4000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.326 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2F8A99959. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21822, FileId: 0xc5000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.326 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj697CA992F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21824, FileId: 0xc6000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.358 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj80355998C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21828, FileId: 0xc7000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.358 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBAE0879B5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21829, FileId: 0xc8000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.373 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCBB4B5975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21832, FileId: 0xc9000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.389 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD4FC5D9E7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21834, FileId: 0xca000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.420 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1304AB953. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21836, FileId: 0xcb000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.436 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2E0FD095B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21837, FileId: 0xcc000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.451 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj116250912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21838, FileId: 0xcd000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.498 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4A165F928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21844, FileId: 0xce000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.529 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC099AF92D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21846, FileId: 0xcf000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.623 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj028E339AF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21850, FileId: 0xd0000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.639 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCAA89B99E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21851, FileId: 0xd1000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.717 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj865C7F98A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21857, FileId: 0xd3000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.733 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj98044091A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21858, FileId: 0xd4000000004bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:18.997 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj90F039978. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21876, FileId: 0x1c00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.044 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj95C42994D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21878, FileId: 0x1d10000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.044 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1473FE925. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21881, FileId: 0x1d20000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.091 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj043966949. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21887, FileId: 0x1d40000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.091 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj903528940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21886, FileId: 0x1d30000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.169 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEF50E991D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21892, FileId: 0x1d50000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.185 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9BE799966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21893, FileId: 0x1d60000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.341 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5A4B4D96D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21901, FileId: 0x1d00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.341 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC448FB9F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21902, FileId: 0x1da0000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.513 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9ACB659BD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21905, FileId: 0x1e00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.528 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj001C4F9E2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21906, FileId: 0x1dc0000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.560 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj40726D9E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21908, FileId: 0x1dd0000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.575 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9F72AD9A6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21909, FileId: 0x1de0000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.591 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj501954924. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21910, FileId: 0x1df0000000002a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.622 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3F992D9F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21912, FileId: 0x1f00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.638 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7D825296B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21913, FileId: 0x2000000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.653 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj37BFC99A3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21914, FileId: 0x2100000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.669 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0B7C7892F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21915, FileId: 0x2200000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.685 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA76FB6910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21916, FileId: 0x2300000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.747 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1510239EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21917, FileId: 0x2400000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.763 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5A43779A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21918, FileId: 0x2500000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.794 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFE6FEB9E4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21919, FileId: 0x2600000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.794 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4435059F4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21920, FileId: 0x2700000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:19.888 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj535A40950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21925, FileId: 0x2900000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.137 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3BDFD69A0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21937, FileId: 0x26000000099fcb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.154 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C801D908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21938, FileId: 0x2b00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.177 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6414C59E8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21939, FileId: 0x2c00000003582b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.195 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFAB6DC9CA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21940, FileId: 0x1c5000000000447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.213 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4072EF919. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21941, FileId: 0x1c6000000000447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.461 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE3F4DD9F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21965, FileId: 0x19100000000111f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.541 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj69FADA9EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21971, FileId: 0x102000000000ddf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.635 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFA6FBA9A4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21982, FileId: 0x19200000000111f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:20.682 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2FE63F9EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21978, FileId: 0x103000000000ddf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:30.249 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22136, FileId: 0x23000000049e91, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:30.311 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22138, FileId: 0x2a00000004a267, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:49:30.499 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22142, FileId: 0x1c000000096ec7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:50:26.815 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-23T15:50:26.815 [RTP] 9 newly mounted volumes accumulated, forcing a config update ... 2026-04-23T15:50:26.815 [RTP] Duplicating the current plugin configuration object... 2026-04-23T15:50:26.815 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-23T15:50:26.815 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-23T15:50:26.815 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-23T15:50:26.815 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-23T15:50:27.658 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-23T15:50:30.799 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23510, FileId: 0xc000000099efd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:51:24.870 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-23T15:51:24.885 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-23T15:51:24.901 Job Notification: New process added to job (11672) 2026-04-23T15:51:24.901 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-23T15:51:24.901 Aggressive catchup quick scan threshold: 1215081429558 / 25920000000000 2026-04-23T15:51:24.901 Job Notification: New process added to job (3312) 2026-04-23T15:51:24.916 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11672] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3312]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-23T15:51:24.963 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 40281225(ms) from now at 05:02 (03:02 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-23T15:51:25.026 Job Notification: New process added to job (3616) 2026-04-23T15:51:25.026 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-23T15:51:25.026 Job Notification: New process added to job (5900) 2026-04-23T15:51:25.057 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:3616] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5900]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-23T15:51:25.260 Job Notification: New process added to job (3424) 2026-04-23T15:51:25.260 Task(GetDeviceTicket -AccessKey B682FDA0-3E99-F177-537E-1771D0E9FC80 ) launched as network service 2026-04-23T15:51:25.401 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-23T15:51:25.401 [RTP] Duplicating the current plugin configuration object... 2026-04-23T15:51:25.401 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-23T15:51:25.401 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-23T15:51:25.401 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T15:51:25.401 [RTP] No config change detected. Not updating plugin configuration. 2026-04-23T15:51:25.401 [RTP] No config changes found. No configuration switch. 2026-04-23T15:51:25.401 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-23T15:51:25.620 Job Notification: Process exited from job (3424) 2026-04-23T15:51:25.666 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-23T15:51:25.666 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T15:51:25.666 [Cloud] Queued cloud request. 2026-04-23T15:51:25.666 [Cloud] Dequeued cloud request. 2026-04-23T15:51:25.682 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T15:51:25.838 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-23T15:51:25.838 [Cloud] End of cloud request. 2026-04-23T15:51:26.135 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T15:51:29.187 Job Notification: Process exited from job (3616) 2026-04-23T15:51:29.187 Job Notification: Process exited from job (5900) 2026-04-23T15:51:29.266 Job Notification: Process exited from job (11672) 2026-04-23T15:51:29.266 Job Notification: Process exited from job (3312) 2026-04-23T15:52:04.555 Process scan (postsignatureupdatescan) started. 2026-04-23T15:52:21.579 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #23966, FileId: 0xe0000000b8bb2, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:52:24.634 Bm signature throttled:0x00002db31bed458f 2026-04-23T15:52:43.296 Process scan (postsignatureupdatescan) completed. 2026-04-23T15:52:55.096 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #24227, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:56:07.860 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #25426, FileId: 0x8a00000000d6a9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:58:20.571 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26802, FileId: 0x46000000010abd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:58:25.883 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #26825, FileId: 0xfa0000000044e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:58:27.997 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-04-23T15:58:29.309 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-04-23T15:58:29.403 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-04-23T15:58:41.569 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\pagefile.sys 2026-04-23T15:58:42.272 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\pagefile.sys 2026-04-23T15:59:30.604 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #29291, FileId: 0x3400000001a9bb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:59:32.338 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #29319, FileId: 0xc30000000001ea, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:59:43.312 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #29634, FileId: 0xdf00000001083f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T15:59:43.358 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #29638, FileId: 0x11000000090293, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T16:01:29.879 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T16:03:57.508 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:CF9AF7FB-C6FA-47C6-A721-5843014E7790, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-23T16:03:57.508 Scheduled scan with Id CF9AF7FB-C6FA-47C6-A721-5843014E7790 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-23T16:03:57.508 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-23T16:03:57.508 [SFC] System file cache build is not needed (already completed) 2026-04-23T16:03:57.729 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-23T16:03:57.729 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-23T16:03:57.729 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-23T16:03:57.729 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-23T16:03:57.729 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-23T16:03:57.752 [AutoPurge] Cleanup Routine tasks have started. 2026-04-23T16:03:57.783 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-23T16:03:57.783 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-23T16:03:57.783 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-23-2026 16:03:57 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-23-2026 16:03:57 2026-04-23T16:03:57.814 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-04-23T16:03:57.814 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-23T16:03:57.824 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-23T16:03:57.824 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-23T16:03:57.824 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-23T16:03:57.824 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-23T16:03:57.971 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-04-23T16:03:58.033 Engine:Setting original file name "System.Printing" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\system.printing.dll", hr=0x800710da 2026-04-23T16:03:58.361 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-04-23T16:03:58.424 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-04-23T16:03:59.299 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-04-23T16:03:59.533 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T16:03:59.549 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-23T16:03:59.549 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T16:03:59.877 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-04-23T16:03:59.908 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-04-23T16:03:59.986 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-04-23T16:04:00.018 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-04-23T16:04:00.471 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-04-23T16:04:00.549 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-04-23T16:04:00.689 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-23T16:04:00.705 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-04-23T16:04:00.877 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-04-23T16:04:00.939 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-04-23T16:04:00.986 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-04-23T16:04:01.143 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:01.314 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-04-23T16:04:01.471 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-04-23T16:04:01.658 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-23T16:04:01.658 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:01.689 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-04-23T16:04:01.877 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-04-23T16:04:01.924 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-04-23T16:04:02.239 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-04-23T16:04:02.536 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-04-23T16:04:02.583 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:03.020 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-04-23T16:04:03.223 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-04-23T16:04:04.411 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:04.442 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-23T16:04:04.504 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:04.739 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-23T16:04:04.864 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-23T16:04:05.004 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-04-23T16:04:05.239 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-04-23T16:04:05.317 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-04-23T16:04:05.333 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-04-23T16:04:05.379 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-23T16:04:05.614 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-04-23T16:04:05.692 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-23T16:04:05.848 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-04-23T16:04:06.020 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-04-23T16:04:06.551 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-04-23T16:04:06.567 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-04-23T16:04:06.833 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-23T16:04:06.895 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-04-23T16:04:07.458 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-04-23T16:04:07.489 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-04-23T16:04:07.489 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:07.489 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-04-23T16:04:07.567 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-04-23T16:04:07.645 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-04-23T16:04:07.754 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-04-23T16:04:08.083 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-04-23T16:04:08.270 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-04-23T16:04:08.395 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-04-23T16:04:08.426 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:08.442 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-04-23T16:04:08.504 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-04-23T16:04:08.645 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-23T16:04:08.739 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-04-23T16:04:08.770 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-04-23T16:04:08.786 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-04-23T16:04:09.098 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-04-23T16:04:09.286 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-23T16:04:09.301 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-04-23T16:04:10.317 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-23T16:04:10.676 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-04-23T16:04:10.848 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:10.864 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-04-23T16:04:10.926 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-23T16:04:11.208 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-04-23T16:04:11.223 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-04-23T16:04:11.551 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-04-23T16:04:11.629 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-04-23T16:04:11.629 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-04-23T16:04:11.708 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-04-23T16:04:11.723 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-23T16:04:11.754 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-04-23T16:04:12.149 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-04-23T16:04:12.196 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-23T16:04:12.290 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-04-23T16:04:12.337 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-04-23T16:04:12.477 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-04-23T16:04:12.618 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-04-23T16:04:12.665 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-04-23T16:04:12.696 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-04-23T16:04:12.837 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-04-23T16:04:13.118 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:13.493 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-04-23T16:04:13.540 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-04-23T16:04:13.556 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:13.618 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:14.462 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:14.571 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:15.946 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-04-23T16:04:15.993 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-04-23T16:04:16.134 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-04-23T16:04:16.227 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-04-23T16:04:16.274 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:16.290 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-04-23T16:04:16.634 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-04-23T16:04:16.712 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-04-23T16:04:16.790 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-04-23T16:04:16.884 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-04-23T16:04:16.899 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-04-23T16:04:17.009 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-04-23T16:04:17.149 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-04-23T16:04:17.259 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-04-23T16:04:17.337 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-04-23T16:04:17.368 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-04-23T16:04:17.368 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-04-23T16:04:17.602 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-04-23T16:04:17.618 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-04-23T16:04:17.774 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-04-23T16:04:18.259 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-04-23T16:04:18.477 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-04-23T16:04:18.540 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-04-23T16:04:18.946 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-04-23T16:04:19.040 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-04-23T16:04:19.102 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-04-23T16:04:19.165 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-04-23T16:04:19.321 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-23T16:04:19.321 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-23T16:04:19.556 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-04-23T16:04:19.790 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2613.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-04-23T16:04:19.790 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-04-23T16:04:20.149 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-04-23T16:04:20.962 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-04-23T16:04:21.056 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-23T16:04:21.274 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-04-23T16:04:21.384 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-23T16:04:21.509 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-04-23T16:04:21.884 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-04-23T16:04:21.962 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-04-23T16:04:21.993 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-04-23T16:04:22.153 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-04-23T16:04:22.153 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-23T16:04:22.278 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-04-23T16:04:22.341 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-04-23T16:04:22.513 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-04-23T16:04:22.622 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-04-23T16:04:22.638 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:22.919 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-04-23T16:04:23.200 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-04-23T16:04:23.247 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-04-23T16:04:23.278 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-23T16:04:23.482 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-04-23T16:04:23.763 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-04-23T16:04:23.825 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:23.841 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-04-23T16:04:23.982 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:24.528 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-04-23T16:04:24.653 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-04-23T16:04:24.763 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-04-23T16:04:25.263 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-04-23T16:04:25.294 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-04-23T16:04:25.310 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-04-23T16:04:25.653 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-04-23T16:04:25.903 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-04-23T16:04:25.950 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-04-23T16:04:26.091 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-04-23T16:04:26.232 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-04-23T16:04:26.247 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-04-23T16:04:26.482 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-04-23T16:04:26.638 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-04-23T16:04:26.653 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-04-23T16:04:26.747 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-23T16:04:27.153 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-04-23T16:04:27.216 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-04-23T16:04:27.216 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-04-23T16:04:27.450 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-04-23T16:04:27.935 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-04-23T16:04:28.075 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-04-23T16:04:28.138 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-04-23T16:04:28.169 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-04-23T16:04:28.325 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-04-23T16:04:28.419 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-04-23T16:04:28.466 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-23T16:04:28.607 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:28.732 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-04-23T16:04:28.903 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-04-23T16:04:29.013 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-23T16:04:29.263 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-04-23T16:04:30.966 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-04-23T16:04:30.982 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-04-23T16:04:31.091 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-04-23T16:04:31.825 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-04-23T16:04:32.264 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-04-23T16:04:32.295 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-23T16:04:32.373 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-04-23T16:04:33.045 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-04-23T16:04:33.483 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-04-23T16:04:33.561 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-04-23T16:04:33.795 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-04-23T16:04:34.030 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-04-23T16:04:34.092 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-04-23T16:04:34.405 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-04-23T16:04:34.498 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-04-23T16:04:34.545 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-04-23T16:04:34.592 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-04-23T16:04:34.701 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-04-23T16:04:35.123 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-04-23T16:04:35.201 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-04-23T16:04:35.483 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-04-23T16:04:35.608 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-04-23T16:04:36.451 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-23T16:04:36.764 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-04-23T16:04:36.920 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-04-23T16:04:37.155 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:37.233 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:37.280 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-04-23T16:04:37.280 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:37.342 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-04-23T16:04:37.451 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-04-23T16:04:37.514 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-04-23T16:04:37.576 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-04-23T16:04:37.686 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-04-23T16:04:37.701 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-04-23T16:04:37.717 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-04-23T16:04:37.764 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-04-23T16:04:37.780 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-04-23T16:04:38.030 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-23T16:04:38.030 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-23T16:04:38.076 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-04-23T16:04:38.170 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-04-23T16:04:38.295 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-04-23T16:04:38.608 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-04-23T16:04:38.889 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-04-23T16:04:39.155 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-04-23T16:04:39.311 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-04-23T16:04:39.389 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:39.592 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-04-23T16:04:39.701 Engine:Setting original file name "msvcp140_atomic_wait_app" for "c:\program files\windowsapps\msteams_26072.519.4556.7438_x64__8wekyb3d8bbwe\msvcp140_atomic_wait_app.dll", hr=0x800710da 2026-04-23T16:04:39.858 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-04-23T16:04:39.936 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-04-23T16:04:40.123 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-04-23T16:04:40.233 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-04-23T16:04:40.467 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-04-23T16:04:40.561 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-04-23T16:04:40.639 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-04-23T16:04:40.686 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-04-23T16:04:40.717 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-04-23T16:04:40.717 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-04-23T16:04:40.795 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:41.092 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-04-23T16:04:41.108 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-04-23T16:04:41.373 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-04-23T16:04:41.733 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-23T16:04:41.826 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-04-23T16:04:42.394 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-04-23T16:04:42.409 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-04-23T16:04:42.737 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-04-23T16:04:42.800 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-04-23T16:04:42.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-04-23T16:04:43.331 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-23T16:04:43.706 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-04-23T16:04:44.065 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-04-23T16:04:44.159 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-04-23T16:04:44.394 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-04-23T16:04:44.690 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-23T16:04:44.769 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-04-23T16:04:44.878 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-04-23T16:04:44.956 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:44.987 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-04-23T16:04:45.112 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-04-23T16:04:45.487 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-04-23T16:04:45.519 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-04-23T16:04:46.269 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-04-23T16:04:46.534 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-04-23T16:04:46.644 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:46.815 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-04-23T16:04:47.222 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-04-23T16:04:47.315 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-04-23T16:04:47.378 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-04-23T16:04:47.394 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-04-23T16:04:47.472 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-04-23T16:04:47.487 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:47.612 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-23T16:04:47.675 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-23T16:04:47.784 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-04-23T16:04:47.847 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-04-23T16:04:47.894 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:48.003 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-04-23T16:04:48.315 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-04-23T16:04:48.394 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-04-23T16:04:48.581 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-04-23T16:04:49.019 Engine:Setting original file name "setup" for "c:\program files\microsoft office\root\integration\addons\vc_redist.x64.exe", hr=0x800710da 2026-04-23T16:04:49.050 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-04-23T16:04:49.472 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-23T16:04:49.565 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:49.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-04-23T16:04:50.253 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-04-23T16:04:50.581 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-04-23T16:04:50.644 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-04-23T16:04:50.690 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-04-23T16:04:50.987 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-04-23T16:04:51.128 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-04-23T16:04:51.253 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-04-23T16:04:51.737 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-04-23T16:04:52.164 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-04-23T16:04:52.179 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-23T16:04:52.304 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:52.304 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-04-23T16:04:52.335 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-04-23T16:04:52.804 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-04-23T16:04:52.851 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-04-23T16:04:52.929 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-04-23T16:04:53.210 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-04-23T16:04:53.460 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-04-23T16:04:53.539 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-23T16:04:53.585 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-04-23T16:04:53.601 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-04-23T16:04:53.726 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-04-23T16:04:54.320 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-04-23T16:04:54.585 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-04-23T16:04:54.601 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-04-23T16:04:54.648 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-04-23T16:04:54.867 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:54.976 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-04-23T16:04:55.304 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-04-23T16:04:55.304 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-04-23T16:04:55.304 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-04-23T16:04:55.570 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-04-23T16:04:55.726 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-04-23T16:04:55.835 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-04-23T16:04:56.054 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-04-23T16:04:56.148 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-04-23T16:04:56.460 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-04-23T16:04:56.539 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-04-23T16:04:56.585 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-04-23T16:04:56.617 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-04-23T16:04:57.512 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-04-23T16:04:57.699 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-04-23T16:04:57.746 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-04-23T16:04:57.934 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-04-23T16:04:58.012 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-04-23T16:04:58.105 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-04-23T16:04:58.184 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-04-23T16:04:58.262 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-04-23T16:04:58.277 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-04-23T16:04:58.309 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-04-23T16:04:58.527 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-04-23T16:04:58.574 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-23T16:04:58.637 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-04-23T16:04:58.684 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-04-23T16:04:58.684 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-04-23T16:04:59.012 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-04-23T16:04:59.137 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-23T16:04:59.184 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-23T16:04:59.215 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-04-23T16:04:59.496 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-04-23T16:04:59.621 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-04-23T16:04:59.637 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-04-23T16:04:59.652 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-04-23T16:04:59.715 OriginalFileName Maintenance::11065 files in Moac, 248 skipped (cached), 1 filename set 2026-04-23T16:04:59.715 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-23T16:05:00.469 Engine:Triggered AR EMS scan 2026-04-23T16:05:00.471 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.485 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.502 Engine:EMS scan for process: svchost pid: 788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.502 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.516 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.516 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.516 Engine:EMS scan for process: svchost pid: 1380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.534 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.534 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.534 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.534 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.548 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.548 Engine:EMS scan for process: svchost pid: 1584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.548 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.548 Engine:EMS scan for process: svchost pid: 1684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.564 Engine:EMS scan for process: svchost pid: 1704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.564 Engine:EMS scan for process: svchost pid: 1804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.564 Engine:EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.564 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.579 Engine:EMS scan for process: svchost pid: 2152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.579 Engine:EMS scan for process: svchost pid: 2176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.579 Engine:EMS scan for process: svchost pid: 2396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.579 Engine:EMS scan for process: svchost pid: 2408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.595 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.595 Engine:EMS scan for process: svchost pid: 2516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.595 Engine:EMS scan for process: svchost pid: 2524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.595 Engine:EMS scan for process: svchost pid: 2660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.595 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.611 Engine:EMS scan for process: svchost pid: 2720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.611 Engine:EMS scan for process: svchost pid: 2752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.611 Engine:EMS scan for process: svchost pid: 3004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.611 Engine:EMS scan for process: svchost pid: 2564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.626 Engine:EMS scan for process: svchost pid: 2768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.626 Engine:EMS scan for process: svchost pid: 3472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.626 Engine:EMS scan for process: svchost pid: 3480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.642 Engine:EMS scan for process: svchost pid: 3596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.642 Engine:EMS scan for process: svchost pid: 3772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.642 Engine:EMS scan for process: svchost pid: 3804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.642 Engine:EMS scan for process: svchost pid: 4080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.658 Engine:EMS scan for process: svchost pid: 3132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.658 Engine:EMS scan for process: svchost pid: 3136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.658 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.673 Engine:EMS scan for process: svchost pid: 4148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.673 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.689 Engine:EMS scan for process: svchost pid: 4412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.689 Engine:EMS scan for process: svchost pid: 4464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.689 Engine:EMS scan for process: svchost pid: 4616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.704 Engine:EMS scan for process: svchost pid: 4768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.704 Engine:EMS scan for process: dllhost pid: 5892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.704 Engine:EMS scan for process: svchost pid: 6104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.704 Engine:EMS scan for process: svchost pid: 6224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.720 Engine:EMS scan for process: svchost pid: 6592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.720 Engine:EMS scan for process: svchost pid: 6600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.720 Engine:EMS scan for process: svchost pid: 6720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.720 Engine:EMS scan for process: svchost pid: 6536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.736 Engine:EMS scan for process: svchost pid: 6664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.736 Bm signature throttled:0x00002db31bed458f 2026-04-23T16:05:00.736 Engine:EMS scan for process: svchost pid: 6888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.751 Bm signature throttled:0x00002db31bed458f 2026-04-23T16:05:00.751 Engine:EMS scan for process: svchost pid: 7020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.751 Engine:EMS scan for process: svchost pid: 5736, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.751 Engine:EMS scan for process: explorer pid: 7548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.814 Engine:EMS scan for process: svchost pid: 7652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.814 Engine:EMS scan for process: svchost pid: 7784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.814 Engine:EMS scan for process: svchost pid: 8080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.829 Engine:EMS scan for process: svchost pid: 8148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.829 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.829 Engine:EMS scan for process: svchost pid: 8340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.829 Bm signature throttled:0x00002db31bed458f 2026-04-23T16:05:00.829 Engine:EMS scan for process: svchost pid: 8372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.845 Engine:EMS scan for process: svchost pid: 9168, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.845 Engine:EMS scan for process: dllhost pid: 9476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.845 Bm signature throttled:0x00002db31bed458f 2026-04-23T16:05:00.845 Engine:EMS scan for process: svchost pid: 10176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.845 Engine:EMS scan for process: svchost pid: 10680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.861 Engine:EMS scan for process: svchost pid: 10868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.861 Bm signature throttled:0x00002db31bed458f 2026-04-23T16:05:00.861 Engine:EMS scan for process: svchost pid: 2000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.861 Engine:EMS scan for process: svchost pid: 4564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.876 Engine:EMS scan for process: svchost pid: 12012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.876 Engine:EMS scan for process: svchost pid: 7392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.892 Engine:EMS scan for process: svchost pid: 13208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.892 Engine:EMS scan for process: svchost pid: 9500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.908 Engine:EMS scan for process: svchost pid: 10396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.908 Engine:EMS scan for process: svchost pid: 8040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.908 Engine:EMS scan for process: svchost pid: 2572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.923 Engine:EMS scan for process: svchost pid: 5128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.923 Engine:EMS scan for process: svchost pid: 3856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:05:00.923 Engine:EMS scan for process: svchost pid: 5876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-23T16:08:40.581 QuickScan:ScanID:CF9AF7FB-C6FA-47C6-A721-5843014E7790: Quick scan finished with error 0 2026-04-23T16:08:41.096 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-23T16:08:41.096 [RTP] Duplicating the current plugin configuration object... 2026-04-23T16:08:41.096 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-23T16:08:41.096 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-23T16:08:41.096 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-23T16:08:41.096 [RTP] No config change detected. Not updating plugin configuration. 2026-04-23T16:08:41.096 [RTP] No config changes found. No configuration switch. 2026-04-23T16:08:41.096 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-23T16:08:42.601 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T16:08:42.601 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-23T16:08:42.601 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-23T16:16:34.885 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T16:31:39.879 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T16:41:24.875 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-23T16:46:44.873 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T17:01:49.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x8f3e43bf 2026-04-23T17:05:36.693 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T17:05:36.693 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T17:05:36.693 [Cloud] Queued cloud request. 2026-04-23T17:05:36.693 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T17:05:36.693 [Cloud] Dequeued cloud request. 2026-04-23T17:05:36.693 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T17:05:37.209 [Cloud] End of cloud request. 2026-04-23T17:05:37.209 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-04-23T17:05:37.725 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T17:16:54.884 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{DC63EB40-AD87-11D1-BC2F-7ECA0B784821} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:6564 ProcessCreationTime:134214332455081361 SessionID:1 CreationTime:04-23-2026 17:22:20 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-23T17:22:21.277 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T17:22:21.277 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T17:22:21.277 [Cloud] Queued cloud request. 2026-04-23T17:22:21.277 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T17:22:21.277 [Cloud] Dequeued cloud request. 2026-04-23T17:22:21.277 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T17:22:21.621 [Cloud] End of cloud request. 2026-04-23T17:22:22.136 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T17:31:59.879 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfb2d5db7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x772d5903 2026-04-23T17:41:58.829 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T17:41:58.829 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T17:41:58.829 [Cloud] Queued cloud request. 2026-04-23T17:41:58.829 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T17:41:58.829 [Cloud] Dequeued cloud request. 2026-04-23T17:41:58.844 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T17:41:59.672 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5c6978c898bc11fd40a0072b0b115ea4b455085c Dynamic Signature Compilation Timestamp:04-23-2026 17:41:59 Persistence Type:Duration Time remaining:288000000 2026-04-23T17:41:59.672 [Cloud] End of cloud request. 2026-04-23T17:41:59.672 RTSD:RTSD recieved, rescanning impacted resources 2026-04-23T17:42:00.188 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T17:42:35.042 ProcessImageName: httpd.exe, Pid: 6032, TotalTime: 45492, Count: 3522, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EstimatedImpact: 2% 2026-04-23T17:42:35.042 ProcessImageName: CCC.exe, Pid: 13320, TotalTime: 8878, Count: 93, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll, EstimatedImpact: 82% 2026-04-23T17:42:35.042 ProcessImageName: explorer.exe, Pid: 7548, TotalTime: 4696, Count: 90, MaxTime: 1281, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: AcroCEF.exe, Pid: 4680, TotalTime: 4409, Count: 174, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 33% 2026-04-23T17:42:35.042 ProcessImageName: Integrator.exe, Pid: 3340, TotalTime: 2325, Count: 243, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\integrator.exe_Rules.xml, EstimatedImpact: 11% 2026-04-23T17:42:35.042 ProcessImageName: firefox.exe, Pid: 11908, TotalTime: 2268, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 31% 2026-04-23T17:42:35.042 ProcessImageName: OfficeClickToRun.exe, Pid: 4116, TotalTime: 2194, Count: 127, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20090\OfficeClickToRun.exe, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: DeviceCensus.exe, Pid: 7276, TotalTime: 1732, Count: 6, MaxTime: 890, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 27% 2026-04-23T17:42:35.042 ProcessImageName: xampp-control.exe, Pid: 6660, TotalTime: 1671, Count: 2, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 97% 2026-04-23T17:42:35.042 ProcessImageName: OfficeClickToRun.exe, Pid: 2284, TotalTime: 1114, Count: 31, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: mysqld.exe, Pid: 2468, TotalTime: 1036, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: wevtutil.exe, Pid: 4400, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 68% 2026-04-23T17:42:35.042 ProcessImageName: AddInUtil.exe, Pid: 13288, TotalTime: 728, Count: 14, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 60% 2026-04-23T17:42:35.042 ProcessImageName: WmiPrvSE.exe, Pid: 14052, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 48% 2026-04-23T17:42:35.042 ProcessImageName: Integrator.exe, Pid: 10612, TotalTime: 667, Count: 68, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 590, Count: 45, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 1620, TotalTime: 578, Count: 2, MaxTime: 578, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-04-23T17:42:35.042 ProcessImageName: wevtutil.exe, Pid: 10744, TotalTime: 499, Count: 2, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 81% 2026-04-23T17:42:35.042 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 408, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 25% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 3584, TotalTime: 405, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\849067d0b991bc54206dc07ef78b89f1b00aa88d\content.phf, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: SDXHelper.exe, Pid: 1976, TotalTime: 405, Count: 6, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 12% 2026-04-23T17:42:35.042 ProcessImageName: powershell.exe, Pid: 10384, TotalTime: 401, Count: 29, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-04-23T17:42:35.042 ProcessImageName: FileCoAuth.exe, Pid: 6336, TotalTime: 288, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\Telemetry.dll, EstimatedImpact: 4% 2026-04-23T17:42:35.042 ProcessImageName: xampp-control.exe, Pid: 11844, TotalTime: 277, Count: 8, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: PhoneExperienceHost.exe, Pid: 11408, TotalTime: 271, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 255, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-23.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 13972, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-04-23T17:42:35.042 ProcessImageName: AdobeARM.exe, Pid: 3336, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 788, TotalTime: 186, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 1420, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-04-23T17:42:35.042 ProcessImageName: TabTip.exe, Pid: 3800, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-23T17:42:35.042 ProcessImageName: backgroundTaskHost.exe, Pid: 4888, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1776496823, EstimatedImpact: 20% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 4408, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: brynhildr.exe, Pid: 3636, TotalTime: 140, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 6508, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: firefox.exe, Pid: 11176, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03384, EstimatedImpact: 11% 2026-04-23T17:42:35.042 ProcessImageName: SDXHelper.exe, Pid: 6192, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 4% 2026-04-23T17:42:35.042 ProcessImageName: Acrobat.exe, Pid: 5240, TotalTime: 121, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 2% 2026-04-23T17:42:35.042 ProcessImageName: dasHost.exe, Pid: 5384, TotalTime: 106, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: backgroundTaskHost.exe, Pid: 5004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 20% 2026-04-23T17:42:35.042 ProcessImageName: spoolsv.exe, Pid: 3920, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1A5A5890-1487-4A9D-850C-1D44679C5493\94766af2.gpd, EstimatedImpact: 21% 2026-04-23T17:42:35.042 ProcessImageName: SecurityHealthHost.exe, Pid: 11668, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 8640, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 40% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 8828, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\BIT4DB0.tmp, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: taskhostw.exe, Pid: 3448, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-23T17:42:35.042 ProcessImageName: vc_redist.x64.exe, Pid: 11140, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{D79219CA-AD56-475A-9FB5-3388EABD4C4D}\.ba\BootstrapperApplicationData.xml->(UTF-16LE), EstimatedImpact: 28% 2026-04-23T17:42:35.042 ProcessImageName: AcroCEF.exe, Pid: 9400, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy4\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 10% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 6956, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 2% 2026-04-23T17:42:35.042 ProcessImageName: SDXHelper.exe, Pid: 10872, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\00111717-539E-4BFC-8BB1-9801308F4C0E, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 8036, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D573C26-27FC-4AAB-A9B7-6A77B622936D, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: OfficeClickToRun.exe, Pid: 8604, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: dllhost.exe, Pid: 3128, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{12144d5d-226d-4071-90a4-62e72600e6c5}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: vc_redist.x86.exe, Pid: 2052, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-04-23T17:42:35.042 ProcessImageName: dllhost.exe, Pid: 5892, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: AcroCEF.exe, Pid: 7916, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 2152, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: OfficeClickToRun.exe, Pid: 12216, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: StoreDesktopExtension.exe, Pid: 6876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 3872, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: SDXHelper.exe, Pid: 10716, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 2% 2026-04-23T17:42:35.042 ProcessImageName: ngentask.exe, Pid: 11108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 6628, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1748.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: xampp-control.exe, Pid: 7432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 7172, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1758a.log, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: wevtutil.exe, Pid: 11640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 24% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 8040, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1903.log, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13672, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 7412, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1936.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: Acrobat.exe, Pid: 1728, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: AggregatorHost.exe, Pid: 5476, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 9836, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1814.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 11284, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1916.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: ADNotificationManager.exe, Pid: 13852, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 12% 2026-04-23T17:42:35.042 ProcessImageName: OfficeC2RClient.exe, Pid: 13996, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1803.log, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: TeamViewer.exe, Pid: 4536, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: svchost.exe, Pid: 7392, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-23T17:42:35.042 ProcessImageName: DismHost.exe, Pid: 8072, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfba60aa9 2026-04-23T17:44:50.558 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T17:44:50.558 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T17:44:50.558 [Cloud] Queued cloud request. 2026-04-23T17:44:50.558 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T17:44:50.558 [Cloud] Dequeued cloud request. 2026-04-23T17:44:50.558 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T17:44:51.230 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e19fd16402b26582924003323d97209e28c47df5 Dynamic Signature Compilation Timestamp:04-23-2026 17:44:51 Persistence Type:Duration Time remaining:150196224 2026-04-23T17:44:51.230 [Cloud] End of cloud request. 2026-04-23T17:44:51.230 RTSD:RTSD recieved, rescanning impacted resources 2026-04-23T17:44:51.746 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T17:47:04.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T18:02:09.874 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x09224982 2026-04-23T18:09:55.415 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:09:55.415 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:09:55.415 [Cloud] Queued cloud request. 2026-04-23T18:09:55.415 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:09:55.415 [Cloud] Dequeued cloud request. 2026-04-23T18:09:55.415 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:09:56.150 [Cloud] End of cloud request. 2026-04-23T18:09:56.150 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_0.php. status=0x40030000, statusex=0x200210, threatid=0x1000139f, sigseq=0x64e730511cb7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x84aab460 2026-04-23T18:09:56.306 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:09:56.306 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:09:56.306 [Cloud] Queued cloud request. 2026-04-23T18:09:56.306 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:09:56.306 [Cloud] Dequeued cloud request. 2026-04-23T18:09:56.306 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:09:56.665 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T18:09:56.681 [Cloud] End of cloud request. 2026-04-23T18:09:56.681 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_1.php. status=0x40030000, statusex=0x200210, threatid=0x1000139f, sigseq=0x64e730511cb7 2026-04-23T18:09:57.197 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x6754f83f 2026-04-23T18:09:58.040 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:09:58.040 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:09:58.040 [Cloud] Queued cloud request. 2026-04-23T18:09:58.040 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:09:58.040 [Cloud] Dequeued cloud request. 2026-04-23T18:09:58.040 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:10:00.170 [Cloud] End of cloud request. 2026-04-23T18:10:00.170 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_51.php. status=0x40030000, statusex=0x200210, threatid=0x1000139f, sigseq=0x64e730511cb7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0xc060b555 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x4de848b7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x000048d0 2026-04-23T18:10:00.674 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x8d88b532 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x9bd0481e Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x1658b5fc Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x5bb0b59b Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x77014fc3 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0xfa89b221 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x6f242712 2026-04-23T18:10:01.689 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:10:01.689 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:10:01.689 [Cloud] Queued cloud request. 2026-04-23T18:10:01.689 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:10:01.689 [Cloud] Dequeued cloud request. 2026-04-23T18:10:01.689 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:10:02.018 [Cloud] End of cloud request. 2026-04-23T18:10:02.018 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_70.php. status=0x40030000, statusex=0x200210, threatid=0x1000139f, sigseq=0x64e730511cb7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0xe2acdaf0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0xaf44da97 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x22cc2775 2026-04-23T18:10:02.533 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T18:17:14.882 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T18:27:39.734 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #40269, FileId: 0xf400000000e5c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T18:32:19.886 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T18:44:55.479 Engine:Process 6232 will be fully monitored because of injection from C:\Program Files\uvnc bvba\UltraVNC\winvnc.exe 2026-04-23T18:45:10.163 Bm signature throttled:0x00002db31bed458f 2026-04-23T18:45:11.566 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=false, source=2, resourceid=0x0880e7ed 2026-04-23T18:45:50.154 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\mobile_reservation_application\Mobile Reservation Application\MobileReservation.apk. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x48e714e8bbc2 Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=true, source=2, resourceid=0xc05002e3 2026-04-23T18:47:24.882 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x40ea13cb 2026-04-23T18:49:08.351 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.45157~. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x0232f62b 2026-04-23T18:49:08.382 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:49:08.382 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:49:08.382 [Cloud] Queued cloud request. 2026-04-23T18:49:08.382 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:49:08.382 [Cloud] Dequeued cloud request. 2026-04-23T18:49:08.382 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:49:08.554 [Cloud] End of cloud request. 2026-04-23T18:49:08.554 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.45157~. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x74dda102 2026-04-23T18:49:08.944 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.59969~. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xf6da02ae 2026-04-23T18:49:08.976 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:49:08.976 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:49:08.976 [Cloud] Queued cloud request. 2026-04-23T18:49:08.976 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:49:08.976 [Cloud] Dequeued cloud request. 2026-04-23T18:49:08.976 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:49:09.007 [Cloud] End of cloud request. 2026-04-23T18:49:09.007 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.59969~. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-04-23T18:49:09.069 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x03093dc2 2026-04-23T18:49:09.444 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\inhalt.php. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xa947e1fe 2026-04-23T18:49:09.460 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T18:49:09.460 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T18:49:09.460 [Cloud] Queued cloud request. 2026-04-23T18:49:09.460 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T18:49:09.460 [Cloud] Dequeued cloud request. 2026-04-23T18:49:09.460 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T18:49:09.538 [Cloud] End of cloud request. 2026-04-23T18:49:09.538 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\inhalt.php. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-04-23T18:49:10.054 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xdefae229 2026-04-23T18:49:25.547 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\benutzerBearbeiten\benutzerAendernDurchfuehren.php. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x401bb71d 2026-04-23T18:49:25.797 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3_4_0\webinterface\benutzerBearbeiten\benutzerEintragen.php. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df 2026-04-23T18:54:40.786 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #44155, FileId: 0xc300000000dc7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T18:57:04.777 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #44432, FileId: 0xfc000000004cd9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T18:57:11.995 Engine:Process 684 will be fully monitored because of injection from C:\Windows\System32\dwm.exe BEGIN BM telemetry GUID:{660D3F0B-9726-BDA5-0B70-02804317E7B5} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:6576 ProcessCreationTime:134214332437588348 SessionID:1 CreationTime:04-23-2026 19:01:20 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-23T19:01:21.891 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T19:01:21.891 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T19:01:21.891 [Cloud] Queued cloud request. 2026-04-23T19:01:21.891 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T19:01:21.891 [Cloud] Dequeued cloud request. 2026-04-23T19:01:21.891 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T19:01:21.906 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-04-23T19:01:21.906 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T19:01:21.906 [Cloud] Queued cloud request. 2026-04-23T19:01:21.906 [Cloud] Dequeued cloud request. 2026-04-23T19:01:21.906 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T19:01:22.078 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-23T19:01:22.078 [Cloud] End of cloud request. 2026-04-23T19:01:22.156 [Cloud] End of cloud request. 2026-04-23T19:01:22.578 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T19:02:29.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T19:17:34.875 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T19:32:39.879 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x4d89d54f 2026-04-23T19:34:42.703 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3\webinterface\inhalt.php. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x95b2594e 2026-04-23T19:34:42.735 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T19:34:42.735 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T19:34:42.735 [Cloud] Queued cloud request. 2026-04-23T19:34:42.735 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T19:34:42.735 [Cloud] Dequeued cloud request. 2026-04-23T19:34:42.735 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T19:34:42.906 [Cloud] End of cloud request. 2026-04-23T19:34:42.906 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3\webinterface\inhalt.php. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-04-23T19:34:43.406 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x443cb0ec 2026-04-23T19:35:42.072 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T19:35:42.072 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T19:35:42.072 [Cloud] Queued cloud request. 2026-04-23T19:35:42.072 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T19:35:42.072 [Cloud] Dequeued cloud request. 2026-04-23T19:35:42.072 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T19:35:42.119 [Cloud] End of cloud request. 2026-04-23T19:35:42.119 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3\webinterface\benutzerBearbeiten\benutzerAendernDurchfuehren.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xd1c9d2db 2026-04-23T19:35:42.337 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T19:35:42.337 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T19:35:42.337 [Cloud] Queued cloud request. 2026-04-23T19:35:42.337 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T19:35:42.337 [Cloud] Dequeued cloud request. 2026-04-23T19:35:42.337 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T19:35:42.384 [Cloud] End of cloud request. 2026-04-23T19:35:42.384 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\rezervi3\webinterface\benutzerBearbeiten\benutzerEintragen.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-04-23T19:35:42.619 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T19:42:35.047 ProcessImageName: httpd.exe, Pid: 6032, TotalTime: 305680, Count: 29645, MaxTime: 3000, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\04_IPTV_AUDIO\Streamity-Xtream-IPTV-Web-player-master\player\js\video.js, EstimatedImpact: 3% 2026-04-23T19:42:35.047 ProcessImageName: CCC.exe, Pid: 13320, TotalTime: 8969, Count: 101, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: explorer.exe, Pid: 7548, TotalTime: 4741, Count: 93, MaxTime: 1281, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: AcroCEF.exe, Pid: 4680, TotalTime: 4409, Count: 174, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 33% 2026-04-23T19:42:35.047 ProcessImageName: Integrator.exe, Pid: 3340, TotalTime: 2325, Count: 243, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\integrator.exe_Rules.xml, EstimatedImpact: 11% 2026-04-23T19:42:35.047 ProcessImageName: firefox.exe, Pid: 11908, TotalTime: 2268, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 31% 2026-04-23T19:42:35.047 ProcessImageName: OfficeClickToRun.exe, Pid: 4116, TotalTime: 2194, Count: 127, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20090\OfficeClickToRun.exe, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: DeviceCensus.exe, Pid: 7276, TotalTime: 1732, Count: 6, MaxTime: 890, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 27% 2026-04-23T19:42:35.047 ProcessImageName: xampp-control.exe, Pid: 6660, TotalTime: 1671, Count: 2, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 97% 2026-04-23T19:42:35.047 ProcessImageName: OfficeClickToRun.exe, Pid: 2284, TotalTime: 1114, Count: 31, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: mysqld.exe, Pid: 2468, TotalTime: 1036, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: wevtutil.exe, Pid: 4400, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 68% 2026-04-23T19:42:35.047 ProcessImageName: AddInUtil.exe, Pid: 13288, TotalTime: 728, Count: 14, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 60% 2026-04-23T19:42:35.047 ProcessImageName: WmiPrvSE.exe, Pid: 14052, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 48% 2026-04-23T19:42:35.047 ProcessImageName: Integrator.exe, Pid: 10612, TotalTime: 667, Count: 68, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 635, Count: 49, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 1620, TotalTime: 578, Count: 2, MaxTime: 578, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-04-23T19:42:35.047 ProcessImageName: wevtutil.exe, Pid: 10744, TotalTime: 499, Count: 2, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 81% 2026-04-23T19:42:35.047 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 408, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 25% 2026-04-23T19:42:35.047 ProcessImageName: firefox.exe, Pid: 11492, TotalTime: 405, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11340, EstimatedImpact: 48% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 3584, TotalTime: 405, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\849067d0b991bc54206dc07ef78b89f1b00aa88d\content.phf, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 1976, TotalTime: 405, Count: 6, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 12% 2026-04-23T19:42:35.047 ProcessImageName: powershell.exe, Pid: 10384, TotalTime: 401, Count: 29, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-04-23T19:42:35.047 ProcessImageName: FileCoAuth.exe, Pid: 6336, TotalTime: 288, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\Telemetry.dll, EstimatedImpact: 4% 2026-04-23T19:42:35.047 ProcessImageName: xampp-control.exe, Pid: 11844, TotalTime: 277, Count: 8, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: PhoneExperienceHost.exe, Pid: 11408, TotalTime: 271, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 255, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-23.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 13972, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-04-23T19:42:35.047 ProcessImageName: AdobeARM.exe, Pid: 3336, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 788, TotalTime: 186, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 1420, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-04-23T19:42:35.047 ProcessImageName: TabTip.exe, Pid: 3800, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-23T19:42:35.047 ProcessImageName: backgroundTaskHost.exe, Pid: 4888, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1776496823, EstimatedImpact: 20% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 4408, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: brynhildr.exe, Pid: 3636, TotalTime: 140, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 6508, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: firefox.exe, Pid: 11176, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03384, EstimatedImpact: 11% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 6192, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 4% 2026-04-23T19:42:35.047 ProcessImageName: Acrobat.exe, Pid: 5240, TotalTime: 121, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 2% 2026-04-23T19:42:35.047 ProcessImageName: dasHost.exe, Pid: 5384, TotalTime: 106, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: backgroundTaskHost.exe, Pid: 5004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 20% 2026-04-23T19:42:35.047 ProcessImageName: spoolsv.exe, Pid: 3920, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1A5A5890-1487-4A9D-850C-1D44679C5493\94766af2.gpd, EstimatedImpact: 21% 2026-04-23T19:42:35.047 ProcessImageName: SecurityHealthHost.exe, Pid: 11668, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 8640, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 40% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 8828, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\BIT4DB0.tmp, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: taskhostw.exe, Pid: 3448, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-23T19:42:35.047 ProcessImageName: vc_redist.x64.exe, Pid: 11140, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{D79219CA-AD56-475A-9FB5-3388EABD4C4D}\.ba\BootstrapperApplicationData.xml->(UTF-16LE), EstimatedImpact: 28% 2026-04-23T19:42:35.047 ProcessImageName: AcroCEF.exe, Pid: 9400, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy4\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 10% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 6956, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 2% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 10872, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\00111717-539E-4BFC-8BB1-9801308F4C0E, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8036, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D573C26-27FC-4AAB-A9B7-6A77B622936D, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeClickToRun.exe, Pid: 8604, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: dllhost.exe, Pid: 3128, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{12144d5d-226d-4071-90a4-62e72600e6c5}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: vc_redist.x86.exe, Pid: 2052, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-04-23T19:42:35.047 ProcessImageName: dllhost.exe, Pid: 5892, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: AcroCEF.exe, Pid: 7916, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 2152, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeClickToRun.exe, Pid: 12216, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: StoreDesktopExtension.exe, Pid: 6876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 3872, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 10716, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 2% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 4400, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-04-23T19:42:35.047 ProcessImageName: ngentask.exe, Pid: 11108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-04-23T19:42:35.047 ProcessImageName: SDXHelper.exe, Pid: 13368, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 17% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 6628, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1748.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: wevtutil.exe, Pid: 11640, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 24% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 7172, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1758a.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 11776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2050.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8256, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1946.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: xampp-control.exe, Pid: 7432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 13372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2114.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 1644, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2057.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 8040, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1903.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 13872, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2106.log, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13672, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-23T19:42:35.047 ProcessImageName: AggregatorHost.exe, Pid: 5476, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: Acrobat.exe, Pid: 1728, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 7412, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1936.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 13172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2101.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 4004, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2027.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 3356, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2012.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 10920, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2040.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 9836, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1814.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 11284, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1916.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 14080, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-2101a.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: ADNotificationManager.exe, Pid: 13852, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 12% 2026-04-23T19:42:35.047 ProcessImageName: TeamViewer.exe, Pid: 4536, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: OfficeC2RClient.exe, Pid: 13996, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260423-1803.log, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: svchost.exe, Pid: 7392, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-23T19:42:35.047 ProcessImageName: DismHost.exe, Pid: 8072, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-04-23T19:47:44.885 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T19:54:35.020 ExpensiveFile:Scan time for `\Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\net2ftp\net2ftp_v1.4b\files_to_upload\plugins\tinymce\themes\silver\theme.min.js` is 5250 units 2026-04-23T20:02:49.880 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T20:15:02.071 Bm signature throttled:0x00002db31bed458f 2026-04-23T20:17:54.873 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T20:32:59.873 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T20:48:04.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=false, source=2, resourceid=0xe2f64208 2026-04-23T20:48:21.410 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T20:48:21.410 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T20:48:21.410 [Cloud] Queued cloud request. 2026-04-23T20:48:21.410 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T20:48:21.410 [Cloud] Dequeued cloud request. 2026-04-23T20:48:21.410 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T20:48:21.957 [Cloud] End of cloud request. 2026-04-23T20:48:21.957 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\06_Hotel\mobile_reservation_application\Mobile Reservation Application\Objects\bin\temp.ap_. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x48e714e8bbc2 2026-04-23T20:48:22.472 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T20:49:05.502 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #57568, FileId: 0xd400000000dc7a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T20:49:05.518 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #57578, FileId: 0xa500000000c866, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-23T21:03:09.875 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T21:18:14.882 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T21:26:13.799 Bm signature throttled:0x00002db31bed458f 2026-04-23T21:29:52.924 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\00017441-AC50-27C2-2060-FC2582E80200-0.bin loaded. 2026-04-23T21:29:52.924 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5944:134214533919625316) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:52.924 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:892:134214533926245033) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:53.212 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:8028:134214533927798947) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:53.418 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:14252:134214533933943602) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:53.658 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:6016:134214533934061893) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:54.591 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:1620:134214533942685322) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:55.434 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10864:134214533950834035) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:59.207 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:13732:134214533958095053) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:29:59.207 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:12240:134214533962548200) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:00.087 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:3764:134214533990837769) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:01.200 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:4420:134214533999271109) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:01.205 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10528:134214534000811148) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:02.158 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:11632:134214534018161265) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:06.373 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:11256:134214534053907475) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:06.379 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:3048:134214534054255936) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:06.387 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:12204:134214534054078122) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:14.499 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5184:134214534134070558) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:16.845 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:12328:134214534162589528) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:30:42.189 Bm signature throttled:0x00002db31bed458f 2026-04-23T21:30:46.322 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:11808:134214534457776252) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:32:17.367 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:4284:134214535367291152) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:33:19.885 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-23T21:35:20.478 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:9532:134214537200121652) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:52.189 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:4132:134214539315807429) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:52.189 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5496:134214539318586336) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:52.393 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:2556:134214539320117199) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:53.115 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5620:134214539325913340) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:53.131 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:2580:134214539326020215) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:53.986 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:12572:134214539333654584) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:57.768 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:9156:134214539347333188) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:57.768 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10500:134214539347844199) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:57.815 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:7540:134214539349440828) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:57.830 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:4432:134214539351207482) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:58.037 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10492:134214539347966685) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:58.968 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:11788:134214539380970053) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:38:59.416 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5160:134214539383177098) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:34.893 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:8968:134214539747603155) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:35.299 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:14272:134214539750421321) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:35.533 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5884:134214539751878914) is tainted: TaintType:0x6. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:36.159 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10588:134214539757462056) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:36.159 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10756:134214539757575444) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:36.674 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:10768:134214539765666091) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:39.693 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:3516:134214539779645245) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:39.707 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:12304:134214539779995832) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:39.707 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:244:134214539780121330) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:40.439 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:5252:134214539782908535) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 2026-04-23T21:39:40.439 Engine:Process C:\Program Files\Mozilla Firefox\firefox.exe (PPID:4640:134214539782187786) is tainted: TaintType:0x8. TaintReason:D:\xampp\htdocs\0_\01_myWebApps\webserver\HFS\hfs.exe, EnableCfa:1 Internal signature match:subtype=Lowfi, sigseq=0x000052E768CD5023, sigsha=d6e90fbfd42546b4ff451c955056cbdbbc72889b, cached=false, source=2, resourceid=0x22d24f50 2026-04-23T21:41:25.460 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T21:41:25.460 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T21:41:25.460 [Cloud] Queued cloud request. 2026-04-23T21:41:25.460 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T21:41:25.460 [Cloud] Dequeued cloud request. 2026-04-23T21:41:25.460 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T21:41:25.913 [Cloud] End of cloud request. 2026-04-23T21:41:25.913 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\eyeos-2.5\eyeos\system\kernel\services\MMap\implementations\MMapMobileScreen.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x52e768cd5023 Internal signature match:subtype=Lowfi, sigseq=0x000052E768CD5023, sigsha=d6e90fbfd42546b4ff451c955056cbdbbc72889b, cached=false, source=2, resourceid=0x783dce36 2026-04-23T21:41:25.928 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-23T21:41:25.928 [Cloud] Start of cloud request. Passive mode: 0 2026-04-23T21:41:25.928 [Cloud] Queued cloud request. 2026-04-23T21:41:25.928 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-23T21:41:25.928 [Cloud] Dequeued cloud request. 2026-04-23T21:41:25.944 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-23T21:41:26.288 [Cloud] End of cloud request. 2026-04-23T21:41:26.288 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\eyeos-2.5\eyeos\system\kernel\services\MMap\implementations\MMapMobileScreen.php. status=0x40030000, statusex=0x200210, threatid=0x80000000, sigseq=0x52e768cd5023 2026-04-23T21:41:26.413 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-23T21:42:35.052 ProcessImageName: httpd.exe, Pid: 6032, TotalTime: 461618, Count: 41524, MaxTime: 5250, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\net2ftp\net2ftp_v1.4b\files_to_upload\plugins\tinymce\themes\silver\theme.min.js, EstimatedImpact: 2% 2026-04-23T21:42:35.052 ProcessImageName: CCC.exe, Pid: 13320, TotalTime: 8969, Count: 101, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: explorer.exe, Pid: 7548, TotalTime: 5915, Count: 125, MaxTime: 1281, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: AcroCEF.exe, Pid: 4680, TotalTime: 4409, Count: 174, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 33% 2026-04-23T21:42:35.052 ProcessImageName: Integrator.exe, Pid: 3340, TotalTime: 2325, Count: 243, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\integrator.exe_Rules.xml, EstimatedImpact: 11% 2026-04-23T21:42:35.052 ProcessImageName: firefox.exe, Pid: 11908, TotalTime: 2268, Count: 172, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 31% 2026-04-23T21:42:35.052 ProcessImageName: OfficeClickToRun.exe, Pid: 4116, TotalTime: 2194, Count: 127, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20090\OfficeClickToRun.exe, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: DeviceCensus.exe, Pid: 7276, TotalTime: 1732, Count: 6, MaxTime: 890, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 27% 2026-04-23T21:42:35.052 ProcessImageName: xampp-control.exe, Pid: 6660, TotalTime: 1671, Count: 2, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 97% 2026-04-23T21:42:35.052 ProcessImageName: OfficeClickToRun.exe, Pid: 2284, TotalTime: 1114, Count: 31, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-04-23T21:42:35.052 ProcessImageName: mysqld.exe, Pid: 2468, TotalTime: 1036, Count: 127, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: wevtutil.exe, Pid: 4400, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 68% 2026-04-23T21:42:35.052 ProcessImageName: AddInUtil.exe, Pid: 13288, TotalTime: 728, Count: 14, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 60% 2026-04-23T21:42:35.052 ProcessImageName: WmiPrvSE.exe, Pid: 14052, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 48% 2026-04-23T21:42:35.052 ProcessImageName: Integrator.exe, Pid: 10612, TotalTime: 667, Count: 68, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-04-23T21:42:35.052 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 665, Count: 55, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: svchost.exe, Pid: 1620, TotalTime: 578, Count: 2, MaxTime: 578, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-04-23T21:42:35.052 ProcessImageName: wevtutil.exe, Pid: 10744, TotalTime: 499, Count: 2, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 81% 2026-04-23T21:42:35.052 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 408, Count: 76, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 25% 2026-04-23T21:42:35.052 ProcessImageName: firefox.exe, Pid: 11492, TotalTime: 405, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11340, EstimatedImpact: 48% 2026-04-23T21:42:35.052 ProcessImageName: svchost.exe, Pid: 3584, TotalTime: 405, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\849067d0b991bc54206dc07ef78b89f1b00aa88d\content.phf, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: SDXHelper.exe, Pid: 1976, TotalTime: 405, Count: 6, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 12% 2026-04-23T21:42:35.052 ProcessImageName: powershell.exe, Pid: 10384, TotalTime: 401, Count: 29, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-04-23T21:42:35.052 ProcessImageName: firefox.exe, Pid: 10828, TotalTime: 391, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\a8cfb9f9-5651-411f-9424-e300d9740742, EstimatedImpact: 49% 2026-04-23T21:42:35.052 ProcessImageName: FileCoAuth.exe, Pid: 6336, TotalTime: 288, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\Telemetry.dll, EstimatedImpact: 4% 2026-04-23T21:42:35.052 ProcessImageName: PhoneExperienceHost.exe, Pid: 11408, TotalTime: 286, Count: 31, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: xampp-control.exe, Pid: 11844, TotalTime: 277, Count: 8, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 1% 2026-04-23T21:42:35.052 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 255, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-23.log, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: ngentask.exe, Pid: 13972, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-04-23T21:42:35.052 ProcessImageName: AdobeARM.exe, Pid: 3336, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: svchost.exe, Pid: 788, TotalTime: 186, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: ngentask.exe, Pid: 1420, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-04-23T21:42:35.052 ProcessImageName: TabTip.exe, Pid: 3800, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-04-23T21:42:35.052 ProcessImageName: backgroundTaskHost.exe, Pid: 4888, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1776496823, EstimatedImpact: 20% 2026-04-23T21:42:35.052 ProcessImageName: ngentask.exe, Pid: 4408, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: brynhildr.exe, Pid: 3636, TotalTime: 140, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: ngentask.exe, Pid: 6508, TotalTime: 135, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: firefox.exe, Pid: 11176, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03384, EstimatedImpact: 11% 2026-04-23T21:42:35.052 ProcessImageName: SDXHelper.exe, Pid: 6192, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B1D45907-AA97-4B6D-8B4C-F3543E824137, EstimatedImpact: 4% 2026-04-23T21:42:35.052 ProcessImageName: Acrobat.exe, Pid: 5240, TotalTime: 121, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 2% 2026-04-23T21:42:35.052 ProcessImageName: dasHost.exe, Pid: 5384, TotalTime: 106, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: backgroundTaskHost.exe, Pid: 5004, TotalTime: 105, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 20% 2026-04-23T21:42:35.052 ProcessImageName: hfs.exe, Pid: 8608, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: spoolsv.exe, Pid: 3920, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1A5A5890-1487-4A9D-850C-1D44679C5493\94766af2.gpd, EstimatedImpact: 21% 2026-04-23T21:42:35.052 ProcessImageName: SecurityHealthHost.exe, Pid: 11668, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-23T21:42:35.052 ProcessImageName: ngentask.exe, Pid: 8640, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 40% 2026-04-23T21:42:35.052 ProcessImageName: svchost.exe, Pid: 8828, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\BIT4DB0.tmp, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: taskhostw.exe, Pid: 3448, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-23T21:42:35.052 ProcessImageName: vc_redist.x64.exe, Pid: 11140, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{D79219CA-AD56-475A-9FB5-3388EABD4C4D}\.ba\BootstrapperApplicationData.xml->(UTF-16LE), EstimatedImpact: 28% 2026-04-23T21:42:35.052 ProcessImageName: hfs.exe, Pid: 8812, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: AcroCEF.exe, Pid: 9400, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 1% 2026-04-23T21:42:35.052 ProcessImageName: , Pid: 4, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy4\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 10% 2026-04-23T21:42:35.052 ProcessImageName: OfficeC2RClient.exe, Pid: 6956, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 2% 2026-04-23T21:42:35.052 ProcessImageName: SDXHelper.exe, Pid: 10872, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\00111717-539E-4BFC-8BB1-9801308F4C0E, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: OfficeC2RClient.exe, Pid: 8036, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D573C26-27FC-4AAB-A9B7-6A77B622936D, EstimatedImpact: 1% 2026-04-23T21:42:35.052 ProcessImageName: OfficeClickToRun.exe, Pid: 8604, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: dllhost.exe, Pid: 3128, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{12144d5d-226d-4071-90a4-62e72600e6c5}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: dllhost.exe, Pid: 5892, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-04-23T21:42:35.052 ProcessImageName: vc_redist.x86.exe, Pid: 2052, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-04-23T21:42:35.052 ProcessImageName: GameBar.exe, Pid: 8912, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.326.2102.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-37.pri, EstimatedImpact: 3% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-24-2026 06:23:48 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/24/2026 06:23:48.710161900 UTC (14421 ms since boot) 2026-04-24T06:23:48.724 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-24T06:23:48.724 WARNING: the previous service shutdown was not expected. 2026-04-24T06:23:48.724 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T06:23:48.724 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T06:23:48.759 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260424-062348-00000003-fffffffeffffffff.bin ... 2026-04-24T06:23:48.904 [WPP] Trace session started - MpWppTracing-20260424-062348-00000003-fffffffeffffffff.bin 2026-04-24T06:23:48.909 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-24T06:23:48.910 [RbM] Rollback manager succesfully initialized. 2026-04-24T06:23:48.910 [RbM] Rollback manager EnableRollbackManager called. 2026-04-24T06:23:48.914 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-24T06:23:48.914 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-24T06:23:48.914 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-24T06:23:48.914 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-24T06:23:48.914 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-24T06:23:48.919 MdCoreSvc is supported in this platform and OS 2026-04-24T06:23:48.919 MdCoreSvc is supported in this platform and OS 2026-04-24T06:23:48.919 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T06:23:48.919 [PlatUpd] Starting MdCoreSvc service 2026-04-24T06:23:48.957 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-24T06:23:52.556 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-24T06:23:52.556 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-24T06:23:52.556 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-24T06:23:52.556 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-24T06:23:52.556 [PlatUpd] CSP platform update started 2026-04-24T06:23:52.556 [PlatUpd] Defender MDM CSP platform update not required 2026-04-24T06:23:52.556 [PlatUpd] WMI/PS provider platform update started 2026-04-24T06:23:52.556 [PlatUpd] WMI/PS provider platform update not required 2026-04-24T06:23:52.556 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-24T06:23:52.556 MdCoreSvc is supported in this platform and OS 2026-04-24T06:23:52.556 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T06:23:52.556 [PlatUpd] Starting MdCoreSvc service 2026-04-24T06:23:52.556 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-24T06:23:52.572 [TS] Troublshooting mode is not available! 2026-04-24T06:23:52.572 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T06:23:52.572 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-24T06:23:52.588 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-24T06:23:52.588 [Service] Enabling AutoLoggers ... 2026-04-24T06:23:52.588 [Service] Enabling AMSI registration ... 2026-04-24T06:23:52.588 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-24T06:23:52.603 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 53162 Number of invalid entries is 0 Number of inserts issued is 1575011 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6433 Number of lookups is 107273148 Number of lookup misses is 5144553 Number of fast lookup misses is 54691738 Number of false fast lookups is 5144548 Number of invalidations is 730129 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-24T06:23:52.603 Verifying license file... 2026-04-24T06:23:52.603 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-24T06:23:52.619 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-24T06:23:52.619 Loaded module#0 MpComServer. 2026-04-24T06:23:52.619 Loaded module#1 StartupPolicies. 2026-04-24T06:23:52.619 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T06:23:52.619 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T06:23:52.619 COM server initialized successfully. 2026-04-24T06:23:52.634 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-24T06:23:52.634 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-24T06:23:52.634 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-24T06:23:52.650 [RTP] [RTP] FilterCommunicator object 0x00000299630949B0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T06:23:52.666 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-24T06:23:52.666 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T06:23:52.666 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T06:23:52.666 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-24T06:23:52.666 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-24T06:23:52.666 [RTP] [RTP] FilterCommunicator object 0x0000029963076150 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T06:23:52.666 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-24T06:23:52.666 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-24T06:23:52.666 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-24T06:23:52.666 [RTP] [RTP] StartCommunication 0x00000299630949B0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T06:23:52.666 [init][RTP] RTPPlugin initialization completed 2026-04-24T06:23:52.666 OS boot count = 2 2026-04-24T06:23:52.666 OS Install = 0 2026-04-24T06:23:52.666 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-24T06:23:52.666 [KSL] Entering CKSLEngine::Initialize. 2026-04-24T06:23:52.666 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-24T06:23:52.666 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-24T06:23:52.681 [KSL] MpInstallKslD: hr=0x1 2026-04-24T06:23:52.681 [KSL] MpRegisterKslD: hr=0 2026-04-24T06:23:52.681 [KSL] MpStartKslD: hr=0 2026-04-24T06:23:52.681 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T06:23:52.681 Loading engine... 2026-04-24T06:23:52.697 Verifying engine and signature files (source: 1) ... 2026-04-24T06:23:52.697 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpengine.dll] due to PPL. 2026-04-24T06:23:52.697 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasbase.vdm] (file in cache) 2026-04-24T06:23:52.697 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasdlta.vdm] (file in cache) 2026-04-24T06:23:52.697 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpavbase.vdm] (file in cache) 2026-04-24T06:23:52.697 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpavdlta.vdm] (file in cache) 2026-04-24T06:23:52.744 [Engine] IsHybridMode: 0 2026-04-24T06:23:52.744 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T06:23:52.759 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0E7C28F85E653F6A9727130A3C39C28C8E584FCB.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T06:23:58.963 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T06:23:58.963 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T06:23:58.963 [Engine] New active engine 00007FFCBEE88020 (no old engine). Number of active engines: 1 2026-04-24T06:23:58.978 EngineInit:Global ASOC is enabled 2026-04-24T06:23:58.978 EngineInit:ASOO is enabled for developer volumes 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.041 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f08ecd624e78ad064b9abe13119bd3d1f7b32989 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:48 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\81a32d41a6e186f75efba21e28af9a75ddfb946f Dynamic Signature Compilation Timestamp:04-13-2026 17:20:49 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bc4564944854d1aa8191b775d7b9e99ef8598096 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:49 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\15811f65ad33b95120c71827f0f76bf54315b572 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:49 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7673c83dcc2a13ca13e47ce2efb590a9b0e97a8 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:50 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a9eea80949ab3e531bac390c0baee2d8e0b0544d Dynamic Signature Compilation Timestamp:04-13-2026 17:20:50 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\34bd1b0b1c46330ad51048a4116435706eec527e Dynamic Signature Compilation Timestamp:04-13-2026 17:20:53 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a060779f8acaddf1020988e4be70e54cd4ea0500 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:55 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\524d261bfeb9eba845cb3e03da631977329aecdf Dynamic Signature Compilation Timestamp:04-13-2026 17:20:56 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2faf3c91b1e2ddb1c211a67eb2b512a75f5b9ea2 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:56 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\58f6d38a1e77d7406c7f272c9bb9356998ef44f9 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:57 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b6119094a1b8029ef4dadf596df6f338c03ca7bb Dynamic Signature Compilation Timestamp:04-13-2026 17:20:57 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.056 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\567501869383aa781979c5a0fb722c1c2cd19b84 Dynamic Signature Compilation Timestamp:04-13-2026 17:20:57 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:23:59.088 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5c6978c898bc11fd40a0072b0b115ea4b455085c Dynamic Signature Compilation Timestamp:04-23-2026 17:41:59 Persistence Type:Duration Time remaining:288000000 2026-04-24T06:23:59.088 MpWriteUupSignatureVersion 1.449.259.0, hr = 0 2026-04-24T06:23:59.088 [SigStatUpd] CSignatureStatus: back to good 2026-04-24T06:23:59.088 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T06:23:59.119 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T06:23:59.119 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T06:23:59.119 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T06:23:59.119 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T06:23:59.119 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T06:23:59.119 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T06:23:59.119 [Plugin] Initializing RTP plugin state... 2026-04-24T06:23:59.119 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T06:23:59.119 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2106 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11671 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2315 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T06:23:59.119 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790} 2026-04-24T06:23:59.119 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:23:59.119 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:23:59.119 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:23:59.119 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T06:23:59.134 MdCoreSvc is supported in this platform and OS 2026-04-24T06:23:59.134 Engine loaded! 2026-04-24T06:23:59.134 [DLP] Create FeatureControlState instance 2026-04-24T06:23:59.134 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-24T06:23:59.134 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-24T06:23:59.134 RegisterSModeChangeListener: hr = 0x1 2026-04-24T06:23:59.134 RegisterHybridModeChangeListener: hr = 0 2026-04-24T06:23:59.150 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-24T06:23:59.150 [SigReleaseHb] Initialized with Stage 0 2026-04-24T06:23:59.150 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-24T06:23:59.150 [SCC][CID=24875_5580] Initializing ... 2026-04-24T06:23:59.150 [SCC][CID=24875_5580] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-24T06:23:59.150 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T06:23:59.150 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T06:23:59.150 [NRI] Stopping NIS service ... 2026-04-24T06:23:59.150 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-24T06:23:59.150 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.259.0 AV Signature Version: 1.449.259.0 ************************************************************ 2026-04-24T06:23:59.150 Resource usage Monitoring is enabled 2026-04-24T06:23:59.150 Job Notification: New process added to job (4660) 2026-04-24T06:23:59.150 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-24T06:23:59.150 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T06:23:59.166 Job Notification: New process added to job (7056) 2026-04-24T06:23:59.166 Job Notification: New process added to job (7020) 2026-04-24T06:23:59.181 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7056] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7020]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T06:23:59.244 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T06:23:59.244 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T06:23:59.244 Job Notification: Process exited from job (7056) 2026-04-24T06:23:59.244 Job Notification: Process exited from job (7020) 2026-04-24T06:23:59.244 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T06:23:59.244 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T06:23:59.244 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T06:23:59.244 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T06:23:59.244 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T06:23:59.244 [RTP] Generating the base plugin configuration ... 2026-04-24T06:23:59.244 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-24T06:23:59.244 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-24T06:23:59.244 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:23:59.244 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-24T06:23:59.244 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-24T06:23:59.244 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:23:59.244 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T06:23:59.259 [RTP] [RTP] StartCommunication 0x0000029963076150 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T06:23:59.259 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-24T06:23:59.259 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-24T06:23:59.572 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:23:59.603 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T06:23:59.603 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T06:23:59.603 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T06:24:02.128 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:24:02.128 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:24:02.128 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-24T06:24:02.128 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T06:24:02.128 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-24T06:24:10.643 [RTP] 1 newly mounted volumes accumulated, forcing a config update ... 2026-04-24T06:24:10.643 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:24:10.643 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:24:10.643 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-24T06:24:10.643 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-24T06:24:10.643 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-24T06:24:10.690 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-24T06:24:11.081 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-24T06:24:12.065 Engine:Triggered SMS scan for filename: explorer.exe, pid: 8424, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-04-24T06:24:40.237 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3439, FileId: 0x5400000004000d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:24:52.628 Process scan (poststartupscan) started. 2026-04-24T06:24:52.628 Process scan (poststartupscan) completed. 2026-04-24T06:24:53.128 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-24T06:24:53.143 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-24T06:24:55.701 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:24:55.701 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:24:55.701 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-24T06:24:55.701 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T06:24:55.701 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-24T06:25:51.482 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:25:51.498 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T06:25:51.498 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:26:06.873 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7412A259-2DAA-4786-9B07-35553BCC91F73738.1dcd3b33aa805b7 2026-04-24T06:26:06.967 Verifying engine and signature files (source: 0) ... 2026-04-24T06:26:06.967 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpengine.dll] due to PPL. 2026-04-24T06:26:06.967 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasbase.vdm] (file in cache) 2026-04-24T06:26:06.967 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-24T06:26:06.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasdlta.vdm] 2026-04-24T06:26:06.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavbase.vdm] (file in cache) 2026-04-24T06:26:06.982 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-24T06:26:06.998 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavdlta.vdm] 2026-04-24T06:26:07.154 [Engine] IsHybridMode: 0 2026-04-24T06:26:07.154 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T06:26:07.154 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-05C166232419B44AC8531DC89B29A1E39A3159A0.bin): 0x00000002 2026-04-24T06:26:07.170 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-05C166232419B44AC8531DC89B29A1E39A3159A0.bin) 2026-04-24T06:26:07.170 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-24T06:26:07.170 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-24T06:26:07.170 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-24T06:26:07.170 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T06:26:18.935 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T06:26:18.935 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T06:26:18.951 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFCBEE88020, lRefCount: 5, hr=0 2026-04-24T06:26:18.951 [Engine] New active engine 00007FFC8A488020 replacing engine 00007FFCBEE88020. Number of active engines: 2 2026-04-24T06:26:18.951 EngineInit:Global ASOC is enabled 2026-04-24T06:26:18.951 EngineInit:ASOO is enabled for developer volumes 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.014 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T06:26:19.029 MpWriteUupSignatureVersion 1.449.270.0, hr = 0 2026-04-24T06:26:19.029 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T06:26:19.045 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T06:26:19.045 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T06:26:19.045 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T06:26:19.045 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T06:26:19.045 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T06:26:19.060 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T06:26:19.060 [Plugin] Initializing RTP plugin state... 2026-04-24T06:26:19.060 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎24‎-‎2026 08:23:59 Last Perf:‎04‎-‎24‎-‎2026 08:23:59 First RTP Scan:‎04‎-‎24‎-‎2026 08:23:59 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2147 Misses:2953 BM Queue:0,373,0 Proc:0,189,0 File:0,184,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5245 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:7560510 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:5981 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:21946 TotalHits:13279 InstanceCacheInserts:279 InstanceCacheUpdates:0 InstanceCacheDeletes:253 InstanceCacheHits:0 InstanceCacheMisses:6777 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:7ms (1180/155) Success: 155, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T06:26:19.060 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T06:26:19.060 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783} 2026-04-24T06:26:19.060 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790}\mpasbase.vdm in use, hr=0x80070020 2026-04-24T06:26:19.060 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T06:26:19.060 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C52EEB9C-29D0-4AB4-B408-77B2537F8EB5} removed 2026-04-24T06:26:19.060 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.060 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.060 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.060 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.060 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-24-2026 06:26:19 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-24-2026 06:26:19 2026-04-24T06:26:19.076 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T06:26:19.076 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T06:26:19.076 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:26:19.076 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T06:26:19.076 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:26:19.076 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.076 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.076 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.076 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T06:26:19.076 MdCoreSvc is supported in this platform and OS Signature updated on 04-24-2026 06:26:19 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.270.0 AV Signature Version: 1.449.270.0 ************************************************************ 2026-04-24T06:26:19.076 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-24T06:26:19.076 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\7412A259-2DAA-4786-9B07-35553BCC91F73738.1dcd3b33aa805b7 2026-04-24T06:26:19.154 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T06:26:19.154 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T06:26:19.498 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T06:26:19.498 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T06:26:19.498 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T06:26:19.498 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T06:26:19.498 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T06:26:19.498 [Engine] Engine 00007FFCBEE88020 no longer in use. Number of active engines: 1 2026-04-24T06:26:19.498 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:26:19.498 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-24T06:26:19.529 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T06:26:19.529 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T06:26:19.529 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T06:26:19.623 ProcessImageName: explorer.exe, Pid: 8424, TotalTime: 6876, Count: 151, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 11% 2026-04-24T06:26:19.623 ProcessImageName: AsPowerBar.exe, Pid: 12860, TotalTime: 3194, Count: 18, MaxTime: 1203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 26% 2026-04-24T06:26:19.623 ProcessImageName: dllhost.exe, Pid: 10752, TotalTime: 2435, Count: 80, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\ISPYEID5BM_94, EstimatedImpact: 34% 2026-04-24T06:26:19.623 ProcessImageName: DipAwayMode.exe, Pid: 8124, TotalTime: 2368, Count: 15, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 7% 2026-04-24T06:26:19.623 ProcessImageName: MOM.exe, Pid: 13668, TotalTime: 1821, Count: 29, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 66% 2026-04-24T06:26:19.623 ProcessImageName: AISuite3.exe, Pid: 8132, TotalTime: 1352, Count: 22, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 10% 2026-04-24T06:26:19.623 ProcessImageName: websockify.exe, Pid: 13712, TotalTime: 895, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-04-24T06:26:19.623 ProcessImageName: TeamViewer.exe, Pid: 8400, TotalTime: 348, Count: 32, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 2% 2026-04-24T06:26:19.623 ProcessImageName: svchost.exe, Pid: 4332, TotalTime: 203, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-04-24T06:26:19.623 ProcessImageName: WhatsApp.Root.exe, Pid: 12132, TotalTime: 165, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-04-24T06:26:19.623 ProcessImageName: FileCoAuth.exe, Pid: 12016, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-04-24T06:26:19.623 ProcessImageName: PhoneExperienceHost.exe, Pid: 12252, TotalTime: 120, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-24T06:26:19.623 ProcessImageName: svchost.exe, Pid: 2072, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-24T06:26:19.623 ProcessImageName: OpenWith.exe, Pid: 12740, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26072.519.4556.7438_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 55% 2026-04-24T06:26:19.654 [Engine] RSIG_UNLOADENGINE, 00007FFCBEE88020, err=0x0 2026-04-24T06:26:19.654 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7BB4C306-D49D-4233-A0BF-835E6074C790} removed 2026-04-24T06:26:21.092 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:26:21.092 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T06:26:21.092 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:28:59.154 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T06:29:02.516 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5983, FileId: 0x15b00000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.531 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5982, FileId: 0x2200000000000ee, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.531 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5987, FileId: 0x2260000000000ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.531 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5981, FileId: 0x21e0000000000ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.923 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0b8dddf3-e1bc-45f2-91a6-856a5a72e3e5. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6028, FileId: 0x1e00000002bd08, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.923 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6026, FileId: 0x5b0000000098d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:29:02.939 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6025, FileId: 0x23b0000000000ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:31:19.004 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-24T06:33:49.395 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6950, FileId: 0xc5000000002702, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:33:49.926 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:583B8FB6-F366-48B8-9410-60DF12FC5437, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-24T06:33:49.926 Scheduled scan with Id 583B8FB6-F366-48B8-9410-60DF12FC5437 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-24T06:33:49.926 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-24T06:33:49.926 [SFC] System file cache build is not needed (already completed) 2026-04-24T06:33:49.926 [AutoPurge] Cleanup Routine tasks have started. 2026-04-24T06:33:49.926 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-24T06:33:49.926 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-24T06:33:49.926 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-24T06:33:49.926 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-24T06:33:49.926 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-24T06:33:49.926 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-24T06:33:49.957 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-24T06:33:49.957 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-24T06:33:49.957 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-24-2026 06:33:49 2026-04-24T06:33:49.989 [AutoPurge] Verification Routine tasks have started. 2026-04-24T06:33:49.989 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-24-2026 06:33:49 2026-04-24T06:33:49.989 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-24T06:33:49.989 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-24T06:33:49.989 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-24T06:33:49.989 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-24T06:33:50.004 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-24T06:33:50.317 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-24T06:33:50.317 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-24T06:33:50.379 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-24T06:33:50.395 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-24T06:33:50.411 [AutoPurge] Verification Routine tasks have ended. 2026-04-24T06:33:51.926 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:33:51.942 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T06:33:51.942 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:33:59.145 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-24T06:33:59.161 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-24T06:33:59.176 Job Notification: New process added to job (13920) 2026-04-24T06:33:59.176 Job Notification: New process added to job (7936) 2026-04-24T06:33:59.176 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-24T06:33:59.192 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:13920] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7936]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T06:33:59.239 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 75538083(ms) from now at 05:32 (03:32 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-24T06:33:59.286 Job Notification: New process added to job (13560) 2026-04-24T06:33:59.301 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-24T06:33:59.301 Job Notification: New process added to job (2776) 2026-04-24T06:33:59.301 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:13560] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2776]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T06:33:59.786 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-24T06:33:59.801 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-24T06:33:59.817 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T06:33:59.817 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T06:33:59.817 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T06:33:59.817 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T06:33:59.817 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-24T06:33:59.817 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-24T06:33:59.817 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:33:59.817 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:33:59.817 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:33:59.817 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:34:02.395 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:34:02.395 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:34:02.395 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-04-24T06:34:02.395 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:34:02.395 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T06:34:02.395 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-04-24T06:34:04.598 Job Notification: Process exited from job (13560) 2026-04-24T06:34:04.598 Job Notification: Process exited from job (2776) 2026-04-24T06:34:04.661 Job Notification: Process exited from job (13920) 2026-04-24T06:34:04.661 Job Notification: Process exited from job (7936) 2026-04-24T06:34:27.683 Engine:Process 7172 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-24T06:34:27.936 Engine:Process 7172 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-24T06:34:31.501 RPC Rundown called on ScanID: 583B8FB6-F366-48B8-9410-60DF12FC5437 2026-04-24T06:34:31.501 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:583B8FB6-F366-48B8-9410-60DF12FC5437. bRemoveFromList(ClientKilled):1 2026-04-24T06:34:31.518 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:583B8FB6-F366-48B8-9410-60DF12FC5437 2026-04-24T06:34:31.518 QuickScan:ScanID:583B8FB6-F366-48B8-9410-60DF12FC5437: Scan was stopped 2026-04-24T06:34:31.519 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:583B8FB6-F366-48B8-9410-60DF12FC5437 2026-04-24T06:34:31.519 QuickScan:ScanID:583B8FB6-F366-48B8-9410-60DF12FC5437: Quick scan aborted by callback after end stage 2026-04-24T06:34:31.519 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:583B8FB6-F366-48B8-9410-60DF12FC5437 2026-04-24T06:34:31.519 OnDemandScanWorker: Scan Cancelled! scanId:583B8FB6-F366-48B8-9410-60DF12FC5437, hr = 0x80508018 BEGIN BM telemetry GUID:{0C0160ED-F38A-EFA3-93C5-239E1A6A60F7} SignatureID:23858905925058 SigSha:bb9deb67e0a930a74a0830b0cf819e8421704cec ThreatLevel:0 ProcessID:592 ProcessCreationTime:134214854225027918 SessionID:0 CreationTime:04-24-2026 06:34:32 ImagePath:C:\Windows\System32\csrss.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-24T06:34:33.131 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:34:33.131 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:34:33.131 [Cloud] Queued cloud request. 2026-04-24T06:34:33.131 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:34:33.131 [Cloud] Dequeued cloud request. 2026-04-24T06:34:33.157 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:34:33.488 [Cloud] End of cloud request. 2026-04-24T06:34:33.533 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:34:33.553 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:34:33.556 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T06:34:33.557 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:34:52.628 Process scan (postsignatureupdatescan) started. 2026-04-24T06:34:59.706 Process scan (postsignatureupdatescan) completed. 2026-04-24T06:36:04.284 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj46292195C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8582, FileId: 0x310000000352d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.331 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5B58A09EB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8590, FileId: 0x22000000034f89, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.331 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj21A9009B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8589, FileId: 0x320000000352d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.378 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB2434991A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8595, FileId: 0x2b000000035470, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.425 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF89A5F9A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8599, FileId: 0x300000000354e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.569 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj46C4D29BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8605, FileId: 0x380000000352d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.640 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDD80E9991. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8621, FileId: 0x390000000352d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:04.671 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj331234918. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8625, FileId: 0x3b000000035557, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:05.419 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5FEB3898A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8634, FileId: 0x81000000035508, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:05.461 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj67639D9D9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8641, FileId: 0x82000000035508, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:05.490 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj58583B92E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8646, FileId: 0x46000000035556, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:05.524 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDC81F2969. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8652, FileId: 0x48000000035556, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:18.953 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8785, FileId: 0x78000000013af1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:19.031 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8789, FileId: 0x5d000000014a98, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:36:19.140 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8793, FileId: 0x2a0000000330e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:37:19.284 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8796, FileId: 0x21b00000000d69a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:37:24.456 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #8804, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x211f41cf 2026-04-24T06:37:29.174 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:29.174 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:29.174 [Cloud] Queued cloud request. 2026-04-24T06:37:29.174 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:29.174 [Cloud] Dequeued cloud request. 2026-04-24T06:37:29.174 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:29.456 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b624b0da8c1870ecdd4ef98deb361e81f8306885 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:29 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:29.456 [Cloud] End of cloud request. 2026-04-24T06:37:29.456 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7133769a 2026-04-24T06:37:29.565 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:29.565 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:29.565 [Cloud] Queued cloud request. 2026-04-24T06:37:29.565 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:29.565 [Cloud] Dequeued cloud request. 2026-04-24T06:37:29.565 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\35c7bf6823f5f561a6c6162725e57a09a4c98e52 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:29 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:29.831 [Cloud] End of cloud request. 2026-04-24T06:37:29.831 RTSD:RTSD recieved, rescanning impacted resources 2026-04-24T06:37:29.971 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a883020 2026-04-24T06:37:30.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:30.096 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:30.096 [Cloud] Queued cloud request. 2026-04-24T06:37:30.096 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:30.096 [Cloud] Dequeued cloud request. 2026-04-24T06:37:30.096 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\caefb083ecabe56a831d9807f231f91f5f0e2986 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:30 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:30.331 [Cloud] End of cloud request. 2026-04-24T06:37:30.331 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ccbb36f 2026-04-24T06:37:30.440 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:30.440 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:30.440 [Cloud] Queued cloud request. 2026-04-24T06:37:30.440 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:30.440 [Cloud] Dequeued cloud request. 2026-04-24T06:37:30.440 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b8547a5555fc9b51aea25e5d9607bce80759fb9 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:30 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:30.768 [Cloud] End of cloud request. 2026-04-24T06:37:30.768 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3dc12e4b 2026-04-24T06:37:30.831 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:37:31.174 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:31.174 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:31.174 [Cloud] Queued cloud request. 2026-04-24T06:37:31.174 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:31.174 [Cloud] Dequeued cloud request. 2026-04-24T06:37:31.174 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:31.190 Dynamic signature received 2026-04-24T06:37:31.190 Dynamic signature received 2026-04-24T06:37:31.190 Dynamic signature received 2026-04-24T06:37:31.362 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79d0beb2c03e15f52af4cc282ae6d2790bc110fd Dynamic Signature Compilation Timestamp:04-24-2026 06:37:31 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:31.362 [Cloud] End of cloud request. 2026-04-24T06:37:31.362 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c25bb8 2026-04-24T06:37:31.440 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:31.440 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:31.440 [Cloud] Queued cloud request. 2026-04-24T06:37:31.440 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:31.440 [Cloud] Dequeued cloud request. 2026-04-24T06:37:31.440 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:31.643 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f07b4d253afc62557c38b1d97663bce44acbb30b Dynamic Signature Compilation Timestamp:04-24-2026 06:37:31 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:31.643 [Cloud] End of cloud request. 2026-04-24T06:37:31.643 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6ab8889 2026-04-24T06:37:31.815 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:31.815 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:31.815 [Cloud] Queued cloud request. 2026-04-24T06:37:31.815 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:31.815 [Cloud] Dequeued cloud request. 2026-04-24T06:37:31.815 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:31.878 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:37:32.003 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c01e8f9ca8f7d7ee7fd89d11b358980ff4ba38cd Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:32.003 [Cloud] End of cloud request. 2026-04-24T06:37:32.003 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf20873eb 2026-04-24T06:37:32.081 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:32.081 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:32.081 [Cloud] Queued cloud request. 2026-04-24T06:37:32.081 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:32.081 [Cloud] Dequeued cloud request. 2026-04-24T06:37:32.081 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:32.253 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5ed85f41250532cca3e19bfa08c100c5d90500d3 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:32.253 [Cloud] End of cloud request. 2026-04-24T06:37:32.253 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb934f277 2026-04-24T06:37:32.315 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:32.315 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:32.315 [Cloud] Queued cloud request. 2026-04-24T06:37:32.315 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:32.315 [Cloud] Dequeued cloud request. 2026-04-24T06:37:32.315 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:32.503 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:37:32.518 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\56d0297c68520290cc39650380bc33f2d4fe11f9 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:32.518 [Cloud] End of cloud request. 2026-04-24T06:37:32.518 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7c337a01 2026-04-24T06:37:32.612 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:32.612 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:32.612 [Cloud] Queued cloud request. 2026-04-24T06:37:32.612 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:32.612 [Cloud] Dequeued cloud request. 2026-04-24T06:37:32.612 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:32.815 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b0d31eb6500b4224000c166d9747d089c3af5b3 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:32.815 [Cloud] End of cloud request. 2026-04-24T06:37:32.815 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe4e9c3ef 2026-04-24T06:37:32.878 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:32.878 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:32.878 [Cloud] Queued cloud request. 2026-04-24T06:37:32.878 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:32.878 [Cloud] Dequeued cloud request. 2026-04-24T06:37:32.878 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:33.018 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:37:33.085 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f437ea1d9a19d51cc0ee5b27b1d791884f0cb53a Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:33.085 [Cloud] End of cloud request. 2026-04-24T06:37:33.085 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9cab2c6 2026-04-24T06:37:33.128 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:33.128 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:33.128 [Cloud] Queued cloud request. 2026-04-24T06:37:33.128 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:33.128 [Cloud] Dequeued cloud request. 2026-04-24T06:37:33.128 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:33.393 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eb50bffb6f8a866e6032c4137cead8cd85b31679 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:33.393 [Cloud] End of cloud request. 2026-04-24T06:37:33.393 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf05abbb8 2026-04-24T06:37:33.440 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T06:37:33.440 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T06:37:33.440 [Cloud] Queued cloud request. 2026-04-24T06:37:33.440 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T06:37:33.440 [Cloud] Dequeued cloud request. 2026-04-24T06:37:33.440 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T06:37:33.596 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:37:33.675 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e3fc9f7fdff1dd41ecdd2a243a0a52acb4e3f5c Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-04-24T06:37:33.675 [Cloud] End of cloud request. 2026-04-24T06:37:33.675 RTSD:RTSD recieved, rescanning impacted resources 2026-04-24T06:37:34.190 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:39:06.690 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #9260, FileId: 0xdf00000000aace, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:40:00.878 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\Prefetch\GEEK.EXE-30F57974.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\geek.exe, Status: 0xc000004b, State: 0, ScanRequest #9320, FileId: 0x1e0000000243c9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:40:02.065 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\update[1].txt. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\geek64.exe, Status: 0xc0000001, State: 0, ScanRequest #9347, FileId: 0x1d00000004a28f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:44:04.159 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T06:46:15.222 [AutoPurge] Verification Routine tasks have started. 2026-04-24T06:46:15.222 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T06:46:15.237 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-24T06:46:15.237 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-24T06:46:15.237 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-24T06:46:15.237 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-24T06:46:15.237 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-24T06:46:15.237 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-24T06:46:15.253 [AutoPurge] Cleanup Routine tasks have started. 2026-04-24T06:46:15.253 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:5F8CDB61-3FA0-4F25-9500-199593304B13, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-24T06:46:15.253 Scheduled scan with Id 5F8CDB61-3FA0-4F25-9500-199593304B13 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-24T06:46:15.253 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-24T06:46:15.253 [SFC] System file cache build is not needed (already completed) 2026-04-24T06:46:15.253 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-24T06:46:15.268 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-24T06:46:15.268 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-24-2026 06:46:15 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-24-2026 06:46:15 2026-04-24T06:46:15.268 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-24T06:46:15.268 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-24T06:46:15.268 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-24T06:46:15.268 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-24T06:46:15.284 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-24T06:46:15.425 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-24T06:46:15.425 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-24T06:46:15.456 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-24T06:46:15.472 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-24T06:46:15.472 [AutoPurge] Verification Routine tasks have ended. 2026-04-24T06:46:16.503 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9757, FileId: 0x1900000004b056, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:46:17.253 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:46:17.253 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T06:46:17.268 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T06:46:19.222 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9761, FileId: 0x21f00000000d69a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:46:19.222 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9763, FileId: 0x2200000004a28f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T06:46:31.315 Engine:Triggered AR EMS scan 2026-04-24T06:46:31.331 Engine:EMS scan for process: lsass pid: 768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.347 Engine:EMS scan for process: svchost pid: 980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.362 Engine:EMS scan for process: svchost pid: 792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.362 Engine:EMS scan for process: svchost pid: 1048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.362 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.378 Engine:EMS scan for process: svchost pid: 1284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.378 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.378 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.378 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.393 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.393 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.393 Engine:EMS scan for process: svchost pid: 1516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.393 Engine:EMS scan for process: svchost pid: 1596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.409 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.409 Engine:EMS scan for process: svchost pid: 1692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.409 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.425 Engine:EMS scan for process: svchost pid: 1824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.425 Engine:EMS scan for process: svchost pid: 1968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.425 Engine:EMS scan for process: svchost pid: 2028, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.425 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.425 Engine:EMS scan for process: svchost pid: 2088, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.440 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.456 Engine:EMS scan for process: svchost pid: 2640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.456 Engine:EMS scan for process: svchost pid: 2680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.456 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.456 Engine:EMS scan for process: svchost pid: 2948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.472 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.472 Engine:EMS scan for process: svchost pid: 2720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.472 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.487 Engine:EMS scan for process: svchost pid: 3592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.487 Engine:EMS scan for process: svchost pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.487 Engine:EMS scan for process: svchost pid: 3684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.487 Engine:EMS scan for process: svchost pid: 3764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.503 Engine:EMS scan for process: svchost pid: 3840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.503 Engine:EMS scan for process: svchost pid: 3880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.518 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.518 Engine:EMS scan for process: svchost pid: 4108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.518 Engine:EMS scan for process: svchost pid: 4252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.518 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.534 Engine:EMS scan for process: svchost pid: 4280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.534 Engine:EMS scan for process: svchost pid: 4332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.534 Engine:EMS scan for process: svchost pid: 4564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.550 Engine:EMS scan for process: svchost pid: 4616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.550 Engine:EMS scan for process: svchost pid: 4676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.550 Engine:EMS scan for process: svchost pid: 5320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.565 Engine:EMS scan for process: dllhost pid: 5924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.565 Engine:EMS scan for process: svchost pid: 6128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.565 Engine:EMS scan for process: svchost pid: 3448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.565 Engine:EMS scan for process: svchost pid: 6620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.565 Engine:EMS scan for process: svchost pid: 6628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.581 Engine:EMS scan for process: svchost pid: 6720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.581 Engine:EMS scan for process: svchost pid: 8024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.581 Engine:EMS scan for process: svchost pid: 8056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.597 Engine:EMS scan for process: svchost pid: 7176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.612 Engine:EMS scan for process: svchost pid: 2024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.612 Engine:EMS scan for process: svchost pid: 8148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.612 Engine:EMS scan for process: explorer pid: 8424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.659 Engine:EMS scan for process: svchost pid: 8660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.659 Engine:EMS scan for process: svchost pid: 8736, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.659 Engine:EMS scan for process: svchost pid: 9152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.675 Engine:EMS scan for process: svchost pid: 6240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.675 Engine:EMS scan for process: svchost pid: 7036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.675 Engine:EMS scan for process: svchost pid: 10464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.690 Engine:EMS scan for process: dllhost pid: 10752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.690 Engine:EMS scan for process: svchost pid: 11008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.690 Engine:EMS scan for process: svchost pid: 2100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.690 Engine:EMS scan for process: svchost pid: 7872, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.690 Engine:EMS scan for process: svchost pid: 7492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.706 Engine:EMS scan for process: svchost pid: 7296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.706 Engine:EMS scan for process: svchost pid: 6008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.706 Engine:EMS scan for process: svchost pid: 8016, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.722 Engine:EMS scan for process: svchost pid: 12652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.722 Engine:EMS scan for process: svchost pid: 13688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:46:31.722 Engine:EMS scan for process: svchost pid: 14188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-24T06:49:49.128 QuickScan:ScanID:5F8CDB61-3FA0-4F25-9500-199593304B13: Quick scan finished with error 0 2026-04-24T06:49:49.643 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-24T06:49:49.659 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-24T06:49:49.659 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:49:49.659 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:49:49.659 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-24T06:49:49.659 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T06:49:49.659 [RTP] No config change detected. Not updating plugin configuration. 2026-04-24T06:49:49.659 [RTP] No config changes found. No configuration switch. 2026-04-24T06:49:49.659 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-24T06:49:49.659 [RTP] Duplicating the current plugin configuration object... 2026-04-24T06:49:49.659 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T06:49:49.659 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-04-24T06:49:49.659 [RTP] No config change detected. Not updating plugin configuration. 2026-04-24T06:49:49.659 [RTP] No config changes found. No configuration switch. 2026-04-24T06:49:49.659 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-24T06:49:49.659 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-24T06:49:49.659 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:49:49.659 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T06:49:49.659 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T06:49:49.659 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T06:49:49.659 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T06:49:49.659 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-24T06:49:49.659 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-24T06:49:49.659 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:49:49.659 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:49:49.674 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T06:49:49.721 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 67241600(ms) from now at 03:30 (01:30 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-24-2026 07:27:02 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/24/2026 07:27:02.111471500 UTC (13828 ms since boot) 2026-04-24T07:27:02.160 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-24T07:27:02.161 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T07:27:02.161 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T07:27:02.226 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260424-072702-00000003-fffffffeffffffff.bin ... 2026-04-24T07:27:02.356 [WPP] Trace session started - MpWppTracing-20260424-072702-00000003-fffffffeffffffff.bin 2026-04-24T07:27:02.361 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-24T07:27:02.361 [RbM] Rollback manager succesfully initialized. 2026-04-24T07:27:02.361 [RbM] Rollback manager EnableRollbackManager called. 2026-04-24T07:27:02.371 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-24T07:27:02.371 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-24T07:27:02.371 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-24T07:27:02.371 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-24T07:27:02.376 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-24T07:27:02.376 MdCoreSvc is supported in this platform and OS 2026-04-24T07:27:02.376 MdCoreSvc is supported in this platform and OS 2026-04-24T07:27:02.376 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T07:27:02.376 [PlatUpd] Starting MdCoreSvc service 2026-04-24T07:27:02.414 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-24T07:27:05.935 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-24T07:27:05.935 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-24T07:27:05.935 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-24T07:27:05.935 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-24T07:27:05.935 [PlatUpd] CSP platform update started 2026-04-24T07:27:05.935 [PlatUpd] Defender MDM CSP platform update not required 2026-04-24T07:27:05.935 [PlatUpd] WMI/PS provider platform update started 2026-04-24T07:27:05.935 [PlatUpd] WMI/PS provider platform update not required 2026-04-24T07:27:05.935 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-24T07:27:05.935 MdCoreSvc is supported in this platform and OS 2026-04-24T07:27:05.935 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T07:27:05.935 [PlatUpd] Starting MdCoreSvc service 2026-04-24T07:27:05.935 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-24T07:27:05.935 [TS] Troublshooting mode is not available! 2026-04-24T07:27:05.935 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T07:27:05.935 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-24T07:27:05.950 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-24T07:27:05.950 [Service] Enabling AutoLoggers ... 2026-04-24T07:27:05.950 [Service] Enabling AMSI registration ... 2026-04-24T07:27:05.950 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-24T07:27:05.966 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 53167 Number of invalid entries is 0 Number of inserts issued is 1575475 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6440 Number of lookups is 107331092 Number of lookup misses is 5147812 Number of fast lookup misses is 54720686 Number of false fast lookups is 5147807 Number of invalidations is 730588 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-24T07:27:05.966 Verifying license file... 2026-04-24T07:27:05.966 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-24T07:27:05.981 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-24T07:27:05.981 Loaded module#0 MpComServer. 2026-04-24T07:27:05.981 Loaded module#1 StartupPolicies. 2026-04-24T07:27:05.981 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T07:27:05.997 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T07:27:05.997 COM server initialized successfully. 2026-04-24T07:27:05.997 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-24T07:27:06.013 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-24T07:27:06.013 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-24T07:27:06.028 [RTP] [RTP] FilterCommunicator object 0x000002635068F230 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T07:27:06.028 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-24T07:27:06.028 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T07:27:06.028 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T07:27:06.028 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-24T07:27:06.028 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-24T07:27:06.028 [RTP] [RTP] FilterCommunicator object 0x000002635068F440 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T07:27:06.028 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-24T07:27:06.028 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-24T07:27:06.028 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-24T07:27:06.028 [RTP] [RTP] StartCommunication 0x000002635068F230 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T07:27:06.028 [init][RTP] RTPPlugin initialization completed 2026-04-24T07:27:06.028 OS boot count = 2 2026-04-24T07:27:06.028 OS Install = 0 2026-04-24T07:27:06.044 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-24T07:27:06.044 [KSL] Entering CKSLEngine::Initialize. 2026-04-24T07:27:06.044 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-24T07:27:06.044 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-24T07:27:06.044 [KSL] MpInstallKslD: hr=0x1 2026-04-24T07:27:06.044 [KSL] MpRegisterKslD: hr=0 2026-04-24T07:27:06.044 [KSL] MpStartKslD: hr=0 2026-04-24T07:27:06.044 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T07:27:06.044 Loading engine... 2026-04-24T07:27:06.060 Verifying engine and signature files (source: 1) ... 2026-04-24T07:27:06.060 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpengine.dll] due to PPL. 2026-04-24T07:27:06.060 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasbase.vdm] (file in cache) 2026-04-24T07:27:06.060 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasdlta.vdm] (file in cache) 2026-04-24T07:27:06.060 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavbase.vdm] (file in cache) 2026-04-24T07:27:06.060 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavdlta.vdm] (file in cache) 2026-04-24T07:27:06.106 [Engine] IsHybridMode: 0 2026-04-24T07:27:06.106 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T07:27:06.138 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-05C166232419B44AC8531DC89B29A1E39A3159A0.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T07:27:12.388 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T07:27:12.388 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T07:27:12.388 [Engine] New active engine 00007FF859B08020 (no old engine). Number of active engines: 1 2026-04-24T07:27:12.403 EngineInit:Global ASOC is enabled 2026-04-24T07:27:12.403 EngineInit:ASOO is enabled for developer volumes 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.481 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T07:27:12.513 MpWriteUupSignatureVersion 1.449.270.0, hr = 0 2026-04-24T07:27:12.528 [SigStatUpd] CSignatureStatus: back to good 2026-04-24T07:27:12.528 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T07:27:12.544 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T07:27:12.544 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T07:27:12.544 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T07:27:12.544 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T07:27:12.544 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T07:27:12.544 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T07:27:12.544 [Plugin] Initializing RTP plugin state... 2026-04-24T07:27:12.560 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T07:27:12.560 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2087 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11581 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2314 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T07:27:12.560 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783} 2026-04-24T07:27:12.560 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T07:27:12.560 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T07:27:12.560 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T07:27:12.560 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T07:27:12.560 MdCoreSvc is supported in this platform and OS 2026-04-24T07:27:12.560 Engine loaded! 2026-04-24T07:27:12.560 [DLP] Create FeatureControlState instance 2026-04-24T07:27:12.560 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-24T07:27:12.560 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-24T07:27:12.560 RegisterSModeChangeListener: hr = 0x1 2026-04-24T07:27:12.560 RegisterHybridModeChangeListener: hr = 0 2026-04-24T07:27:12.575 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-24T07:27:12.575 [SigReleaseHb] Initialized with Stage 0 2026-04-24T07:27:12.575 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-24T07:27:12.575 [SCC][CID=24296_5456] Initializing ... 2026-04-24T07:27:12.575 [SCC][CID=24296_5456] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-24T07:27:12.575 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T07:27:12.575 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T07:27:12.575 [NRI] Stopping NIS service ... 2026-04-24T07:27:12.575 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-24T07:27:12.575 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.270.0 AV Signature Version: 1.449.270.0 ************************************************************ 2026-04-24T07:27:12.575 Resource usage Monitoring is enabled 2026-04-24T07:27:12.575 Job Notification: New process added to job (4608) 2026-04-24T07:27:12.575 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T07:27:12.575 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-24T07:27:12.669 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T07:27:12.669 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T07:27:12.669 Job Notification: New process added to job (4708) 2026-04-24T07:27:12.669 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T07:27:12.669 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T07:27:12.669 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T07:27:12.669 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T07:27:12.669 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T07:27:12.669 [RTP] Generating the base plugin configuration ... 2026-04-24T07:27:12.669 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-24T07:27:12.669 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T07:27:12.669 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-24T07:27:12.669 Job Notification: New process added to job (7160) 2026-04-24T07:27:12.669 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-24T07:27:12.669 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T07:27:12.669 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T07:27:12.669 [RTP] [RTP] StartCommunication 0x000002635068F440 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T07:27:12.669 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-24T07:27:12.685 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:4708] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7160]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T07:27:12.685 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-24T07:27:12.763 Job Notification: Process exited from job (4708) 2026-04-24T07:27:12.763 Job Notification: Process exited from job (7160) 2026-04-24T07:27:12.763 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-24T07:27:12.997 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T07:27:13.044 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T07:27:13.044 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T07:27:13.044 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T07:27:15.575 [RTP] Duplicating the current plugin configuration object... 2026-04-24T07:27:15.575 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T07:27:15.575 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-24T07:27:15.575 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T07:27:15.575 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-24T07:28:05.997 Process scan (poststartupscan) started. 2026-04-24T07:28:05.997 Process scan (poststartupscan) completed. 2026-04-24T07:28:06.513 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-24T07:28:06.528 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-24T07:28:09.107 [RTP] Duplicating the current plugin configuration object... 2026-04-24T07:28:09.107 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T07:28:09.107 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-24T07:28:09.107 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T07:28:09.107 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-24T07:29:05.606 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T07:29:05.622 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T07:29:05.622 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T07:32:12.435 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-24T07:32:12.575 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T07:37:03.091 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #1044, FileId: 0xc700000000a9b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:37:12.575 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-24T07:37:12.575 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-24T07:37:12.606 Job Notification: New process added to job (3200) 2026-04-24T07:37:12.622 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-24T07:37:12.622 Job Notification: New process added to job (6588) 2026-04-24T07:37:12.638 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:3200] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6588]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T07:37:12.685 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 62063125(ms) from now at 02:51 (00:51 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-24T07:37:12.716 Job Notification: New process added to job (3564) 2026-04-24T07:37:12.716 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-24T07:37:12.731 Job Notification: New process added to job (6568) 2026-04-24T07:37:12.731 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:3564] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6568]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T07:37:18.966 Job Notification: Process exited from job (3564) 2026-04-24T07:37:18.966 Job Notification: Process exited from job (6568) 2026-04-24T07:37:19.044 Job Notification: Process exited from job (3200) 2026-04-24T07:37:19.044 Job Notification: Process exited from job (6588) 2026-04-24T07:46:48.362 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-04-24T07:46:48.362 [RTP] Duplicating the current plugin configuration object... 2026-04-24T07:46:48.362 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T07:46:48.362 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-24T07:46:48.362 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-24T07:46:48.362 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-24T07:46:48.721 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-24T07:47:13.255 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4174, FileId: 0x25000000065c10, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:47:17.591 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T07:47:38.969 [RTP] [Mini-filter] OpenWithoutRead notification (5829, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-04-24T07:48:01.635 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-24T07:51:24.743 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16673, FileId: 0xd000000001a696, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:51:43.060 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16684, FileId: 0x14c00000001a238, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.536 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCB3A99979. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17068, FileId: 0x2d00000001af05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.567 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEAF1BA975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17070, FileId: 0x1d00000001aef8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.567 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCDB1F997D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17071, FileId: 0x2900000001aeed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.661 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj72229C94C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17079, FileId: 0x1f00000001aef8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.719 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCC21E7989. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17077, FileId: 0x1e00000001aef8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.800 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj126585918. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17084, FileId: 0x2f00000001af05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.804 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA40C629FF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17086, FileId: 0x3000000001af05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.826 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBFA2A69EF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17089, FileId: 0xdb0000000044f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.890 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj211DB4912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17097, FileId: 0x8c00000001b039, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.952 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj81D1CC981. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17099, FileId: 0x2000000001afad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.968 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECB36799D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17100, FileId: 0x3200000001b011, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:42.983 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj910EB3920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17101, FileId: 0x3300000001b011, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:43.636 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFA75D79B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17114, FileId: 0x2400000001afad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:57.197 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17256, FileId: 0xa600000000800d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:57.259 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17260, FileId: 0x2700000001adc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:58:57.369 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17264, FileId: 0x56000000014866, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:59:08.373 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17272, FileId: 0x5c00000000ac75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T07:59:57.490 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17274, FileId: 0xae00000000800d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:01:43.335 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #17315, FileId: 0xe000000000aace, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:02:22.582 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T08:08:57.412 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17824, FileId: 0x24200000001ade6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:08:57.428 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17826, FileId: 0x3700000001aeb1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:11:10.296 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17837, FileId: 0x1800000001ae33, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:17:27.578 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T08:24:46.022 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #19114, FileId: 0x4b00000001a690, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:27:12.576 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-24T08:32:32.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T08:47:37.591 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T08:51:01.051 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19619, FileId: 0x3600000001b248, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.147 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19716, FileId: 0x7900000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.147 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19719, FileId: 0x7a00000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.147 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19715, FileId: 0x7800000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.147 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19717, FileId: 0x16600000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.147 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19718, FileId: 0x16700000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.163 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19722, FileId: 0x16800000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.163 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19724, FileId: 0x7c00000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.163 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19725, FileId: 0x7d00000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.163 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19723, FileId: 0x16900000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.178 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19728, FileId: 0x16c00000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.178 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19730, FileId: 0x8000000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.178 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19731, FileId: 0x16d00000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.178 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19733, FileId: 0x16e00000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.194 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19735, FileId: 0x8200000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.194 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19729, FileId: 0x7f00000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.194 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19737, FileId: 0x17100000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.569 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19767, FileId: 0x17300000000be79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T08:54:40.569 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13f9ee6c-0937-4ffb-a21b-a7e5f5fb803b. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #19769, FileId: 0x270000000038de, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T09:02:42.580 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T09:07:42.111 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19972, FileId: 0x4900000001b28a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T09:15:20.111 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20005, FileId: 0x3500000001b34a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T09:17:47.579 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T09:27:12.399 ProcessImageName: CCC.exe, Pid: 2960, TotalTime: 28335, Count: 577, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 4% 2026-04-24T09:27:12.399 ProcessImageName: explorer.exe, Pid: 7512, TotalTime: 5763, Count: 115, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: AcroCEF.exe, Pid: 4252, TotalTime: 3576, Count: 168, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-24T09:27:12.399 ProcessImageName: DipAwayMode.exe, Pid: 1952, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: AsPowerBar.exe, Pid: 9020, TotalTime: 2534, Count: 18, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-24T09:27:12.399 ProcessImageName: dllhost.exe, Pid: 8616, TotalTime: 2210, Count: 60, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\ISPYEID5BM_94, EstimatedImpact: 70% 2026-04-24T09:27:12.399 ProcessImageName: MOM.exe, Pid: 10152, TotalTime: 1759, Count: 30, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: AISuite3.exe, Pid: 3836, TotalTime: 1445, Count: 22, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 11% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 2228, TotalTime: 1108, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100% 2026-04-24T09:27:12.399 ProcessImageName: websockify.exe, Pid: 5812, TotalTime: 928, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 49% 2026-04-24T09:27:12.399 ProcessImageName: firefox.exe, Pid: 668, TotalTime: 555, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 42% 2026-04-24T09:27:12.399 ProcessImageName: TeamViewer.exe, Pid: 2476, TotalTime: 333, Count: 31, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\prefs.js, EstimatedImpact: 3% 2026-04-24T09:27:12.399 ProcessImageName: AdobeCollabSync.exe, Pid: 9868, TotalTime: 225, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-24.log, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: brynhildr.exe, Pid: 3488, TotalTime: 156, Count: 4, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: WhatsApp.Root.exe, Pid: 10252, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 2096, TotalTime: 138, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: FileCoAuth.exe, Pid: 8908, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: SDXHelper.exe, Pid: 8, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 10% 2026-04-24T09:27:12.399 ProcessImageName: AcroCEF.exe, Pid: 7896, TotalTime: 107, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 31% 2026-04-24T09:27:12.399 ProcessImageName: backgroundTaskHost.exe, Pid: 1756, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-24T09:27:12.399 ProcessImageName: Acrobat.exe, Pid: 1316, TotalTime: 105, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 22% 2026-04-24T09:27:12.399 ProcessImageName: PhoneExperienceHost.exe, Pid: 1692, TotalTime: 76, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 7268, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 3% 2026-04-24T09:27:12.399 ProcessImageName: taskhostw.exe, Pid: 7620, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 32% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: FileCoAuth.exe, Pid: 13220, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-24.0824.13220.1.aodl, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 12164, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-0951.log, EstimatedImpact: 2% 2026-04-24T09:27:12.399 ProcessImageName: SDXHelper.exe, Pid: 3128, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 9% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 1404, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\PushToInstall\Registration->(UTF-16LE), EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: winlogon.exe, Pid: 7692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Resources\Themes\aero\VSCache\Aero.msstyles_1031_96_01.mss, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: SDXHelper.exe, Pid: 2512, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 16% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-0959.log->(UTF-16LE), EstimatedImpact: 2% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 1120, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1107.log, EstimatedImpact: 2% 2026-04-24T09:27:12.399 ProcessImageName: TeamViewer_Service.exe, Pid: 4552, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: Acrobat.exe, Pid: 6772, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 16% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 9664, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-04-24T09:27:12.399 ProcessImageName: runonce.exe, Pid: 1432, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: dllhost.exe, Pid: 1664, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MicrosoftWindows.Client.CBS_1000.22001.1000.0_x64__cw5n1h2txyewy\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 2% 2026-04-24T09:27:12.399 ProcessImageName: backgroundTaskHost.exe, Pid: 9308, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 22% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 5592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1115.log, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: OneDriveLauncher.exe, Pid: 1736, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 12268, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1034.log, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 9536, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-0951a.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: OfficeC2RClient.exe, Pid: 5632, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1011.log->(UTF-16LE), EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: AggregatorHost.exe, Pid: 5388, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: ApplicationFrameHost.exe, Pid: 9936, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: SDXHelper.exe, Pid: 5824, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-04-24T09:27:12.399 ProcessImageName: svchost.exe, Pid: 1272, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-24T09:27:12.399 ProcessImageName: dllhost.exe, Pid: 5196, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-24T09:27:53.098 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20056, FileId: 0x2600000001b3cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T09:32:52.604 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T09:47:57.580 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T09:54:48.891 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20329, FileId: 0x8200000000d035, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:00:28.888 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20369, FileId: 0x8700000000d035, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:03:02.579 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T10:07:28.892 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20385, FileId: 0x8a00000000d035, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:12:53.906 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20417, FileId: 0x6d000000016c54, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:18:07.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T10:33:12.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T10:43:17.914 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20912, FileId: 0x2a00000001b401, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:48:17.583 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T10:49:04.559 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20949, FileId: 0x7000000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.575 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20950, FileId: 0x8900000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.575 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20953, FileId: 0x7300000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.575 Bm signature throttled:0x000045b3435c1067 2026-04-24T10:49:04.590 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20955, FileId: 0x7500000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.590 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20958, FileId: 0x7600000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.606 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20956, FileId: 0x8d00000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.606 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20962, FileId: 0x7900000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.606 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20961, FileId: 0x9200000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.606 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20960, FileId: 0x9000000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T10:49:04.621 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20964, FileId: 0x9300000001b29c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-24-2026 11:00:22 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/24/2026 11:00:22.898752500 UTC (13609 ms since boot) 2026-04-24T11:00:22.920 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-24T11:00:22.925 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T11:00:22.925 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T11:00:22.969 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260424-110022-00000003-fffffffeffffffff.bin ... 2026-04-24T11:00:23.135 [WPP] Trace session started - MpWppTracing-20260424-110022-00000003-fffffffeffffffff.bin 2026-04-24T11:00:23.135 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-24T11:00:23.140 [RbM] Rollback manager succesfully initialized. 2026-04-24T11:00:23.140 [RbM] Rollback manager EnableRollbackManager called. 2026-04-24T11:00:23.145 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-24T11:00:23.145 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-24T11:00:23.145 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-24T11:00:23.148 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-24T11:00:23.148 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-24T11:00:23.150 MdCoreSvc is supported in this platform and OS 2026-04-24T11:00:23.150 MdCoreSvc is supported in this platform and OS 2026-04-24T11:00:23.150 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T11:00:23.150 [PlatUpd] Starting MdCoreSvc service 2026-04-24T11:00:23.220 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-24T11:00:26.719 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-24T11:00:26.719 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-24T11:00:26.719 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-24T11:00:26.719 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-24T11:00:26.719 [PlatUpd] CSP platform update started 2026-04-24T11:00:26.719 [PlatUpd] Defender MDM CSP platform update not required 2026-04-24T11:00:26.719 [PlatUpd] WMI/PS provider platform update started 2026-04-24T11:00:26.719 [PlatUpd] WMI/PS provider platform update not required 2026-04-24T11:00:26.719 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-24T11:00:26.719 MdCoreSvc is supported in this platform and OS 2026-04-24T11:00:26.719 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-24T11:00:26.719 [PlatUpd] Starting MdCoreSvc service 2026-04-24T11:00:26.719 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-24T11:00:26.719 [TS] Troublshooting mode is not available! 2026-04-24T11:00:26.719 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T11:00:26.719 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-24T11:00:26.750 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-24T11:00:26.750 [Service] Enabling AutoLoggers ... 2026-04-24T11:00:26.750 [Service] Enabling AMSI registration ... 2026-04-24T11:00:26.750 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-24T11:00:26.766 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 53152 Number of invalid entries is 0 Number of inserts issued is 1575476 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6440 Number of lookups is 107370755 Number of lookup misses is 5149952 Number of fast lookup misses is 54738571 Number of false fast lookups is 5149947 Number of invalidations is 730604 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-24T11:00:26.766 Verifying license file... 2026-04-24T11:00:26.766 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-24T11:00:26.782 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-24T11:00:26.782 Loaded module#0 MpComServer. 2026-04-24T11:00:26.782 Loaded module#1 StartupPolicies. 2026-04-24T11:00:26.782 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-24T11:00:26.782 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T11:00:26.782 COM server initialized successfully. 2026-04-24T11:00:26.797 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-24T11:00:26.797 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-24T11:00:26.797 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-24T11:00:26.813 [RTP] [RTP] FilterCommunicator object 0x000001F646A9E450 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T11:00:26.813 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-24T11:00:26.813 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T11:00:26.813 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T11:00:26.813 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-24T11:00:26.813 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-24T11:00:26.813 [RTP] [RTP] FilterCommunicator object 0x000001F646A9E660 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T11:00:26.813 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-24T11:00:26.813 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-24T11:00:26.813 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-24T11:00:26.813 [RTP] [RTP] StartCommunication 0x000001F646A9E450 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-24T11:00:26.813 [init][RTP] RTPPlugin initialization completed 2026-04-24T11:00:26.813 OS boot count = 2 2026-04-24T11:00:26.813 OS Install = 0 2026-04-24T11:00:26.829 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-24T11:00:26.829 [KSL] Entering CKSLEngine::Initialize. 2026-04-24T11:00:26.829 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-24T11:00:26.829 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-24T11:00:26.829 [KSL] MpInstallKslD: hr=0x1 2026-04-24T11:00:26.829 [KSL] MpRegisterKslD: hr=0 2026-04-24T11:00:26.844 [KSL] MpStartKslD: hr=0 2026-04-24T11:00:26.844 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T11:00:26.844 Loading engine... 2026-04-24T11:00:26.860 Verifying engine and signature files (source: 1) ... 2026-04-24T11:00:26.860 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpengine.dll] due to PPL. 2026-04-24T11:00:26.860 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasbase.vdm] (file in cache) 2026-04-24T11:00:26.860 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasdlta.vdm] (file in cache) 2026-04-24T11:00:26.860 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavbase.vdm] (file in cache) 2026-04-24T11:00:26.860 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpavdlta.vdm] (file in cache) 2026-04-24T11:00:26.891 [Engine] IsHybridMode: 0 2026-04-24T11:00:26.891 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T11:00:26.922 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-05C166232419B44AC8531DC89B29A1E39A3159A0.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T11:00:33.157 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T11:00:33.157 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T11:00:33.157 [Engine] New active engine 00007FFAE7CB8020 (no old engine). Number of active engines: 1 2026-04-24T11:00:33.172 EngineInit:Global ASOC is enabled 2026-04-24T11:00:33.172 EngineInit:ASOO is enabled for developer volumes 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.250 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:00:33.282 MpWriteUupSignatureVersion 1.449.270.0, hr = 0 2026-04-24T11:00:33.282 [SigStatUpd] CSignatureStatus: back to good 2026-04-24T11:00:33.282 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T11:00:33.313 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T11:00:33.313 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T11:00:33.313 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T11:00:33.313 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T11:00:33.313 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T11:00:33.313 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T11:00:33.313 [Plugin] Initializing RTP plugin state... 2026-04-24T11:00:33.313 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T11:00:33.313 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2101 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11636 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2286 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T11:00:33.313 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783} 2026-04-24T11:00:33.329 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:00:33.329 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:00:33.329 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:00:33.329 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T11:00:33.329 MdCoreSvc is supported in this platform and OS 2026-04-24T11:00:33.329 Engine loaded! 2026-04-24T11:00:33.329 [DLP] Create FeatureControlState instance 2026-04-24T11:00:33.329 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-24T11:00:33.329 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-24T11:00:33.329 RegisterSModeChangeListener: hr = 0x1 2026-04-24T11:00:33.329 RegisterHybridModeChangeListener: hr = 0 2026-04-24T11:00:33.344 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-24T11:00:33.344 [SigReleaseHb] Initialized with Stage 0 2026-04-24T11:00:33.344 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-24T11:00:33.344 [SCC][CID=24062_5372] Initializing ... 2026-04-24T11:00:33.344 [SCC][CID=24062_5372] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-24T11:00:33.344 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T11:00:33.344 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T11:00:33.344 [NRI] Stopping NIS service ... 2026-04-24T11:00:33.344 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-24T11:00:33.344 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.270.0 AV Signature Version: 1.449.270.0 ************************************************************ 2026-04-24T11:00:33.344 Resource usage Monitoring is enabled 2026-04-24T11:00:33.344 Job Notification: New process added to job (4460) 2026-04-24T11:00:33.344 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T11:00:33.344 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-24T11:00:33.360 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6668] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6780]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T11:00:33.422 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-24T11:00:33.438 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T11:00:33.438 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T11:00:33.438 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T11:00:33.438 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T11:00:33.438 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T11:00:33.438 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T11:00:33.438 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T11:00:33.438 [RTP] Generating the base plugin configuration ... 2026-04-24T11:00:33.438 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-24T11:00:33.438 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T11:00:33.438 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-24T11:00:33.438 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-24T11:00:33.438 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T11:00:33.438 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T11:00:33.438 [RTP] [RTP] StartCommunication 0x000001F646A9E660 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-24T11:00:33.438 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-24T11:00:33.454 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-24T11:00:33.766 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T11:00:33.782 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T11:00:33.782 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T11:00:33.782 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T11:00:36.344 [RTP] Duplicating the current plugin configuration object... 2026-04-24T11:00:36.344 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T11:00:36.344 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-24T11:00:36.344 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T11:00:36.344 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-24T11:01:01.189 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-24T11:01:01.189 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-04-24T11:01:01.189 [RTP] Duplicating the current plugin configuration object... 2026-04-24T11:01:01.189 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T11:01:01.189 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-24T11:01:01.189 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-24T11:01:01.189 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-24T11:01:01.204 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-24T11:01:07.239 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-24T11:01:07.255 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-24T11:01:07.255 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-24T11:01:07.442 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-24T11:01:07.505 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-04-24T11:01:26.883 Process scan (poststartupscan) started. 2026-04-24T11:01:26.900 Process scan (poststartupscan) completed. 2026-04-24T11:01:27.402 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-24T11:01:27.418 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-24T11:01:28.324 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3102, FileId: 0x75000000035495, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:01:30.011 [RTP] Duplicating the current plugin configuration object... 2026-04-24T11:01:30.011 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-24T11:01:30.011 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-24T11:01:30.011 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-24T11:01:30.011 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-24T11:02:26.295 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T11:02:26.310 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T11:02:26.310 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T11:03:19.056 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5324, FileId: 0x2200000008a5ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:05:33.211 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-24T11:05:33.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T11:05:54.549 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6106, FileId: 0x1900000008a781, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:08:23.717 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #6771, FileId: 0x5600000008b747, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:10:32.815 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #9336, FileId: 0x3c000000061c8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:10:33.362 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-24T11:10:33.362 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-24T11:10:33.628 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 48427185(ms) from now at 02:37 (00:37 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-24T11:10:42.503 Job Notification: New process added to job (8144) 2026-04-24T11:10:42.645 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-24T11:10:42.653 Job Notification: New process added to job (8560) 2026-04-24T11:10:42.663 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:8144] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8560]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T11:10:42.901 Job Notification: New process added to job (12344) 2026-04-24T11:10:42.901 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-24T11:10:42.909 Job Notification: New process added to job (12848) 2026-04-24T11:10:42.917 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:12344] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:12848]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-24T11:10:52.878 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\4337C441-AD1B-43F4-9F93-31109868190126cc.1dcd3db02b32821 2026-04-24T11:10:52.971 Verifying engine and signature files (source: 0) ... 2026-04-24T11:10:52.971 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpengine.dll] due to PPL. 2026-04-24T11:10:52.971 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpasbase.vdm] (file in cache) 2026-04-24T11:10:52.971 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-24T11:10:52.987 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpasdlta.vdm] 2026-04-24T11:10:52.987 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpavbase.vdm] (file in cache) 2026-04-24T11:10:52.987 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-24T11:10:53.002 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpavdlta.vdm] 2026-04-24T11:10:53.159 [Engine] IsHybridMode: 0 2026-04-24T11:10:53.159 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T11:10:53.174 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F474C7666DD2B52BAE847CDF632BCECAE903AF02.bin): 0x00000002 2026-04-24T11:10:53.174 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F474C7666DD2B52BAE847CDF632BCECAE903AF02.bin) 2026-04-24T11:10:53.174 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-24T11:10:53.174 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-24T11:10:53.174 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-24T11:10:53.174 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T11:11:06.393 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T11:11:06.393 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T11:11:06.409 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFAE7CB8020, lRefCount: 5, hr=0 2026-04-24T11:11:06.409 [Engine] New active engine 00007FFAA33E8020 replacing engine 00007FFAE7CB8020. Number of active engines: 2 2026-04-24T11:11:06.409 EngineInit:Global ASOC is enabled 2026-04-24T11:11:06.409 EngineInit:ASOO is enabled for developer volumes 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.471 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T11:11:06.487 MpWriteUupSignatureVersion 1.449.272.0, hr = 0 2026-04-24T11:11:06.487 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T11:11:06.502 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T11:11:06.502 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T11:11:06.502 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T11:11:06.502 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T11:11:06.502 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T11:11:06.534 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T11:11:06.534 [Plugin] Initializing RTP plugin state... 2026-04-24T11:11:06.534 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎24‎-‎2026 13:00:33 Last Perf:‎04‎-‎24‎-‎2026 13:00:33 First RTP Scan:‎04‎-‎24‎-‎2026 13:00:33 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:3269 Misses:5923 BM Queue:0,696,0 Proc:0,620,0 File:0,266,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:9635 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:24274875 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:7625 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:34233 TotalHits:35728 InstanceCacheInserts:576 InstanceCacheUpdates:0 InstanceCacheDeletes:79 InstanceCacheHits:1 InstanceCacheMisses:9476 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (1143/370) Success: 370, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T11:11:06.534 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T11:11:06.534 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A} 2026-04-24T11:11:06.534 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{84AC4392-AEC6-45BB-9672-A54F44FACBEA} removed 2026-04-24T11:11:06.534 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T11:11:06.534 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783}\mpasbase.vdm in use, hr=0x80070020 2026-04-24T11:11:06.534 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.534 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.534 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.534 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.534 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-24-2026 11:11:06 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-24-2026 11:11:06 2026-04-24T11:11:06.534 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T11:11:06.534 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T11:11:06.534 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T11:11:06.534 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T11:11:06.549 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T11:11:06.549 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.549 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.549 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.549 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T11:11:06.549 MdCoreSvc is supported in this platform and OS Signature updated on 04-24-2026 11:11:06 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.272.0 AV Signature Version: 1.449.272.0 ************************************************************ 2026-04-24T11:11:06.549 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-24T11:11:06.549 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\4337C441-AD1B-43F4-9F93-31109868190126cc.1dcd3db02b32821 2026-04-24T11:11:06.627 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T11:11:06.627 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 04-24-2026 11:11:06 ************************************************************ 2026-04-24T11:11:06.659 Job Notification: Process exited from job (12344) 2026-04-24T11:11:06.659 Job Notification: Process exited from job (12848) 2026-04-24T11:11:06.737 Job Notification: Process exited from job (8144) 2026-04-24T11:11:06.737 Job Notification: Process exited from job (8560) 2026-04-24T11:11:06.987 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T11:11:06.987 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T11:11:06.987 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T11:11:06.987 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T11:11:06.987 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T11:11:06.987 [Engine] Engine 00007FFAE7CB8020 no longer in use. Number of active engines: 1 2026-04-24T11:11:06.987 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T11:11:06.987 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-24T11:11:07.002 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T11:11:07.002 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T11:11:07.002 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T11:11:07.096 ProcessImageName: CCC.exe, Pid: 12828, TotalTime: 30717, Count: 425, MaxTime: 2031, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 13% 2026-04-24T11:11:07.096 ProcessImageName: explorer.exe, Pid: 7784, TotalTime: 8244, Count: 168, MaxTime: 1406, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-04-24T11:11:07.096 ProcessImageName: AsPowerBar.exe, Pid: 12992, TotalTime: 3225, Count: 18, MaxTime: 1218, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-24T11:11:07.096 ProcessImageName: DipAwayMode.exe, Pid: 7284, TotalTime: 2572, Count: 15, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 11% 2026-04-24T11:11:07.096 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 2151, Count: 28, MaxTime: 750, MaxTimeFile: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\UVNC_Launch.exe, EstimatedImpact: 6% 2026-04-24T11:11:07.096 ProcessImageName: dllhost.exe, Pid: 10144, TotalTime: 2142, Count: 66, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\ISPYEID5BM_94, EstimatedImpact: 0% 2026-04-24T11:11:07.096 ProcessImageName: dllhost.exe, Pid: 9280, TotalTime: 2037, Count: 63, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\ISPYEID5BM_94, EstimatedImpact: 55% 2026-04-24T11:11:07.096 ProcessImageName: MOM.exe, Pid: 12420, TotalTime: 2009, Count: 30, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-04-24T11:11:07.096 ProcessImageName: DipAwayMode.exe, Pid: 12900, TotalTime: 1701, Count: 12, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 9% 2026-04-24T11:11:07.096 ProcessImageName: AISuite3.exe, Pid: 7276, TotalTime: 1507, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 4% 2026-04-24T11:11:07.096 ProcessImageName: AISuite3.exe, Pid: 7552, TotalTime: 1295, Count: 13, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 5% 2026-04-24T11:11:07.096 ProcessImageName: websockify.exe, Pid: 12460, TotalTime: 975, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 69% 2026-04-24T11:11:07.096 ProcessImageName: TeamViewer.exe, Pid: 3892, TotalTime: 363, Count: 35, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 0% 2026-04-24T11:11:07.096 ProcessImageName: brynhildr.exe, Pid: 3464, TotalTime: 280, Count: 5, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-24T11:11:07.096 ProcessImageName: svchost.exe, Pid: 4224, TotalTime: 265, Count: 2, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-04-24T11:11:07.127 [Engine] RSIG_UNLOADENGINE, 00007FFAE7CB8020, err=0x0 2026-04-24T11:11:07.143 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9029306D-1A57-40C7-B6BE-697C387BE783} removed 2026-04-24T11:11:08.549 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T11:11:08.549 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T11:11:08.549 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T11:11:26.924 Process scan (postsignatureupdatescan) started. 2026-04-24T11:11:27.206 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #9694, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:11:46.456 Process scan (postsignatureupdatescan) completed. 2026-04-24T11:12:19.517 [RTP] [Mini-filter] OpenWithoutRead notification (1149, 10025, \Device\HarddiskVolume3\Program Files\Mozilla Firefox\firefox.exe) sent successfully. 2026-04-24T11:13:08.417 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #10799, FileId: 0x5400000001b666, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:13:08.418 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #10800, FileId: 0x5400000001b666, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:13:08.418 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #10802, FileId: 0x1000000009928b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:15:06.471 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11368, FileId: 0x2c0000000bce65, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:16:06.453 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-24T11:20:38.353 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T11:22:05.855 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE855D7944. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12385, FileId: 0x5e0000000bd5c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:05.988 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8E0F7096C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12396, FileId: 0x5f0000000bd5c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:05.990 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEFEC749FD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12390, FileId: 0x110000000bd5b9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.037 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj77A83E998. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12392, FileId: 0xdc000000003cab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.083 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA392F29A8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12395, FileId: 0x120000000bd5b9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.196 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26FD8B94B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12411, FileId: 0x610000000bd5c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.246 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2836579FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12419, FileId: 0x1a0000000bd5b9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.446 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1A3E6969. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12435, FileId: 0x120000000bd609, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:06.550 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7137749E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12438, FileId: 0x170000000bd5f5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:07.288 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1B163F9FF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12486, FileId: 0x200000000bd5eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:07.311 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D037D9BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12489, FileId: 0x210000000bd5eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:07.359 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7719DF993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12493, FileId: 0x220000000bd5eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:20.564 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12625, FileId: 0xb7000000005f88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:20.670 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12627, FileId: 0x120000000bd0b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:22:20.765 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12631, FileId: 0x120000000bd348, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:23:20.840 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #12676, FileId: 0x4c0000000bd0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:24:06.801 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEF3C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12742, FileId: 0x11e00000000a89e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:24:10.952 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFF79.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12748, FileId: 0x2e00000008f864, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:24:16.611 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php15A2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12760, FileId: 0x12100000000a89e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:25:07.553 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #12885, FileId: 0xe100000000aace, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:25:49.124 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7EE7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12937, FileId: 0x3600000008f864, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:25:52.052 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8A52.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12939, FileId: 0x3700000008f864, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:25:55.650 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php986C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #12943, FileId: 0x670000000bd5c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:32:20.820 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #13359, FileId: 0x170000000bd656, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:32:20.822 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #13361, FileId: 0x100000000bd678, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:35:43.345 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T11:36:18.443 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php192B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13459, FileId: 0x4f0000000bd0b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:20.983 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php231E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13464, FileId: 0x2e00000001b590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:22.913 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2AA1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13471, FileId: 0x3500000004a26b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:40.182 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6E33.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13481, FileId: 0x3900000004a26b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:42.599 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php778B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13485, FileId: 0x3600000001b590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:48.068 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8CE9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13491, FileId: 0x2500000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:36:52.294 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9D84.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13496, FileId: 0x3d00000004a26b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:37:49.718 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7DD2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13780, FileId: 0x100000000bd6c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:37:52.699 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php896C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13784, FileId: 0x3900000001b590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:37:58.066 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9E6C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13789, FileId: 0x2900000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:38:05.857 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBCD2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13796, FileId: 0x3c00000001b590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:38:08.615 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC7B1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13800, FileId: 0x3d00000001b590, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:38:10.541 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCF34.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13804, FileId: 0x2c00000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:38:12.932 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD87C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13811, FileId: 0x2f00000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:38:15.224 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE166.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #13815, FileId: 0x3f000000029f7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:50:48.349 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T11:55:37.090 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC74F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14830, FileId: 0x2b00000001b59d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:55:38.929 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCE65.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14834, FileId: 0x4000000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:55:45.419 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE7CA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14840, FileId: 0x4200000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:55:59.908 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2061.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14850, FileId: 0x140000000bd67f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:56:02.274 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php29B9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14854, FileId: 0x320000000b9cb5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:56:26.543 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8874.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14990, FileId: 0x4800000008f489, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:56:35.046 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA9A9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #14999, FileId: 0x1d000000090152, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:57:37.405 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9D43.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15023, FileId: 0x11b000000014856, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:57:39.624 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA5EF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15027, FileId: 0x3b0000000b9cb5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:57:47.221 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC3A9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15032, FileId: 0x110000000befe8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:57:54.568 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE04B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15037, FileId: 0x120000000014856, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:58:30.296 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6BF2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15277, FileId: 0x4900000003da2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:58:33.075 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php76D0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15279, FileId: 0x4a00000003da2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T11:58:38.591 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8C4D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15282, FileId: 0x4c00000003da2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:00:10.332 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF277.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15568, FileId: 0x90000000c2415, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:00:16.459 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA75.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15578, FileId: 0xa0000000c2415, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:00:19.777 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1776.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15582, FileId: 0xfd000000004a2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:00:28.765 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3A80.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #15589, FileId: 0x49000000008188, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:00:33.346 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-24T12:05:53.347 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T12:14:06.928 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB67D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16000, FileId: 0x190000000c2437, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:14:15.660 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD89C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16007, FileId: 0x3700000004a21a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:14:20.879 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpED00.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16011, FileId: 0x2900000008f67d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:14:25.978 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16016, FileId: 0x2c00000008bc4c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:14:43.647 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php45EF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16019, FileId: 0x2e00000008bc4c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:20:58.346 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T12:31:20.300 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7B30.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16872, FileId: 0xe0000000ba000, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:31:25.012 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8D81.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16878, FileId: 0x110000000ba005, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:31:27.819 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php986F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16882, FileId: 0x1d000000090283, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:31:33.770 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAFB1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16886, FileId: 0x130000000ba000, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:32:05.302 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2AED.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #16895, FileId: 0xc0000000ba211, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:32:34.232 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9BE7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #17024, FileId: 0x2960000000000ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:33:02.573 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAA0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #17031, FileId: 0x110000000ba211, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T12:36:03.347 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T12:51:08.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T12:59:12.713 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19001, FileId: 0xf0000000bd284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:01:41.901 Engine:Process 1572 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-04-24T13:02:48.487 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4AF3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19420, FileId: 0x2d0000000bae03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:02:53.298 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5DB1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19424, FileId: 0x170000000bd27f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:02:59.264 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php74F3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19429, FileId: 0xa500000000500f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:03:09.422 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9CA0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19435, FileId: 0x1b0000000bd27f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:03:13.512 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpACAE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19439, FileId: 0xa900000000500f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:03:20.637 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC875.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19446, FileId: 0x290000000bcc2d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:03:41.447 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php19C2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19455, FileId: 0xae00000000500f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:06:13.357 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T13:08:45.837 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19713, FileId: 0x210000000c2447, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:11:06.420 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 8513, Count: 557, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: AcroCEF.exe, Pid: 7972, TotalTime: 4082, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 32% 2026-04-24T13:11:06.420 ProcessImageName: xampp-control.exe, Pid: 11760, TotalTime: 1855, Count: 9, MaxTime: 1609, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-04-24T13:11:06.420 ProcessImageName: httpd.exe, Pid: 6844, TotalTime: 1130, Count: 86, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_107.php, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: mysqld.exe, Pid: 10900, TotalTime: 1006, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: notepad++.exe, Pid: 11088, TotalTime: 887, Count: 69, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: WmiPrvSE.exe, Pid: 8948, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-04-24T13:11:06.420 ProcessImageName: Notepad.exe, Pid: 5912, TotalTime: 577, Count: 61, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_116.php, EstimatedImpact: 4% 2026-04-24T13:11:06.420 ProcessImageName: WmiPrvSE.exe, Pid: 4660, TotalTime: 465, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 18% 2026-04-24T13:11:06.420 ProcessImageName: httpd.exe, Pid: 3320, TotalTime: 452, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\sess_535vrga86jvb7u95qdk4v1fo2d, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: httpd.exe, Pid: 3276, TotalTime: 347, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 22% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 6156, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 12992, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 3% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 10948, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 6840, TotalTime: 226, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 6), EstimatedImpact: 1% 2026-04-24T13:11:06.420 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 218, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 58% 2026-04-24T13:11:06.420 ProcessImageName: RuntimeBroker.exe, Pid: 8420, TotalTime: 213, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{50BC8D5E-75C5-4FA0-B0EF-7754EC2C1F1C}.json, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: AdobeCollabSync.exe, Pid: 2500, TotalTime: 210, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-24.log, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 9804, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T13:11:06.420 ProcessImageName: PickerHost.exe, Pid: 2972, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: Acrobat.exe, Pid: 6812, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 9% 2026-04-24T13:11:06.420 ProcessImageName: SDXHelper.exe, Pid: 3336, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 8% 2026-04-24T13:11:06.420 ProcessImageName: OneDriveLauncher.exe, Pid: 4124, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 6% 2026-04-24T13:11:06.420 ProcessImageName: dasHost.exe, Pid: 5364, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: SDXHelper.exe, Pid: 3756, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-04-24T13:11:06.420 ProcessImageName: OfficeC2RClient.exe, Pid: 3736, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1459.log, EstimatedImpact: 3% 2026-04-24T13:11:06.420 ProcessImageName: svchost.exe, Pid: 2672, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 19% 2026-04-24T13:11:06.420 ProcessImageName: svchost.exe, Pid: 2032, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: AcroCEF.exe, Pid: 9600, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 29% 2026-04-24T13:11:06.420 ProcessImageName: notepad++.exe, Pid: 12128, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 0% 2026-04-24T13:11:06.420 ProcessImageName: OfficeC2RClient.exe, Pid: 3812, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 1% 2026-04-24T13:11:06.420 ProcessImageName: Acrobat.exe, Pid: 12880, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 3% 2026-04-24T13:11:06.420 ProcessImageName: AcroCEF.exe, Pid: 2972, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 26% 2026-04-24T13:11:06.420 ProcessImageName: AdobeARM.exe, Pid: 8064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-24T13:11:06.420 ProcessImageName: OfficeC2RClient.exe, Pid: 7756, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1508.log, EstimatedImpact: 0% 2026-04-24T13:11:06.421 ProcessImageName: TeamViewer.exe, Pid: 3076, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 8% 2026-04-24T13:11:06.421 ProcessImageName: AggregatorHost.exe, Pid: 5420, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-24T13:14:35.354 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19950, FileId: 0xb0000000c2ce2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:31.927 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC5E7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19974, FileId: 0x130000000bd065, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:42.789 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF044.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19980, FileId: 0x140000000bd064, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:44.712 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF7B7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19984, FileId: 0x150000000bd064, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:51.498 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1245.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19989, FileId: 0xcd000000004808, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:54.347 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1D81.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19995, FileId: 0xce000000004808, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:55.388 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2189.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19999, FileId: 0x160000000bd064, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:17:57.485 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php29B8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20003, FileId: 0x170000000bd064, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:01.489 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3959.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20009, FileId: 0xd5000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:02.754 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3E5B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20012, FileId: 0xd6000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:03.949 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php42F0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20016, FileId: 0xd7000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:04.897 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php46AA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20020, FileId: 0xd8000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:09.529 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php58BC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20031, FileId: 0xd9000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:10.885 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5E1C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20038, FileId: 0xda000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:11.996 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6263.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20042, FileId: 0xdb000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:18:12.883 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php65DF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20046, FileId: 0xdc000000005084, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:21:18.359 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T13:33:00.287 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF038.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20423, FileId: 0x320000000bd033, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T13:36:23.345 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T13:51:28.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T14:04:34.748 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD8A4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #21369, FileId: 0xba0000000297ee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T14:06:33.358 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T14:21:38.350 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T14:34:14.943 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php27A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23292, FileId: 0xb40000000016f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T14:36:43.353 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T14:44:02.545 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF9ED.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #23995, FileId: 0x250000000c2e03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T14:46:08.289 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE52D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #24055, FileId: 0xb0000000c3524, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T14:51:48.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T15:06:53.352 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T15:11:06.430 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 13435, Count: 817, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: AcroCEF.exe, Pid: 7972, TotalTime: 4082, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 32% 2026-04-24T15:11:06.430 ProcessImageName: httpd.exe, Pid: 3320, TotalTime: 1972, Count: 157, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: xampp-control.exe, Pid: 11760, TotalTime: 1855, Count: 9, MaxTime: 1609, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-04-24T15:11:06.430 ProcessImageName: httpd.exe, Pid: 6844, TotalTime: 1130, Count: 86, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_107.php, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: mysqld.exe, Pid: 10900, TotalTime: 1006, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: notepad++.exe, Pid: 11088, TotalTime: 887, Count: 69, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: WmiPrvSE.exe, Pid: 8948, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-04-24T15:11:06.430 ProcessImageName: Notepad.exe, Pid: 5912, TotalTime: 577, Count: 61, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_116.php, EstimatedImpact: 4% 2026-04-24T15:11:06.430 ProcessImageName: WmiPrvSE.exe, Pid: 4660, TotalTime: 465, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 18% 2026-04-24T15:11:06.430 ProcessImageName: httpd.exe, Pid: 3276, TotalTime: 347, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 22% 2026-04-24T15:11:06.430 ProcessImageName: RuntimeBroker.exe, Pid: 8420, TotalTime: 335, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{50BC8D5E-75C5-4FA0-B0EF-7754EC2C1F1C}.json, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 6156, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 12992, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 3% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 10948, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 6840, TotalTime: 226, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 6), EstimatedImpact: 1% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 4016, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T15:11:06.430 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 218, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 58% 2026-04-24T15:11:06.430 ProcessImageName: AdobeCollabSync.exe, Pid: 2500, TotalTime: 210, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-24.log, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 508, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 9804, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 2972, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 9072, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 76% 2026-04-24T15:11:06.430 ProcessImageName: PickerHost.exe, Pid: 1768, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T15:11:06.430 ProcessImageName: Acrobat.exe, Pid: 6812, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 9% 2026-04-24T15:11:06.430 ProcessImageName: SDXHelper.exe, Pid: 3336, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 8% 2026-04-24T15:11:06.430 ProcessImageName: dasHost.exe, Pid: 5364, TotalTime: 105, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: OneDriveLauncher.exe, Pid: 4124, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 6% 2026-04-24T15:11:06.430 ProcessImageName: SecurityHealthHost.exe, Pid: 3996, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 7% 2026-04-24T15:11:06.430 ProcessImageName: SDXHelper.exe, Pid: 3756, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 3736, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1459.log, EstimatedImpact: 3% 2026-04-24T15:11:06.430 ProcessImageName: svchost.exe, Pid: 2672, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 19% 2026-04-24T15:11:06.430 ProcessImageName: svchost.exe, Pid: 2032, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 4312, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1651.log, EstimatedImpact: 2% 2026-04-24T15:11:06.430 ProcessImageName: AcroCEF.exe, Pid: 9600, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 29% 2026-04-24T15:11:06.430 ProcessImageName: dllhost.exe, Pid: 2960, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 5000, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1514.log, EstimatedImpact: 2% 2026-04-24T15:11:06.430 ProcessImageName: notepad++.exe, Pid: 12128, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 3812, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 1% 2026-04-24T15:11:06.430 ProcessImageName: Acrobat.exe, Pid: 12880, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 3% 2026-04-24T15:11:06.430 ProcessImageName: AdobeARM.exe, Pid: 8064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 12440, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1603.log, EstimatedImpact: 1% 2026-04-24T15:11:06.430 ProcessImageName: AcroCEF.exe, Pid: 2972, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 26% 2026-04-24T15:11:06.430 ProcessImageName: pingsender.exe, Pid: 7740, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\b9aaed57-fcae-4162-b808-137c6c693330, EstimatedImpact: 6% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 7756, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1508.log, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: SDXHelper.exe, Pid: 1956, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-04-24T15:11:06.430 ProcessImageName: AggregatorHost.exe, Pid: 5420, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: OfficeC2RClient.exe, Pid: 13040, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1547.log, EstimatedImpact: 0% 2026-04-24T15:11:06.430 ProcessImageName: TeamViewer.exe, Pid: 3076, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 8% 2026-04-24T15:11:06.430 ProcessImageName: SDXHelper.exe, Pid: 12160, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-24T15:21:58.346 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T15:25:28.756 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE9A8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #26209, FileId: 0x3c0000000ab5e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:34:31.147 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3078.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #27234, FileId: 0xca00000001db27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:37:03.347 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T15:49:18.442 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA8631A94C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #27998, FileId: 0x40000000c366d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:49:18.780 [RTP] [Mini-filter] Unsuccessful scan status(#190): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2FB13D916. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #28008, FileId: 0xd0000000c366e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:49:19.177 [RTP] [Mini-filter] Unsuccessful scan status(#200): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD7A0119C8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #28018, FileId: 0x40000000c366f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:49:20.166 [RTP] [Mini-filter] Unsuccessful scan status(#210): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2A687A952. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #28028, FileId: 0x1f0000000c366e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{DF2E190C-4D1E-FE43-878E-3DB3A8DABD0B} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:11596 ProcessCreationTime:134215056015158803 SessionID:3 CreationTime:04-24-2026 15:52:04 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-24T15:52:04.952 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-24T15:52:04.952 [Cloud] Start of cloud request. Passive mode: 0 2026-04-24T15:52:04.952 [Cloud] Queued cloud request. 2026-04-24T15:52:04.952 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-24T15:52:04.952 [Cloud] Dequeued cloud request. 2026-04-24T15:52:04.952 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-24T15:52:05.712 [Cloud] End of cloud request. 2026-04-24T15:52:06.236 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T15:52:08.337 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T15:54:41.084 [RTP] [Mini-filter] Unsuccessful scan status(#220): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #28099, FileId: 0x3400000001b28d, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T15:54:41.769 [RTP] [Mini-filter] Unsuccessful scan status(#230): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #28169, FileId: 0x4100000001b28d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:04:09.196 [RTP] [Mini-filter] Unsuccessful scan status(#240): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php524F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #28784, FileId: 0xa7000000001e79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:07:13.272 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T16:18:19.463 [RTP] [Mini-filter] Unsuccessful scan status(#250): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4BE2.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29305, FileId: 0x20000000c3708, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:22:18.219 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T16:31:58.255 [RTP] [Mini-filter] Unsuccessful scan status(#260): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCA96.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29827, FileId: 0x250000000c353c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:32:50.959 [RTP] [Mini-filter] Unsuccessful scan status(#270): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9873.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #29888, FileId: 0x260000000c35da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:37:23.182 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T16:39:25.713 [RTP] [Mini-filter] Unsuccessful scan status(#280): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9E8B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #30294, FileId: 0x3a0000000c351e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:43:40.214 [RTP] [Mini-filter] Unsuccessful scan status(#290): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php80CA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #30581, FileId: 0x30000000c3738, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T16:52:28.156 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T17:07:33.130 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T17:11:06.218 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 19153, Count: 1296, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: AcroCEF.exe, Pid: 7972, TotalTime: 4082, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 32% 2026-04-24T17:11:06.218 ProcessImageName: httpd.exe, Pid: 3320, TotalTime: 3898, Count: 297, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: firefox.exe, Pid: 2016, TotalTime: 2687, Count: 234, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 68% 2026-04-24T17:11:06.218 ProcessImageName: xampp-control.exe, Pid: 11760, TotalTime: 1855, Count: 9, MaxTime: 1609, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-04-24T17:11:06.218 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6580, TotalTime: 1391, Count: 66, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\OneDrive.Sync.Service.dll, EstimatedImpact: 19% 2026-04-24T17:11:06.218 ProcessImageName: httpd.exe, Pid: 6844, TotalTime: 1130, Count: 86, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_107.php, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: mysqld.exe, Pid: 10900, TotalTime: 1006, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: notepad++.exe, Pid: 11088, TotalTime: 887, Count: 69, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: WmiPrvSE.exe, Pid: 8948, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-04-24T17:11:06.218 ProcessImageName: Notepad.exe, Pid: 5912, TotalTime: 577, Count: 61, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_116.php, EstimatedImpact: 4% 2026-04-24T17:11:06.218 ProcessImageName: RuntimeBroker.exe, Pid: 8420, TotalTime: 577, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{50BC8D5E-75C5-4FA0-B0EF-7754EC2C1F1C}.json, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: WmiPrvSE.exe, Pid: 4660, TotalTime: 465, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 18% 2026-04-24T17:11:06.218 ProcessImageName: httpd.exe, Pid: 3276, TotalTime: 347, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 22% 2026-04-24T17:11:06.218 ProcessImageName: AdobeCollabSync.exe, Pid: 2500, TotalTime: 270, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-24.log, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 6156, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 12992, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 3% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 10948, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 6840, TotalTime: 226, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 6), EstimatedImpact: 1% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 4016, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 8868, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.218 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 218, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 58% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 11136, TotalTime: 211, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 4), EstimatedImpact: 2% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 10808, TotalTime: 211, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 3)->[CMDEmbedded], EstimatedImpact: 1% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 508, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 9804, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 1800, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 2972, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 0% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 9300, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 7% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 7316, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 9072, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 76% 2026-04-24T17:11:06.218 ProcessImageName: PickerHost.exe, Pid: 1768, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: PickerHost.exe, Pid: 1236, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: TabTip.exe, Pid: 11788, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 92% 2026-04-24T17:11:06.219 ProcessImageName: PickerHost.exe, Pid: 3664, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T17:11:06.219 ProcessImageName: PickerHost.exe, Pid: 1304, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T17:11:06.219 ProcessImageName: PickerHost.exe, Pid: 2780, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: PickerHost.exe, Pid: 7348, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: dasHost.exe, Pid: 5364, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: Acrobat.exe, Pid: 6812, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 9% 2026-04-24T17:11:06.219 ProcessImageName: SDXHelper.exe, Pid: 3336, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 8% 2026-04-24T17:11:06.219 ProcessImageName: backgroundTaskHost.exe, Pid: 3484, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 26% 2026-04-24T17:11:06.219 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 105, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: OneDriveLauncher.exe, Pid: 4124, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 6% 2026-04-24T17:11:06.219 ProcessImageName: FileCoAuth.exe, Pid: 13008, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: svchost.exe, Pid: 2032, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: SecurityHealthHost.exe, Pid: 3996, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 7% 2026-04-24T17:11:06.219 ProcessImageName: SDXHelper.exe, Pid: 3756, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 3736, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1459.log, EstimatedImpact: 3% 2026-04-24T17:11:06.219 ProcessImageName: svchost.exe, Pid: 2672, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 19% 2026-04-24T17:11:06.219 ProcessImageName: svchost.exe, Pid: 12096, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITF74D.tmp, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: dllhost.exe, Pid: 2960, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: PhoneExperienceHost.exe, Pid: 2536, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 4312, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1651.log, EstimatedImpact: 2% 2026-04-24T17:11:06.219 ProcessImageName: AcroCEF.exe, Pid: 9600, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 29% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 5000, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1514.log, EstimatedImpact: 2% 2026-04-24T17:11:06.219 ProcessImageName: notepad++.exe, Pid: 12128, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 3812, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: AggregatorHost.exe, Pid: 5420, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: Acrobat.exe, Pid: 12880, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 3% 2026-04-24T17:11:06.219 ProcessImageName: SDXHelper.exe, Pid: 8756, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 12440, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1603.log, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: AcroCEF.exe, Pid: 2972, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 26% 2026-04-24T17:11:06.219 ProcessImageName: AdobeARM.exe, Pid: 8064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-24T17:11:06.219 ProcessImageName: pingsender.exe, Pid: 7740, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\b9aaed57-fcae-4162-b808-137c6c693330, EstimatedImpact: 6% 2026-04-24T17:11:06.219 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13076, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 7756, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1508.log, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: SDXHelper.exe, Pid: 1956, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-04-24T17:11:06.219 ProcessImageName: OfficeC2RClient.exe, Pid: 13040, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1547.log, EstimatedImpact: 0% 2026-04-24T17:11:06.219 ProcessImageName: TeamViewer.exe, Pid: 3076, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 8% 2026-04-24T17:11:06.219 ProcessImageName: SDXHelper.exe, Pid: 12160, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-24T17:22:38.109 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T17:25:29.270 [RTP] [Mini-filter] Unsuccessful scan status(#300): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCA09.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #32862, FileId: 0x1050000000044e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T17:37:43.100 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T17:38:21.924 [RTP] [Mini-filter] Unsuccessful scan status(#310): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9432.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #34354, FileId: 0x1000000009a044, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T17:49:05.412 [RTP] [Mini-filter] Unsuccessful scan status(#320): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #49123, FileId: 0xa800000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T17:52:19.643 [RTP] [Mini-filter] Unsuccessful scan status(#330): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5C9B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #49182, FileId: 0xb700000000443c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T17:52:48.095 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T18:07:53.097 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T18:10:04.429 [RTP] [Mini-filter] Unsuccessful scan status(#340): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9C01.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #49387, FileId: 0xe000000000418a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T18:22:58.092 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T18:38:03.075 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T18:43:02.550 [RTP] [Mini-filter] Unsuccessful scan status(#350): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCB27.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #50986, FileId: 0x18000000099feb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T18:48:59.432 [RTP] [Mini-filter] Unsuccessful scan status(#360): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3D4C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #51319, FileId: 0x1c000000099ff0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T18:49:44.647 [RTP] [Mini-filter] Unsuccessful scan status(#370): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEDE9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #51371, FileId: 0x112000000004918, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T18:50:57.854 [RTP] [Mini-filter] Unsuccessful scan status(#380): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBE6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #51428, FileId: 0x1b00000009a022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T18:53:08.082 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T19:03:36.127 [RTP] [Mini-filter] Unsuccessful scan status(#390): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9DF9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #52178, FileId: 0x6d000000003124, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:08:13.080 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T19:11:06.183 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 23265, Count: 1632, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: httpd.exe, Pid: 3320, TotalTime: 5444, Count: 423, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: AcroCEF.exe, Pid: 7972, TotalTime: 4082, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 32% 2026-04-24T19:11:06.183 ProcessImageName: firefox.exe, Pid: 2016, TotalTime: 2687, Count: 234, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 68% 2026-04-24T19:11:06.183 ProcessImageName: xampp-control.exe, Pid: 11760, TotalTime: 1855, Count: 9, MaxTime: 1609, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-04-24T19:11:06.183 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6580, TotalTime: 1421, Count: 68, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\OneDrive.Sync.Service.dll, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: httpd.exe, Pid: 6844, TotalTime: 1130, Count: 86, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_107.php, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: mysqld.exe, Pid: 10900, TotalTime: 1006, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: notepad++.exe, Pid: 11088, TotalTime: 887, Count: 69, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: RuntimeBroker.exe, Pid: 8420, TotalTime: 759, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{50BC8D5E-75C5-4FA0-B0EF-7754EC2C1F1C}.json, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: WmiPrvSE.exe, Pid: 8948, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-04-24T19:11:06.183 ProcessImageName: Notepad.exe, Pid: 5912, TotalTime: 577, Count: 61, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_116.php, EstimatedImpact: 4% 2026-04-24T19:11:06.183 ProcessImageName: WmiPrvSE.exe, Pid: 4660, TotalTime: 465, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 18% 2026-04-24T19:11:06.183 ProcessImageName: firefox.exe, Pid: 8884, TotalTime: 435, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11880, EstimatedImpact: 55% 2026-04-24T19:11:06.183 ProcessImageName: httpd.exe, Pid: 3276, TotalTime: 347, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 22% 2026-04-24T19:11:06.183 ProcessImageName: svchost.exe, Pid: 3528, TotalTime: 330, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f315f70e8d62d6f0beb9cfb774a905c1de3a2acc\content.phf, EstimatedImpact: 1% 2026-04-24T19:11:06.183 ProcessImageName: AdobeCollabSync.exe, Pid: 2500, TotalTime: 270, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-24.log, EstimatedImpact: 0% 2026-04-24T19:11:06.183 ProcessImageName: PickerHost.exe, Pid: 7480, TotalTime: 243, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 10% 2026-04-24T19:11:06.183 ProcessImageName: PickerHost.exe, Pid: 6156, TotalTime: 242, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T19:11:06.183 ProcessImageName: PickerHost.exe, Pid: 10948, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.183 ProcessImageName: PickerHost.exe, Pid: 12992, TotalTime: 241, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 3% 2026-04-24T19:11:06.183 ProcessImageName: PickerHost.exe, Pid: 6840, TotalTime: 226, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 6), EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 6856, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 6), EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 8868, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 4016, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 5764, TotalTime: 226, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 5% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 218, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 58% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 11136, TotalTime: 211, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 4), EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 10808, TotalTime: 211, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 3)->[CMDEmbedded], EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 8508, TotalTime: 210, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 508, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 98% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 3064, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 4% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 12588, TotalTime: 196, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 92% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 9804, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 2972, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 7216, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 10776, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 7316, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 9300, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 7% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 1800, TotalTime: 195, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 9072, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms->(Ole Stream 0), EstimatedImpact: 76% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 2168, TotalTime: 195, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 73% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 1768, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 1236, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 3100, TotalTime: 180, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 84% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 12688, TotalTime: 180, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 84% 2026-04-24T19:11:06.184 ProcessImageName: TabTip.exe, Pid: 11788, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 92% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 824, TotalTime: 166, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 70% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 2780, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 3664, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 11604, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 12756, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 1304, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 7348, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: PickerHost.exe, Pid: 7728, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms, EstimatedImpact: 75% 2026-04-24T19:11:06.184 ProcessImageName: dasHost.exe, Pid: 5364, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: Acrobat.exe, Pid: 6812, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini->(UTF-16LE), EstimatedImpact: 9% 2026-04-24T19:11:06.184 ProcessImageName: SDXHelper.exe, Pid: 3336, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\38BF1800-BDE9-4AE7-8088-DA1D2693012D, EstimatedImpact: 8% 2026-04-24T19:11:06.184 ProcessImageName: backgroundTaskHost.exe, Pid: 3484, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 26% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: OneDriveLauncher.exe, Pid: 4124, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 6% 2026-04-24T19:11:06.184 ProcessImageName: OfficeClickToRun.exe, Pid: 7220, TotalTime: 91, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: FileCoAuth.exe, Pid: 13008, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 2032, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: SecurityHealthHost.exe, Pid: 3996, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 7% 2026-04-24T19:11:06.184 ProcessImageName: SDXHelper.exe, Pid: 3756, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 3736, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1459.log, EstimatedImpact: 3% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 2672, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 19% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 12096, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITF74D.tmp, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 6084, TotalTime: 61, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6D735938-3D0B-4044-8BAA-B44A204A3CD4, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: dllhost.exe, Pid: 2960, TotalTime: 60, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: AggregatorHost.exe, Pid: 5420, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: PhoneExperienceHost.exe, Pid: 2536, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 4312, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1651.log, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: AcroCEF.exe, Pid: 9600, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 29% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 5000, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1514.log, EstimatedImpact: 2% 2026-04-24T19:11:06.184 ProcessImageName: notepad++.exe, Pid: 12128, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\session.xml, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 3812, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4D3A901-91FD-444E-AB1C-252A715A2F8E, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 7380, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-2001.log, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: SDXHelper.exe, Pid: 8756, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-24T19:11:06.184 ProcessImageName: Acrobat.exe, Pid: 12880, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro81920.dat, EstimatedImpact: 3% 2026-04-24T19:11:06.184 ProcessImageName: AdobeARM.exe, Pid: 8064, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 6% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 8000, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1948.log, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: AcroCEF.exe, Pid: 2972, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\obs-studio-hook\obs-vulkan64.json, EstimatedImpact: 26% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 13032, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1942.log, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 12440, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1603.log, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: pingsender.exe, Pid: 7740, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\b9aaed57-fcae-4162-b808-137c6c693330, EstimatedImpact: 6% 2026-04-24T19:11:06.184 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 13076, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 7756, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1508.log, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: SDXHelper.exe, Pid: 1956, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-04-24T19:11:06.184 ProcessImageName: OfficeC2RClient.exe, Pid: 13040, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260424-1547.log, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: svchost.exe, Pid: 3696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-24T19:11:06.184 ProcessImageName: TeamViewer.exe, Pid: 3076, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 8% 2026-04-24T19:11:06.184 ProcessImageName: SDXHelper.exe, Pid: 12160, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 0% 2026-04-24T19:11:37.781 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\1C2F2786-1246-4091-8D76-EEA46BA7F0392398.1dcd41e2b6fa1c3 2026-04-24T19:11:37.962 Verifying engine and signature files (source: 0) ... 2026-04-24T19:11:37.962 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpengine.dll] due to PPL. 2026-04-24T19:11:37.962 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasbase.vdm] (file in cache) 2026-04-24T19:11:37.963 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-24T19:11:37.978 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasdlta.vdm] 2026-04-24T19:11:37.978 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpavbase.vdm] (file in cache) 2026-04-24T19:11:37.978 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-24T19:11:37.994 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpavdlta.vdm] 2026-04-24T19:11:38.156 [Engine] IsHybridMode: 0 2026-04-24T19:11:38.156 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-24T19:11:38.162 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-27883A770350754A30389F4E1465940350BF6103.bin): 0x00000002 2026-04-24T19:11:38.166 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-27883A770350754A30389F4E1465940350BF6103.bin) 2026-04-24T19:11:38.166 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-24T19:11:38.166 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-24T19:11:38.166 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-24T19:11:38.166 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-24T19:11:51.906 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-24T19:11:51.907 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-24T19:11:51.918 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFAA33E8020, lRefCount: 5, hr=0 2026-04-24T19:11:51.918 [Engine] New active engine 00007FFAB3868020 replacing engine 00007FFAA33E8020. Number of active engines: 2 2026-04-24T19:11:51.930 EngineInit:Global ASOC is enabled 2026-04-24T19:11:51.930 EngineInit:ASOO is enabled for developer volumes 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.005 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.006 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-24T19:11:52.020 MpWriteUupSignatureVersion 1.449.276.0, hr = 0 2026-04-24T19:11:52.022 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-24T19:11:52.041 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-24T19:11:52.042 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-24T19:11:52.042 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-24T19:11:52.042 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-24T19:11:52.042 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-24T19:11:52.063 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-24T19:11:52.063 [Plugin] Initializing RTP plugin state... 2026-04-24T19:11:52.063 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎24‎-‎2026 13:11:06 Last Perf:‎04‎-‎24‎-‎2026 13:11:06 First RTP Scan:‎04‎-‎24‎-‎2026 13:11:07 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1733 Misses:37497 BM Queue:0,366,0 Proc:0,159,0 File:0,257,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:52633 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:247050315 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:27681 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:128007 TotalHits:398391 InstanceCacheInserts:3014 InstanceCacheUpdates:0 InstanceCacheDeletes:576 InstanceCacheHits:249 InstanceCacheMisses:44073 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (3086/1315) Success: 1315, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-24T19:11:52.063 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-24T19:11:52.063 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A} 2026-04-24T19:11:52.065 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{CD09C483-78E4-40D2-9886-94F4D1C4C67D} removed 2026-04-24T19:11:52.065 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A}\mpasbase.vdm in use, hr=0x80070020 2026-04-24T19:11:52.065 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-24T19:11:52.067 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.067 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.067 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.067 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.067 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-24-2026 19:11:52 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-24-2026 19:11:52 2026-04-24T19:11:52.071 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-24T19:11:52.072 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-24T19:11:52.075 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T19:11:52.076 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-24T19:11:52.076 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-24T19:11:52.077 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.077 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.077 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.077 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-24T19:11:52.078 MdCoreSvc is supported in this platform and OS Signature updated on 04-24-2026 19:11:52 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.276.0 AV Signature Version: 1.449.276.0 ************************************************************ 2026-04-24T19:11:52.081 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-24T19:11:52.081 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\1C2F2786-1246-4091-8D76-EEA46BA7F0392398.1dcd41e2b6fa1c3 2026-04-24T19:11:52.110 Process scan (postsignatureupdatescan) started. 2026-04-24T19:11:52.216 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-24T19:11:52.218 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-24T19:11:52.570 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-24T19:11:52.570 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-24T19:11:52.571 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-24T19:11:52.880 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-24T19:11:52.880 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-24T19:11:52.881 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-24T19:11:52.881 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-24T19:11:52.881 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-24T19:11:52.885 [Engine] Engine 00007FFAA33E8020 no longer in use. Number of active engines: 1 2026-04-24T19:11:52.885 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-24T19:11:52.885 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-24T19:11:53.233 ProcessImageName: explorer.exe, Pid: 9516, TotalTime: 23265, Count: 1632, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: httpd.exe, Pid: 3320, TotalTime: 5444, Count: 423, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index.php, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: AcroCEF.exe, Pid: 7972, TotalTime: 4082, Count: 175, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 32% 2026-04-24T19:11:53.233 ProcessImageName: firefox.exe, Pid: 2016, TotalTime: 2687, Count: 234, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 68% 2026-04-24T19:11:53.233 ProcessImageName: xampp-control.exe, Pid: 11760, TotalTime: 1855, Count: 9, MaxTime: 1609, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-04-24T19:11:53.233 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6580, TotalTime: 1421, Count: 68, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0001\OneDrive.Sync.Service.dll, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: httpd.exe, Pid: 6844, TotalTime: 1130, Count: 86, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_107.php, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: mysqld.exe, Pid: 10900, TotalTime: 1006, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: notepad++.exe, Pid: 11088, TotalTime: 887, Count: 69, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: RuntimeBroker.exe, Pid: 8420, TotalTime: 759, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{50BC8D5E-75C5-4FA0-B0EF-7754EC2C1F1C}.json, EstimatedImpact: 0% 2026-04-24T19:11:53.233 ProcessImageName: WmiPrvSE.exe, Pid: 8948, TotalTime: 647, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-04-24T19:11:53.233 ProcessImageName: Notepad.exe, Pid: 5912, TotalTime: 577, Count: 61, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\Webftp\fileflowweb\index_116.php, EstimatedImpact: 4% 2026-04-24T19:11:53.233 ProcessImageName: WmiPrvSE.exe, Pid: 4660, TotalTime: 465, Count: 64, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 18% 2026-04-24T19:11:53.233 ProcessImageName: firefox.exe, Pid: 8884, TotalTime: 435, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11880, EstimatedImpact: 55% 2026-04-24T19:11:53.313 [Engine] RSIG_UNLOADENGINE, 00007FFAA33E8020, err=0x0 2026-04-24T19:11:53.329 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EF2AA410-7A43-4992-B126-67B5AB50BE1A} removed 2026-04-24T19:11:54.094 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T19:11:54.100 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-24T19:11:54.102 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-24T19:12:18.311 Process scan (postsignatureupdatescan) completed. 2026-04-24T19:16:51.973 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-24T19:21:07.453 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #52908, FileId: 0x14000000099fc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:23:18.081 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T19:26:41.581 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC1E9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53270, FileId: 0x4c000000049982, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:26:49.007 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDED9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53274, FileId: 0x78000000004b58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:26:51.928 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEA63.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53276, FileId: 0x7a000000004b58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:26:54.247 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF36C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53280, FileId: 0x4d00000003dff7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:26:57.786 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php139.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53284, FileId: 0x13f0000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:26:59.092 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php65A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53288, FileId: 0x5000000003dff7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:00.307 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB1E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53292, FileId: 0x1420000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:01.730 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php10AD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53296, FileId: 0x7f000000004b58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:03.608 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1801.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53300, FileId: 0x1450000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:05.339 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1EC8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53305, FileId: 0x82000000004b58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:06.943 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php24F3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53309, FileId: 0x5500000003dff7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:09.827 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php304E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53313, FileId: 0x1490000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:11.081 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3522.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53319, FileId: 0x150000000b5f0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:12.394 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3A63.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53323, FileId: 0x14c0000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:14.373 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4224.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53327, FileId: 0x180000000b5f0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:27:15.553 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php46B9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53331, FileId: 0x14f0000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:07.613 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFC69.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53421, FileId: 0xc0000000b7782, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:16.849 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php209B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53427, FileId: 0x160000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:23.908 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3C14.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53434, FileId: 0x370000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:25.946 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4404.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53438, FileId: 0x1d000000097f44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:27.467 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A00.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53442, FileId: 0x6200000003a801, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:28.516 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4E28.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53446, FileId: 0x20000000097f44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:33.524 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php61C4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53458, FileId: 0x6900000003a801, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:34.730 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6659.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53462, FileId: 0x27000000097f44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:36.689 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6E1A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53466, FileId: 0x6b00000003a801, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:38.536 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7540.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53470, FileId: 0x410000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:39.953 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7ACE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53474, FileId: 0x6e00000003a801, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:41.512 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php80EA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53478, FileId: 0x440000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:53.482 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAFAC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53482, FileId: 0x7100000003a801, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:29:57.180 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBE33.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53486, FileId: 0x3d000000099fbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:01.113 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCD77.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53490, FileId: 0x480000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:07.947 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE833.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53496, FileId: 0x190000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:17.370 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCF3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53501, FileId: 0x130000000b7cb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:19.827 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1698.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53534, FileId: 0x4c0000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:21.206 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1C08.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53538, FileId: 0x160000000b7cb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:22.493 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php20FB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53542, FileId: 0x4f0000000354c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:23.804 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php261C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53546, FileId: 0x1e0000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:44.481 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php76FC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53555, FileId: 0x17000000099fa5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:48.251 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php85B3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53560, FileId: 0x210000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:50.101 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8CF7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53565, FileId: 0x1e0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:52.913 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php97D6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53569, FileId: 0x1b000000099fa5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:55.064 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA043.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53573, FileId: 0x250000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:30:57.313 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA90E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53578, FileId: 0x220000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:00.597 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB5F0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53583, FileId: 0x1f000000099fa5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:02.184 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBC2A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53588, FileId: 0x290000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:05.932 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCAD1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53592, FileId: 0x260000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:07.639 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD17A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53597, FileId: 0x23000000099fa5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:10.055 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDAD1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53601, FileId: 0x2d0000000b78c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:12.239 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE36D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53608, FileId: 0x2a0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:31:14.159 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEAF0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53612, FileId: 0x1540000000046c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:38:23.069 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-24T19:45:02.783 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8FA3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53756, FileId: 0x140000000bbea7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:06.621 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9EA8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53760, FileId: 0x160000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:12.958 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB770.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53766, FileId: 0x120000000bd603, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:16.114 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC3D5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53770, FileId: 0x310000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:19.757 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD1FF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53789, FileId: 0x1a0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:24.639 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE52B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53794, FileId: 0x9a000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:27.330 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEFAB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53799, FileId: 0x350000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:30.324 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpFB64.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53806, FileId: 0x1e0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:32.683 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php49C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53810, FileId: 0x9e000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:34.273 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAB8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53814, FileId: 0x210000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:37.540 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php177B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53819, FileId: 0x230000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:39.065 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1D77.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53824, FileId: 0xa1000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:41.210 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php25F4.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53829, FileId: 0x3c0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:43.394 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2E71.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53834, FileId: 0x270000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:45.149 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3538.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53838, FileId: 0xa5000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:47.485 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3E61.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53842, FileId: 0x400000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:52.309 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php513E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53847, FileId: 0x2b0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:45:53.918 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5779.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53852, FileId: 0xa9000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:00.106 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6FB5.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53856, FileId: 0x440000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:12.303 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9F51.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53861, FileId: 0x2f0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:15.856 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAD3D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53866, FileId: 0xad000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:18.389 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB721.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53872, FileId: 0x480000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:25.155 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD190.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53876, FileId: 0x330000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:26.524 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD6E0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53880, FileId: 0x4b0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:29.470 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE27A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53884, FileId: 0x360000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:33.630 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF2A7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53888, FileId: 0x4e0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:41.177 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1033.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53896, FileId: 0x3a0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:43.441 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php18FE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53901, FileId: 0x520000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:45.570 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php215B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53905, FileId: 0xb6000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:47.080 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2738.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53909, FileId: 0x3d0000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:46:49.643 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php314C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53913, FileId: 0x570000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:47:03.042 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php659B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53918, FileId: 0xba000000003926, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:47:06.829 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7461.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53923, FileId: 0x410000000bbe52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-24T19:47:09.086 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7D2C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #53928, FileId: 0x5b0000000b5e62, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-26-2026 08:10:51 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/26/2026 08:10:51.917671400 UTC (17625 ms since boot) 2026-04-26T08:10:51.937 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-26T08:10:51.942 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:10:51.942 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:10:51.977 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260426-081051-00000003-fffffffeffffffff.bin ... 2026-04-26T08:10:52.073 [WPP] Trace session started - MpWppTracing-20260426-081051-00000003-fffffffeffffffff.bin 2026-04-26T08:10:52.073 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-26T08:10:52.073 [RbM] Rollback manager succesfully initialized. 2026-04-26T08:10:52.073 [RbM] Rollback manager EnableRollbackManager called. 2026-04-26T08:10:52.082 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-26T08:10:52.082 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-26T08:10:52.082 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-26T08:10:52.082 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-26T08:10:52.082 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-26T08:10:52.087 MdCoreSvc is supported in this platform and OS 2026-04-26T08:10:52.087 MdCoreSvc is supported in this platform and OS 2026-04-26T08:10:52.087 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-26T08:10:52.089 [PlatUpd] Starting MdCoreSvc service 2026-04-26T08:10:52.142 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-26T08:10:55.896 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-26T08:10:55.896 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-26T08:10:55.896 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-26T08:10:55.896 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-26T08:10:55.896 [PlatUpd] CSP platform update started 2026-04-26T08:10:55.896 [PlatUpd] Defender MDM CSP platform update not required 2026-04-26T08:10:55.896 [PlatUpd] WMI/PS provider platform update started 2026-04-26T08:10:55.896 [PlatUpd] WMI/PS provider platform update not required 2026-04-26T08:10:55.896 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-26T08:10:55.896 MdCoreSvc is supported in this platform and OS 2026-04-26T08:10:55.896 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-26T08:10:55.896 [PlatUpd] Starting MdCoreSvc service 2026-04-26T08:10:55.896 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-26T08:10:55.896 [TS] Troublshooting mode is not available! 2026-04-26T08:10:55.896 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-26T08:10:55.896 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-26T08:10:55.927 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-26T08:10:55.927 [Service] Enabling AutoLoggers ... 2026-04-26T08:10:55.927 [Service] Enabling AMSI registration ... 2026-04-26T08:10:55.927 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-26T08:10:55.943 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52914 Number of invalid entries is 0 Number of inserts issued is 1575781 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6454 Number of lookups is 107488779 Number of lookup misses is 5156997 Number of fast lookup misses is 54780467 Number of false fast lookups is 5156992 Number of invalidations is 731145 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-26T08:10:55.943 Verifying license file... 2026-04-26T08:10:55.943 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-26T08:10:55.959 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-26T08:10:55.959 Loaded module#0 MpComServer. 2026-04-26T08:10:55.959 Loaded module#1 StartupPolicies. 2026-04-26T08:10:55.959 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-26T08:10:55.959 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-26T08:10:55.959 COM server initialized successfully. 2026-04-26T08:10:55.974 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-26T08:10:55.974 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-26T08:10:55.974 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-26T08:10:55.990 [RTP] [RTP] FilterCommunicator object 0x000001C788895430 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-26T08:10:55.990 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-26T08:10:55.990 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-26T08:10:55.990 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-26T08:10:55.990 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-26T08:10:55.990 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-26T08:10:55.990 [RTP] [RTP] FilterCommunicator object 0x000001C788895640 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-26T08:10:55.990 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-26T08:10:55.990 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-26T08:10:55.990 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-26T08:10:55.990 [RTP] [RTP] StartCommunication 0x000001C788895430 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-26T08:10:55.990 [init][RTP] RTPPlugin initialization completed 2026-04-26T08:10:55.990 OS boot count = 2 2026-04-26T08:10:55.990 OS Install = 0 2026-04-26T08:10:56.006 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-26T08:10:56.006 [KSL] Entering CKSLEngine::Initialize. 2026-04-26T08:10:56.006 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-26T08:10:56.006 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-26T08:10:56.006 [KSL] MpInstallKslD: hr=0x1 2026-04-26T08:10:56.006 [KSL] MpRegisterKslD: hr=0 2026-04-26T08:10:56.021 [KSL] MpStartKslD: hr=0 2026-04-26T08:10:56.021 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-26T08:10:56.021 Loading engine... 2026-04-26T08:10:56.021 Verifying engine and signature files (source: 1) ... 2026-04-26T08:10:56.021 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpengine.dll] due to PPL. 2026-04-26T08:10:56.021 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasbase.vdm] (file in cache) 2026-04-26T08:10:56.021 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasdlta.vdm] (file in cache) 2026-04-26T08:10:56.021 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpavbase.vdm] (file in cache) 2026-04-26T08:10:56.021 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpavdlta.vdm] (file in cache) 2026-04-26T08:10:56.068 [Engine] IsHybridMode: 0 2026-04-26T08:10:56.068 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-26T08:10:56.099 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-27883A770350754A30389F4E1465940350BF6103.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-26T08:11:02.912 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-26T08:11:02.912 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_NISDrv_Cleanup new=0 old1 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-26T08:11:02.912 [Engine] New active engine 00007FFF95ED8020 (no old engine). Number of active engines: 1 2026-04-26T08:11:02.927 EngineInit:Global ASOC is enabled 2026-04-26T08:11:02.927 EngineInit:ASOO is enabled for developer volumes 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:03.006 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fa9481a13ec7b6099acf14f90e4da0d1ee6acbdd Dynamic Signature Compilation Timestamp:04-15-2026 11:56:59 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.006 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8826eda23b0f48cfc32bb620e47e4733a6423836 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:00 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.006 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c93c2ae501fc6252008717ab83a1d40433ebfe9b Dynamic Signature Compilation Timestamp:04-15-2026 11:57:00 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d2e2815347d307f7a9da54cdc6a3a2feb58e7be2 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:00 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aa3474a83e445699b35999fee9301dd7c8cda493 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:00 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\008e111078fc675595eac9f211a9c4acfce4262d Dynamic Signature Compilation Timestamp:04-15-2026 11:57:00 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\68a8395f16cbcfa0ec1510008ebf5ec7d9644446 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:01 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7c1558745e9741ec641b00eab5a3cafa77697c33 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:01 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99ce11a2948b75c4dc18ab5a57a005e4dd9c67aa Dynamic Signature Compilation Timestamp:04-15-2026 11:57:01 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8bf18cacc592d47852e3d164e8155a1ff3cd2f4f Dynamic Signature Compilation Timestamp:04-15-2026 11:57:02 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0e0c61b900c0914e739c82071a3dca1c4212b60f Dynamic Signature Compilation Timestamp:04-15-2026 11:57:02 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fafa8b09774de23c524749a8fc155e7c97d4811f Dynamic Signature Compilation Timestamp:04-15-2026 11:57:02 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\03f7a6b68c15fdd5b15f08daf0ffd6553122454c Dynamic Signature Compilation Timestamp:04-15-2026 11:57:02 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\801924acb0454b71e0c573da51a65accb2163728 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:03 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\702f3993c4ab3246750163c3f42c0dd483b56d7d Dynamic Signature Compilation Timestamp:04-15-2026 11:57:03 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f3298de14b5e37b6c54e49b1b426332d37cf1eb7 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:03 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\906e23818f7319a007d38877829ff869d150f2cd Dynamic Signature Compilation Timestamp:04-15-2026 11:57:04 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aeda59d34805a51bc32094342fad55ad90c4c945 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:04 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\47ca6c6cac689dc092cb5e1ce922e108b459126e Dynamic Signature Compilation Timestamp:04-15-2026 11:57:04 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\272fd2e439c42b61bb925379415c74dd0967fff0 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:04 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1bb42ba50b15c399fe9aa42d70e06d23fcd11b9 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:05 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f0a496dd5d4fe8535c6748795be22c8ecdfddc66 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:05 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dbab0dfa51062d4586abd7784341c8960dab59d1 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:05 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b477bd85626b5071d3e683c7564a54e618563e06 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:06 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\caeb884705e865208a3cc6aba00040d1b8de568b Dynamic Signature Compilation Timestamp:04-15-2026 11:57:06 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae5ef0121eec49f93b2c0c3b52a047e51dbaab13 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:06 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9280daca9ae94b10b85c95a7dca9370e5e987776 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:07 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\44df5e537be3d00d5af9f1360800a675b9bf1e75 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:07 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1483c8f3595d7997372e71f78906ff339d6b41c1 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:07 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ab4457c9d0ee18746fc34e05b761800d65b607e0 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:08 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5b5388c70ba8ff9f1fc9f60682533e0b6d26f613 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:08 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\432405fe12c85786a0d1d0fd34fb180b7addfdc7 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:09 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82e38a532108490408b3986f7041137396b7b787 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:09 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6ca6dc0629cce45c7bc79ac245365d5f136af4d2 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:09 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\737a1685ad61a4f31691f70d489bbed72c9e9ad6 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:10 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.021 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8fbb5cc3ae5a4cb001b1816d5e2f69bfff332ace Dynamic Signature Compilation Timestamp:04-15-2026 11:57:10 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bbf6313901c2c39e80f96da1f1665a245227ecee Dynamic Signature Compilation Timestamp:04-15-2026 11:57:10 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6efd45651d5d6896d5bc54f1bdfcfbe209899b5a Dynamic Signature Compilation Timestamp:04-15-2026 11:57:10 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1002a79c52a35e4db0109e6b9f068f7e87097c3f Dynamic Signature Compilation Timestamp:04-15-2026 11:57:11 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bf6aa4585113099b7b4357a6c94acd8075fbf599 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:11 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2f0a47df843290a59ef7ac6686452abf60bb0cce Dynamic Signature Compilation Timestamp:04-15-2026 11:57:11 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\508cf875eaf8d3a59f3e3bf18dae8a11782b89b1 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:11 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b83aadce07049806ce2ef7f00a4c7a9c9445e362 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:12 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14d67bf80763d7ffbbaf8ce0e15dd268b4f443de Dynamic Signature Compilation Timestamp:04-15-2026 11:57:12 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.037 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b01760c0d90f93bbafe6b58d88998bcf9ca09a71 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:12 Persistence Type:Duration Time remaining:50065408 2026-04-26T08:11:03.052 MpWriteUupSignatureVersion 1.449.276.0, hr = 0 2026-04-26T08:11:03.052 [SigStatUpd] CSignatureStatus: back to good 2026-04-26T08:11:03.052 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-26T08:11:03.084 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-26T08:11:03.084 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:11:03.084 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-26T08:11:03.084 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-26T08:11:03.084 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-26T08:11:03.084 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-26T08:11:03.084 [Plugin] Initializing RTP plugin state... 2026-04-26T08:11:03.084 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2389 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13375 TotalHits:0 InstanceCacheInserts:16 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2721 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-26T08:11:03.084 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-26T08:11:03.099 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A} 2026-04-26T08:11:03.099 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:03.099 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:03.099 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:03.099 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:03.099 MdCoreSvc is supported in this platform and OS 2026-04-26T08:11:03.099 Engine loaded! 2026-04-26T08:11:03.099 [DLP] Create FeatureControlState instance 2026-04-26T08:11:03.099 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-26T08:11:03.099 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-26T08:11:03.099 RegisterSModeChangeListener: hr = 0x1 2026-04-26T08:11:03.099 RegisterHybridModeChangeListener: hr = 0 2026-04-26T08:11:03.115 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-26T08:11:03.115 [SigReleaseHb] Initialized with Stage 0 2026-04-26T08:11:03.115 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-26T08:11:03.115 [SCC][CID=28828_5524] Initializing ... 2026-04-26T08:11:03.115 [SCC][CID=28828_5524] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-26T08:11:03.115 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-26T08:11:03.115 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-26T08:11:03.115 [NRI] Stopping NIS service ... 2026-04-26T08:11:03.115 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-26T08:11:03.115 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). 2026-04-26T08:11:03.131 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.276.0 AV Signature Version: 1.449.276.0 ************************************************************ 2026-04-26T08:11:03.131 Resource usage Monitoring is enabled 2026-04-26T08:11:03.131 Job Notification: New process added to job (4768) 2026-04-26T08:11:03.131 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-26T08:11:03.193 Job Notification: New process added to job (7664) 2026-04-26T08:11:03.193 Job Notification: New process added to job (7672) 2026-04-26T08:11:03.193 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7664] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7672]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-26T08:11:03.209 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-26T08:11:03.209 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-26T08:11:03.209 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-26T08:11:03.209 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-26T08:11:03.209 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-26T08:11:03.209 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-26T08:11:03.209 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-26T08:11:03.224 [RTP] Generating the base plugin configuration ... 2026-04-26T08:11:03.224 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-26T08:11:03.224 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:11:03.224 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-26T08:11:03.224 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-26T08:11:03.224 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:11:03.224 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-26T08:11:03.224 [RTP] [RTP] StartCommunication 0x000001C788895640 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-26T08:11:03.224 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-26T08:11:03.224 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-26T08:11:03.302 Job Notification: Process exited from job (7664) 2026-04-26T08:11:03.318 Job Notification: Process exited from job (7672) 2026-04-26T08:11:03.318 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-26T08:11:03.552 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:03.568 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-26T08:11:03.568 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-26T08:11:03.568 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-26T08:11:03.974 [AutoPurge] Verification Routine tasks have started. 2026-04-26T08:11:03.974 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-26T08:11:04.209 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-26T08:11:04.209 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-26T08:11:04.240 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-26T08:11:04.568 Job Notification: New process added to job (7876) 2026-04-26T08:11:04.568 Task(GetDeviceTicket -AccessKey D0F46B25-FD81-CDF6-93E3-27936C09ACF7 ) launched as network service 2026-04-26T08:11:04.943 Job Notification: Process exited from job (7876) 2026-04-26T08:11:05.006 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-26T08:11:05.006 [Cloud] Start of cloud request. Passive mode: 0 2026-04-26T08:11:05.006 [Cloud] Queued cloud request. 2026-04-26T08:11:05.006 [Cloud] Dequeued cloud request. 2026-04-26T08:11:05.006 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-26T08:11:05.240 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-26T08:11:05.240 [AutoPurge] Verification Routine tasks have ended. 2026-04-26T08:11:05.287 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-26T08:11:05.302 [Cloud] End of cloud request. 2026-04-26T08:11:05.459 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-26T08:11:05.474 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:05.474 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-26T08:11:05.474 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-26T08:11:05.474 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-26T08:11:05.474 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-26T08:11:05.474 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-26T08:11:05.474 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-26T08:11:05.474 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-26T08:11:05.490 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:05.490 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:05.490 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:06.131 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:11:06.131 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:11:06.131 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-04-26T08:11:06.131 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:11:06.131 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-26T08:11:06.131 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-04-26T08:11:17.693 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\4D4CF0CE-347E-44D1-B7C4-6B6FBCE3F0141cc8.1dcd554410060e9 2026-04-26T08:11:17.787 Verifying engine and signature files (source: 0) ... 2026-04-26T08:11:17.787 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll] due to PPL. 2026-04-26T08:11:17.787 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasbase.vdm] (file in cache) 2026-04-26T08:11:17.787 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-26T08:11:17.803 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasdlta.vdm] 2026-04-26T08:11:17.803 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavbase.vdm] (file in cache) 2026-04-26T08:11:17.803 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-26T08:11:17.818 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavdlta.vdm] 2026-04-26T08:11:17.959 [Engine] IsHybridMode: 0 2026-04-26T08:11:17.959 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-26T08:11:17.974 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-70313110BCCF211D6857DBB8386082EDF910919C.bin): 0x00000002 2026-04-26T08:11:17.974 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-70313110BCCF211D6857DBB8386082EDF910919C.bin) 2026-04-26T08:11:17.974 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-26T08:11:17.974 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-26T08:11:17.974 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-26T08:11:17.974 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-26T08:11:29.678 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-26T08:11:29.678 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-26T08:11:29.693 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFF95ED8020, lRefCount: 6, hr=0 2026-04-26T08:11:29.693 [Engine] New active engine 00007FFF90F38020 replacing engine 00007FFF95ED8020. Number of active engines: 2 2026-04-26T08:11:29.709 EngineInit:Global ASOC is enabled 2026-04-26T08:11:29.709 EngineInit:ASOO is enabled for developer volumes 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.771 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:11:29.787 MpWriteUupSignatureVersion 1.449.304.0, hr = 0 2026-04-26T08:11:29.787 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-26T08:11:29.803 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-26T08:11:29.803 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:11:29.803 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-26T08:11:29.803 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-26T08:11:29.803 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-26T08:11:29.818 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-26T08:11:29.818 [Plugin] Initializing RTP plugin state... 2026-04-26T08:11:29.818 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎26‎-‎2026 10:11:03 Last Perf:‎04‎-‎26‎-‎2026 10:11:03 First RTP Scan:‎04‎-‎26‎-‎2026 10:11:03 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:260 Misses:524 BM Queue:0,14,0 Proc:0,14,0 File:0,4,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:809 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:693818 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2641 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:15232 TotalHits:939 InstanceCacheInserts:16 InstanceCacheUpdates:0 InstanceCacheDeletes:16 InstanceCacheHits:0 InstanceCacheMisses:3003 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (30/8) Success: 8, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-26T08:11:29.818 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-26T08:11:29.818 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20} 2026-04-26T08:11:29.818 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-26T08:11:29.818 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{49E6DB23-137A-4165-8543-3C27520FD50D} removed 2026-04-26T08:11:29.818 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{609A0720-4D71-4341-9E06-88E05DEAC29A}\mpasbase.vdm in use, hr=0x80070020 2026-04-26T08:11:29.818 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.818 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.818 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.818 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.818 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-26-2026 08:11:29 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-26-2026 08:11:29 2026-04-26T08:11:29.834 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-26T08:11:29.834 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-26T08:11:29.834 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:11:29.834 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-26T08:11:29.834 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:11:29.834 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.834 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.834 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.834 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-26T08:11:29.834 MdCoreSvc is supported in this platform and OS Signature updated on 04-26-2026 08:11:29 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.304.0 AV Signature Version: 1.449.304.0 ************************************************************ 2026-04-26T08:11:29.834 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-26T08:11:29.834 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\4D4CF0CE-347E-44D1-B7C4-6B6FBCE3F0141cc8.1dcd554410060e9 2026-04-26T08:11:29.928 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-26T08:11:29.928 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-26T08:11:30.240 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-26T08:11:30.240 [RTP] Setting EfsHardeningFlags to 1 (hr=0). -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-26-2026 08:17:39 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/26/2026 08:17:39.517421300 UTC (15234 ms since boot) 2026-04-26T08:17:39.531 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-26T08:17:39.531 WARNING: the previous service shutdown was not expected. 2026-04-26T08:17:39.536 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:17:39.536 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:17:39.616 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260426-081739-00000003-fffffffeffffffff.bin ... 2026-04-26T08:17:39.763 [WPP] Trace session started - MpWppTracing-20260426-081739-00000003-fffffffeffffffff.bin 2026-04-26T08:17:39.763 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-26T08:17:39.763 [RbM] Rollback manager succesfully initialized. 2026-04-26T08:17:39.763 [RbM] Rollback manager EnableRollbackManager called. 2026-04-26T08:17:39.778 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-26T08:17:39.778 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-26T08:17:39.778 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-26T08:17:39.778 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-26T08:17:39.778 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-26T08:17:39.778 MdCoreSvc is supported in this platform and OS 2026-04-26T08:17:39.778 MdCoreSvc is supported in this platform and OS 2026-04-26T08:17:39.778 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-26T08:17:39.778 [PlatUpd] Starting MdCoreSvc service 2026-04-26T08:17:39.841 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-26T08:17:43.684 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-26T08:17:43.684 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-26T08:17:43.684 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-26T08:17:43.684 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-26T08:17:43.684 [PlatUpd] CSP platform update started 2026-04-26T08:17:43.684 [PlatUpd] Defender MDM CSP platform update not required 2026-04-26T08:17:43.684 [PlatUpd] WMI/PS provider platform update started 2026-04-26T08:17:43.684 [PlatUpd] WMI/PS provider platform update not required 2026-04-26T08:17:43.684 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-26T08:17:43.684 MdCoreSvc is supported in this platform and OS 2026-04-26T08:17:43.684 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-26T08:17:43.684 [PlatUpd] Starting MdCoreSvc service 2026-04-26T08:17:43.684 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-26T08:17:43.684 [TS] Troublshooting mode is not available! 2026-04-26T08:17:43.684 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-26T08:17:43.700 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-26T08:17:43.716 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-26T08:17:43.716 [Service] Enabling AutoLoggers ... 2026-04-26T08:17:43.716 [Service] Enabling AMSI registration ... 2026-04-26T08:17:43.716 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-26T08:17:43.731 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 52914 Number of invalid entries is 0 Number of inserts issued is 1575781 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6454 Number of lookups is 107488779 Number of lookup misses is 5156997 Number of fast lookup misses is 54780467 Number of false fast lookups is 5156992 Number of invalidations is 731145 Number of maintenance invalidations is 508705 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-26T08:17:43.731 Verifying license file... 2026-04-26T08:17:43.731 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll]. File not in cache (0x1) 2026-04-26T08:17:43.762 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] 2026-04-26T08:17:43.778 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-26T08:17:43.778 Loaded module#0 MpComServer. 2026-04-26T08:17:43.778 Loaded module#1 StartupPolicies. 2026-04-26T08:17:43.778 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-26T08:17:43.778 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-26T08:17:43.778 COM server initialized successfully. 2026-04-26T08:17:43.794 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-26T08:17:43.794 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-26T08:17:43.794 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-26T08:17:43.809 [RTP] [RTP] FilterCommunicator object 0x000002362490C5D0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-26T08:17:43.809 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-26T08:17:43.809 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-26T08:17:43.809 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-26T08:17:43.809 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-26T08:17:43.809 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-26T08:17:43.809 [RTP] [RTP] FilterCommunicator object 0x000002362490C7E0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-26T08:17:43.809 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-26T08:17:43.809 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-26T08:17:43.825 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-26T08:17:43.825 [RTP] [RTP] StartCommunication 0x000002362490C5D0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-26T08:17:43.825 [init][RTP] RTPPlugin initialization completed 2026-04-26T08:17:43.825 OS boot count = 2 2026-04-26T08:17:43.825 OS Install = 0 2026-04-26T08:17:43.841 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-26T08:17:43.841 [KSL] Entering CKSLEngine::Initialize. 2026-04-26T08:17:43.841 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-26T08:17:43.841 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-26T08:17:43.841 [KSL] MpInstallKslD: hr=0x1 2026-04-26T08:17:43.841 [KSL] MpRegisterKslD: hr=0 2026-04-26T08:17:43.841 [KSL] MpStartKslD: hr=0 2026-04-26T08:17:43.841 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-26T08:17:43.841 Loading engine... 2026-04-26T08:17:43.856 Verifying engine and signature files (source: 1) ... 2026-04-26T08:17:43.856 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll] due to PPL. 2026-04-26T08:17:43.856 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasbase.vdm]. File not in cache (0x1) 2026-04-26T08:17:44.809 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasbase.vdm] 2026-04-26T08:17:44.809 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpasdlta.vdm] (file in cache) 2026-04-26T08:17:44.809 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavbase.vdm]. File not in cache (0x1) 2026-04-26T08:17:45.231 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavbase.vdm] 2026-04-26T08:17:45.231 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-26T08:17:45.262 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpavdlta.vdm] 2026-04-26T08:17:45.309 [Engine] IsHybridMode: 0 2026-04-26T08:17:45.309 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-26T08:17:45.325 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-70313110BCCF211D6857DBB8386082EDF910919C.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-26T08:17:51.497 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-26T08:17:51.497 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-26T08:17:51.497 [Engine] New active engine 00007FFB0EEC8020 (no old engine). Number of active engines: 1 2026-04-26T08:17:51.512 EngineInit:Global ASOC is enabled 2026-04-26T08:17:51.512 EngineInit:ASOO is enabled for developer volumes 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.591 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T08:17:51.622 MpWriteUupSignatureVersion 1.449.304.0, hr = 0 2026-04-26T08:17:51.622 [SigStatUpd] CSignatureStatus: back to good 2026-04-26T08:17:51.622 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-26T08:17:51.637 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-26T08:17:51.637 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T08:17:51.637 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-26T08:17:51.637 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-26T08:17:51.637 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-26T08:17:51.653 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-26T08:17:51.653 [Plugin] Initializing RTP plugin state... 2026-04-26T08:17:51.653 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-26T08:17:51.653 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2090 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11820 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2357 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-26T08:17:51.653 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20} 2026-04-26T08:17:51.653 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:17:51.653 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:17:51.653 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-26T08:17:51.653 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-26T08:17:51.653 MdCoreSvc is supported in this platform and OS 2026-04-26T08:17:51.653 Engine loaded! 2026-04-26T08:17:51.653 [DLP] Create FeatureControlState instance 2026-04-26T08:17:51.653 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-26T08:17:51.653 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-26T08:17:51.653 RegisterSModeChangeListener: hr = 0x1 2026-04-26T08:17:51.653 RegisterHybridModeChangeListener: hr = 0 2026-04-26T08:17:51.669 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-26T08:17:51.669 [SigReleaseHb] Initialized with Stage 0 2026-04-26T08:17:51.669 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-26T08:17:51.669 [SCC][CID=27390_5320] Initializing ... 2026-04-26T08:17:51.669 [SCC][CID=27390_5320] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-26T08:17:51.669 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-26T08:17:51.669 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-26T08:17:51.669 [NRI] Stopping NIS service ... 2026-04-26T08:17:51.669 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-26T08:17:51.669 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.304.0 AV Signature Version: 1.449.304.0 ************************************************************ 2026-04-26T08:17:51.684 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-26T08:17:51.684 Resource usage Monitoring is enabled 2026-04-26T08:17:51.684 Job Notification: New process added to job (4596) 2026-04-26T08:17:51.684 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-26T08:17:51.700 Job Notification: New process added to job (4324) 2026-04-26T08:17:51.700 Job Notification: New process added to job (6436) 2026-04-26T08:17:51.700 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:4324] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6436]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-26T08:17:51.762 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-26T08:17:51.762 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-26T08:17:51.762 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-26T08:17:51.762 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-26T08:17:51.762 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-26T08:17:51.762 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-26T08:17:51.762 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-26T08:17:51.762 [RTP] Generating the base plugin configuration ... 2026-04-26T08:17:51.762 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-26T08:17:51.762 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:17:51.762 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-26T08:17:51.762 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-26T08:17:51.762 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:17:51.762 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-26T08:17:51.762 Job Notification: Process exited from job (4324) 2026-04-26T08:17:51.778 [RTP] [RTP] StartCommunication 0x000002362490C7E0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-26T08:17:51.778 Job Notification: Process exited from job (6436) 2026-04-26T08:17:51.778 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-26T08:17:51.778 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-26T08:17:51.778 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-26T08:17:52.137 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-26T08:17:52.137 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-26T08:17:52.137 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-26T08:17:52.153 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:17:54.731 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:17:54.731 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:17:54.731 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-26T08:17:54.731 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-26T08:17:54.731 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-26T08:18:43.763 Process scan (poststartupscan) started. 2026-04-26T08:18:43.763 Process scan (poststartupscan) completed. 2026-04-26T08:18:44.263 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-26T08:18:44.263 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-26T08:18:46.841 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:18:46.841 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:18:46.841 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-26T08:18:46.841 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-26T08:18:46.841 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-26T08:19:43.059 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:19:43.059 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-26T08:19:43.059 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:22:51.544 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-26T08:22:51.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T08:27:37.934 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-26T08:27:37.934 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-26T08:27:37.934 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-26T08:27:37.934 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-26T08:27:37.934 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-26T08:27:38.091 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:89B35D69-B6A4-48EE-AC87-D668C878E6D0, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-26T08:27:38.091 Scheduled scan with Id 89B35D69-B6A4-48EE-AC87-D668C878E6D0 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-26T08:27:38.091 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-26T08:27:38.091 [SFC] System file cache build is not needed (already completed) 2026-04-26T08:27:38.107 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-04-26T08:27:38.279 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-04-26T08:27:38.357 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-26T08:27:38.373 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:38.889 [AutoPurge] Cleanup Routine tasks have started. 2026-04-26T08:27:38.935 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-26T08:27:38.951 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-26T08:27:38.951 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-26-2026 08:27:38 2026-04-26T08:27:38.967 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-26-2026 08:27:38 2026-04-26T08:27:38.998 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-26T08:27:38.998 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-26T08:27:38.998 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-26T08:27:38.998 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-26T08:27:38.998 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-26T08:27:39.670 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-04-26T08:27:39.701 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-04-26T08:27:39.779 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-04-26T08:27:39.810 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-04-26T08:27:40.092 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:27:40.107 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-26T08:27:40.107 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:27:40.295 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-04-26T08:27:40.357 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-04-26T08:27:40.482 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-26T08:27:40.482 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-04-26T08:27:40.670 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-04-26T08:27:40.717 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-04-26T08:27:40.764 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-04-26T08:27:40.904 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-04-26T08:27:41.092 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-04-26T08:27:41.248 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-04-26T08:27:41.420 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-26T08:27:41.435 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:41.467 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-04-26T08:27:41.623 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-04-26T08:27:41.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-04-26T08:27:42.029 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-04-26T08:27:42.107 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #1562, FileId: 0xa900000000052e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-26T08:27:42.264 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-04-26T08:27:42.295 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-04-26T08:27:42.623 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-04-26T08:27:42.764 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-04-26T08:27:43.248 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:43.279 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-26T08:27:43.342 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:43.560 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-26T08:27:43.670 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-26T08:27:43.826 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-04-26T08:27:44.029 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-04-26T08:27:44.123 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-04-26T08:27:44.139 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-04-26T08:27:44.170 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-26T08:27:44.373 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-04-26T08:27:44.451 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-26T08:27:44.607 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-04-26T08:27:44.764 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-04-26T08:27:45.279 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-04-26T08:27:45.295 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-04-26T08:27:45.514 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-26T08:27:45.576 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-04-26T08:27:46.154 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-04-26T08:27:46.185 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-04-26T08:27:46.185 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-04-26T08:27:46.201 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-04-26T08:27:46.264 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-04-26T08:27:46.326 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-04-26T08:27:46.435 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-04-26T08:27:46.732 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\winsxs\amd64_networking-mpssvc-ui_31bf3856ad364e35_10.0.22000.653_none_73afee5687447108\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-04-26T08:27:46.842 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-04-26T08:27:46.935 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-04-26T08:27:46.951 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:46.998 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x00003540116FC1B3, sigsha=3d1f2522a4c0cef6ff74b2042442d26e99bfc20f, cached=false, source=0, resourceid=0x58275d12 Internal signature match:subtype=Lowfi, sigseq=0x0000E76133888793, sigsha=2d3d9c42af1fcd3fac10a31e884fccce7febe7aa, cached=false, source=0, resourceid=0x58275d12 Internal signature match:subtype=Lowfi, sigseq=0x00010461F177AC1C, sigsha=e9893c7ef2e241f0fb5ea2a72cdf8df5590f6dee, cached=false, source=0, resourceid=0x58275d12 2026-04-26T08:27:47.107 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-26T08:27:47.170 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-04-26T08:27:47.170 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-26T08:27:47.170 [Cloud] Start of cloud request. Passive mode: 0 2026-04-26T08:27:47.170 [Cloud] Queued cloud request. 2026-04-26T08:27:47.170 [Cloud] Dequeued cloud request. 2026-04-26T08:27:47.170 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-26T08:27:47.170 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-26T08:27:47.201 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-04-26T08:27:47.201 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-04-26T08:27:47.232 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Temp\cab_5252_4. Process: \Device\HarddiskVolume3\Windows\System32\makecab.exe, Status: 0xc0000001, State: 0, ScanRequest #1685, FileId: 0x5d0000000135c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-26T08:27:47.420 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-04-26T08:27:47.545 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-26T08:27:47.560 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1239f991c057a24c77e3aa3270c3895d2df97c7c Dynamic Signature Compilation Timestamp:04-26-2026 08:27:47 Persistence Type:Duration Time remaining:150196224 2026-04-26T08:27:47.576 Dynamic signature received 2026-04-26T08:27:47.576 RTSD:RTSD recieved, rescanning impacted resources 2026-04-26T08:27:47.576 [Cloud] End of cloud request. 2026-04-26T08:27:47.764 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-04-26T08:27:47.810 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-26T08:27:48.076 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-26T08:27:48.154 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-04-26T08:27:48.295 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-04-26T08:27:48.342 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-26T08:27:48.607 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-04-26T08:27:48.623 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-04-26T08:27:48.904 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-04-26T08:27:48.967 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-04-26T08:27:48.967 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-04-26T08:27:49.045 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-04-26T08:27:49.060 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-26T08:27:49.092 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-04-26T08:27:49.451 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-04-26T08:27:49.498 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-26T08:27:49.592 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-04-26T08:27:49.623 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-04-26T08:27:49.764 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-04-26T08:27:49.873 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-04-26T08:27:49.935 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-04-26T08:27:49.967 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-04-26T08:27:50.092 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-04-26T08:27:50.310 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:50.529 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-04-26T08:27:50.560 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-04-26T08:27:50.576 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:50.623 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:51.201 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:51.295 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:51.560 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-04-26T08:27:51.607 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-04-26T08:27:51.670 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-26T08:27:51.670 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-26T08:27:51.685 Job Notification: New process added to job (7012) 2026-04-26T08:27:51.701 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-26T08:27:51.701 Aggressive catchup quick scan threshold: 1788964528122 / 25920000000000 2026-04-26T08:27:51.701 Job Notification: New process added to job (8092) 2026-04-26T08:27:51.717 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7012] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8092]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-26T08:27:51.732 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-04-26T08:27:51.764 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 65047085(ms) from now at 04:31 (02:31 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-26T08:27:51.810 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-04-26T08:27:51.810 Job Notification: New process added to job (2308) 2026-04-26T08:27:51.826 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-26T08:27:51.826 Job Notification: New process added to job (1496) 2026-04-26T08:27:51.826 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:2308] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:1496]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-26T08:27:51.857 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-04-26T08:27:51.873 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-04-26T08:27:52.185 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-04-26T08:27:52.201 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-26T08:27:52.201 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:27:52.201 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:27:52.201 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-26T08:27:52.201 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:27:52.201 [RTP] No config change detected. Not updating plugin configuration. 2026-04-26T08:27:52.201 [RTP] No config changes found. No configuration switch. 2026-04-26T08:27:52.201 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-26T08:27:52.264 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-04-26T08:27:52.342 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-04-26T08:27:52.420 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-04-26T08:27:52.435 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-04-26T08:27:52.514 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-04-26T08:27:52.639 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-04-26T08:27:52.717 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-04-26T08:27:52.779 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-04-26T08:27:52.810 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-04-26T08:27:52.810 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-04-26T08:27:52.998 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-04-26T08:27:53.014 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-04-26T08:27:53.139 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-04-26T08:27:53.560 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-04-26T08:27:53.764 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-04-26T08:27:53.810 Engine:Setting original file name "stobject.dll" for "c:\windows\winsxs\amd64_microsoft-windows-stobject_31bf3856ad364e35_10.0.22000.708_none_45a5d433da92062e\stobject.dll.mun", hr=0x800710da 2026-04-26T08:27:54.154 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-04-26T08:27:54.201 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-04-26T08:27:54.248 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-04-26T08:27:54.310 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-04-26T08:27:54.404 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-26T08:27:54.404 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-26T08:27:54.545 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-04-26T08:27:54.732 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-04-26T08:27:54.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-04-26T08:27:55.014 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-04-26T08:27:55.279 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-04-26T08:27:55.373 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-26T08:27:55.482 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-04-26T08:27:55.764 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-04-26T08:27:55.842 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-04-26T08:27:55.889 Job Notification: Process exited from job (2308) 2026-04-26T08:27:55.889 Job Notification: Process exited from job (1496) 2026-04-26T08:27:55.920 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-04-26T08:27:55.951 Job Notification: Process exited from job (7012) 2026-04-26T08:27:55.951 Job Notification: Process exited from job (8092) 2026-04-26T08:27:56.045 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-04-26T08:27:56.060 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-26T08:27:56.154 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-04-26T08:27:56.201 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-04-26T08:27:56.342 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-04-26T08:27:56.420 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-04-26T08:27:56.420 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:56.639 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-04-26T08:27:56.873 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-04-26T08:27:56.920 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-04-26T08:27:56.951 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-26T08:27:57.045 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-04-26T08:27:57.264 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-04-26T08:27:57.310 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-26T08:27:57.342 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-04-26T08:27:57.435 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:27:57.873 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-04-26T08:27:57.982 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-04-26T08:27:58.045 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-04-26T08:27:58.389 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-04-26T08:27:58.404 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-04-26T08:27:58.420 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-04-26T08:27:58.670 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-04-26T08:27:58.873 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-04-26T08:27:58.889 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-04-26T08:27:59.014 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-04-26T08:27:59.139 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-04-26T08:27:59.154 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-04-26T08:27:59.342 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-04-26T08:27:59.467 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-04-26T08:27:59.482 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-04-26T08:27:59.560 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-26T08:27:59.873 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-04-26T08:27:59.920 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-04-26T08:27:59.935 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.139 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-04-26T08:28:00.545 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-04-26T08:28:00.639 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.717 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.842 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-04-26T08:28:00.935 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-26T08:28:01.045 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:01.139 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-04-26T08:28:01.279 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-04-26T08:28:01.357 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-26T08:28:01.576 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-04-26T08:28:01.779 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-04-26T08:28:01.795 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-04-26T08:28:01.889 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-04-26T08:28:02.451 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-04-26T08:28:02.857 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-04-26T08:28:02.889 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-26T08:28:02.951 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-04-26T08:28:03.451 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-04-26T08:28:03.826 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-04-26T08:28:03.873 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-04-26T08:28:04.029 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-04-26T08:28:04.232 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-04-26T08:28:04.264 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-04-26T08:28:04.514 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-04-26T08:28:04.576 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-04-26T08:28:04.623 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-04-26T08:28:04.654 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-04-26T08:28:04.748 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-04-26T08:28:05.045 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-04-26T08:28:05.107 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-04-26T08:28:05.326 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-04-26T08:28:05.373 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-04-26T08:28:05.857 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-26T08:28:06.092 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-04-26T08:28:06.217 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-04-26T08:28:06.389 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-04-26T08:28:06.467 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-04-26T08:28:06.482 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-04-26T08:28:06.498 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-04-26T08:28:06.529 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-04-26T08:28:06.623 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-04-26T08:28:06.685 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-04-26T08:28:06.732 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-04-26T08:28:06.826 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-04-26T08:28:06.842 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-04-26T08:28:06.857 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-04-26T08:28:06.889 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-04-26T08:28:06.889 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-04-26T08:28:07.107 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-26T08:28:07.107 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-26T08:28:07.139 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-04-26T08:28:07.217 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-04-26T08:28:07.326 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-04-26T08:28:07.592 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-04-26T08:28:07.795 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-04-26T08:28:08.014 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-04-26T08:28:08.185 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-04-26T08:28:08.248 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-04-26T08:28:08.373 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-04-26T08:28:08.592 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-04-26T08:28:08.639 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-04-26T08:28:08.795 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-04-26T08:28:08.857 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-04-26T08:28:09.060 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-04-26T08:28:09.139 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-04-26T08:28:09.185 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-04-26T08:28:09.232 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-04-26T08:28:09.248 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-04-26T08:28:09.248 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-04-26T08:28:09.310 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-04-26T08:28:09.545 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-04-26T08:28:09.560 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-04-26T08:28:09.732 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-04-26T08:28:09.967 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-26T08:28:10.029 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-04-26T08:28:10.498 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-04-26T08:28:10.779 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-04-26T08:28:10.826 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-04-26T08:28:10.873 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-04-26T08:28:11.264 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-26T08:28:11.560 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-04-26T08:28:11.857 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-04-26T08:28:11.904 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-04-26T08:28:12.092 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-04-26T08:28:12.326 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-26T08:28:12.389 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-04-26T08:28:12.435 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-04-26T08:28:12.514 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-04-26T08:28:12.576 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-04-26T08:28:12.592 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-04-26T08:28:12.701 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-04-26T08:28:12.951 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-04-26T08:28:12.982 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-04-26T08:28:13.607 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-04-26T08:28:13.826 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-04-26T08:28:13.920 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:14.029 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-04-26T08:28:14.357 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-04-26T08:28:14.435 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-04-26T08:28:14.467 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-04-26T08:28:14.498 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-04-26T08:28:14.545 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-04-26T08:28:14.576 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:14.670 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-26T08:28:14.717 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-26T08:28:14.795 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-04-26T08:28:14.842 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-04-26T08:28:14.904 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:14.982 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-04-26T08:28:15.248 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-04-26T08:28:15.295 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-04-26T08:28:15.435 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-04-26T08:28:15.607 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-04-26T08:28:15.967 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-26T08:28:16.045 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-04-26T08:28:16.279 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-04-26T08:28:16.623 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-04-26T08:28:16.951 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-04-26T08:28:17.217 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-04-26T08:28:17.326 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-04-26T08:28:17.420 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-04-26T08:28:17.873 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-04-26T08:28:18.045 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-04-26T08:28:18.060 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-26T08:28:18.123 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-26T08:28:18.139 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-04-26T08:28:18.139 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-04-26T08:28:18.826 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-04-26T08:28:18.857 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-04-26T08:28:18.920 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-04-26T08:28:19.154 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-04-26T08:28:19.170 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-04-26T08:28:19.357 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-04-26T08:28:19.420 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-26T08:28:19.467 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-04-26T08:28:19.467 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-04-26T08:28:19.576 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-04-26T08:28:19.998 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-04-26T08:28:20.185 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-04-26T08:28:20.201 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-04-26T08:28:20.248 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-04-26T08:28:20.420 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-04-26T08:28:20.498 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-04-26T08:28:20.764 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-04-26T08:28:20.764 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-04-26T08:28:20.779 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-04-26T08:28:20.982 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-04-26T08:28:21.107 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-04-26T08:28:21.389 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-04-26T08:28:21.451 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-04-26T08:28:21.717 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-04-26T08:28:21.795 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-04-26T08:28:21.826 Engine:Setting original file name "TWINUI.dll" for "c:\windows\winsxs\amd64_microsoft-windows-twinui_31bf3856ad364e35_10.0.22000.2538_none_ecbf26dcf11a684d\twinui.dll.mun", hr=0x800710da 2026-04-26T08:28:21.857 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-04-26T08:28:22.592 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-04-26T08:28:22.717 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-04-26T08:28:22.748 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-04-26T08:28:22.935 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-shell32_31bf3856ad364e35_10.0.22000.2482_none_e551341849a7f566\shell32.dll.mun", hr=0x800710da 2026-04-26T08:28:22.982 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-04-26T08:28:23.060 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-04-26T08:28:23.107 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-04-26T08:28:23.185 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-04-26T08:28:23.201 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-04-26T08:28:23.217 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-04-26T08:28:23.389 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-04-26T08:28:23.436 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-26T08:28:23.498 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-04-26T08:28:23.529 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-04-26T08:28:23.545 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-04-26T08:28:23.795 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-04-26T08:28:23.904 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-26T08:28:23.951 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-26T08:28:23.982 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-04-26T08:28:24.201 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-04-26T08:28:24.295 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-04-26T08:28:24.310 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:24.326 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-04-26T08:28:24.560 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-04-26T08:28:24.920 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-26T08:28:24.998 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-04-26T08:28:25.107 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-04-26T08:28:25.217 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-26T08:28:25.279 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-04-26T08:28:25.389 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-04-26T08:28:25.451 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-04-26T08:28:25.529 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-04-26T08:28:25.654 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-04-26T08:28:25.685 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-04-26T08:28:25.717 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-04-26T08:28:25.920 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-04-26T08:28:25.998 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-04-26T08:28:26.014 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-04-26T08:28:26.014 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-26T08:28:26.732 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-04-26T08:28:26.842 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-04-26T08:28:26.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-04-26T08:28:27.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-04-26T08:28:27.310 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-04-26T08:28:27.326 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-04-26T08:28:27.654 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-04-26T08:28:27.732 Engine:Setting original file name "msdxm.ocx" for "c:\windows\syswow64\dxmasf.dll", hr=0x800710da 2026-04-26T08:28:27.967 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-04-26T08:28:27.982 Engine:Triggered AR EMS scan 2026-04-26T08:28:27.982 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:27.998 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.014 Engine:EMS scan for process: svchost pid: 672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.014 Engine:EMS scan for process: svchost pid: 1032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.014 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-04-26T08:28:28.014 Engine:EMS scan for process: svchost pid: 1180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.014 Engine:EMS scan for process: svchost pid: 1276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.014 Engine:EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.029 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.029 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.029 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.029 Engine:EMS scan for process: svchost pid: 1460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.029 Engine:EMS scan for process: svchost pid: 1472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.045 Engine:EMS scan for process: svchost pid: 1948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 1288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 1720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 2200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 2268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.060 Engine:EMS scan for process: svchost pid: 2432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.076 Engine:EMS scan for process: svchost pid: 2956, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.092 Engine:EMS scan for process: svchost pid: 3036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.092 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-04-26T08:28:28.092 Engine:EMS scan for process: svchost pid: 2220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.092 Engine:EMS scan for process: svchost pid: 3096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.107 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-04-26T08:28:28.107 Engine:EMS scan for process: svchost pid: 3596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.107 Engine:EMS scan for process: svchost pid: 3604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.107 Engine:EMS scan for process: svchost pid: 3712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.107 Engine:EMS scan for process: svchost pid: 3724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.123 Engine:EMS scan for process: svchost pid: 3792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.139 Engine:EMS scan for process: svchost pid: 3828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.139 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.139 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.139 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.139 Engine:EMS scan for process: svchost pid: 4172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.154 Engine:EMS scan for process: svchost pid: 4208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.154 Engine:EMS scan for process: svchost pid: 4332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.154 Engine:EMS scan for process: svchost pid: 4428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.170 Engine:EMS scan for process: svchost pid: 4528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.170 Engine:EMS scan for process: svchost pid: 4688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.170 Engine:EMS scan for process: svchost pid: 4796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.170 Engine:EMS scan for process: svchost pid: 5544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: svchost pid: 5968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: svchost pid: 5476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: svchost pid: 5772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: svchost pid: 1256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: dllhost pid: 5128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.185 Engine:EMS scan for process: svchost pid: 6508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.201 Engine:EMS scan for process: svchost pid: 7432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.201 Engine:EMS scan for process: svchost pid: 7608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.201 Engine:EMS scan for process: svchost pid: 7756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.201 Engine:EMS scan for process: svchost pid: 2328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.201 Engine:EMS scan for process: svchost pid: 912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.217 Engine:EMS scan for process: svchost pid: 7232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.217 Engine:EMS scan for process: svchost pid: 3308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.217 Engine:EMS scan for process: svchost pid: 6684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.217 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.217 Engine:EMS scan for process: svchost pid: 5676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-26T08:28:28.295 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_flac_plugin.dll", hr=0x800710da 2026-04-26T08:28:28.310 OriginalFileName Maintenance::9880 files in Moac, 246 skipped (cached), 1 filename set 2026-04-26T08:28:28.310 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-26T08:31:57.029 QuickScan:ScanID:89B35D69-B6A4-48EE-AC87-D668C878E6D0: Quick scan finished with error 0 2026-04-26T08:31:57.545 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-26T08:31:57.545 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:31:57.545 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:31:57.545 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-26T08:31:57.545 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-26T08:31:57.545 [RTP] No config change detected. Not updating plugin configuration. 2026-04-26T08:31:57.545 [RTP] No config changes found. No configuration switch. 2026-04-26T08:31:57.545 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-26T08:31:59.045 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:31:59.045 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-26T08:31:59.045 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-26T08:33:01.029 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #1947, FileId: 0x44000000018749, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-26T08:33:03.154 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-04-26T08:33:03.154 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-04-26T08:33:03.154 [RTP] Duplicating the current plugin configuration object... 2026-04-26T08:33:03.154 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-26T08:33:03.154 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-26T08:33:03.154 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-26T08:33:03.154 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-26T08:33:04.498 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-04-26T08:33:04.592 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-04-26T08:33:04.811 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-04-26T08:33:04.811 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-04-26T08:37:56.670 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T08:53:01.670 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T09:08:06.670 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T09:17:51.669 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-26T09:23:11.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T09:38:16.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T09:53:21.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T10:08:26.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T10:17:51.497 ProcessImageName: setup.exe, Pid: 2232, TotalTime: 6427, Count: 396, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.86\EBWebView\x86\EmbeddedBrowserWebView.dll, EstimatedImpact: 19% 2026-04-26T10:17:51.497 ProcessImageName: SrTasks.exe, Pid: 5688, TotalTime: 2895, Count: 395, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 16% 2026-04-26T10:17:51.497 ProcessImageName: svchost.exe, Pid: 3308, TotalTime: 1483, Count: 2, MaxTime: 765, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-04-26T10:17:51.497 ProcessImageName: WmiPrvSE.exe, Pid: 1668, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-26T10:17:51.497 ProcessImageName: svchost.exe, Pid: 3724, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll, EstimatedImpact: 100% 2026-04-26T10:17:51.497 ProcessImageName: svchost.exe, Pid: 1432, TotalTime: 200, Count: 7, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-26T10:17:51.497 ProcessImageName: ngentask.exe, Pid: 8072, TotalTime: 180, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 5% 2026-04-26T10:17:51.497 ProcessImageName: ngentask.exe, Pid: 7508, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 6% 2026-04-26T10:17:51.497 ProcessImageName: svchost.exe, Pid: 2452, TotalTime: 108, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-26T10:17:51.497 ProcessImageName: MicrosoftEdge_X64_147.0.3912.86_147.0.3912.72.exe, Pid: 5464, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{A3CE9A20-F1B4-42E1-818A-6175F0A64676}\EDGEMITMP_A0CEA.tmp\setup.exe, EstimatedImpact: 74% 2026-04-26T10:17:51.497 ProcessImageName: OfficeC2RClient.exe, Pid: 6244, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8853795B-7A73-4BA7-9888-DB36A082B34E, EstimatedImpact: 1% 2026-04-26T10:17:51.497 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-26T10:17:51.497 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-26T10:17:51.497 ProcessImageName: taskhostw.exe, Pid: 7084, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-04-26T10:17:51.497 ProcessImageName: brynhildr.exe, Pid: 4112, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-26T10:17:51.497 ProcessImageName: AggregatorHost.exe, Pid: 5484, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-26T10:23:31.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T10:38:36.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T10:53:41.669 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T11:08:46.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T11:23:51.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T11:38:56.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T11:54:01.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T12:09:06.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T12:17:51.496 ProcessImageName: setup.exe, Pid: 2232, TotalTime: 6427, Count: 396, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.86\EBWebView\x86\EmbeddedBrowserWebView.dll, EstimatedImpact: 19% 2026-04-26T12:17:51.496 ProcessImageName: SrTasks.exe, Pid: 5688, TotalTime: 2895, Count: 395, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 16% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 3308, TotalTime: 1483, Count: 2, MaxTime: 765, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-04-26T12:17:51.496 ProcessImageName: WmiPrvSE.exe, Pid: 1668, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 1432, TotalTime: 260, Count: 13, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 3724, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll, EstimatedImpact: 100% 2026-04-26T12:17:51.496 ProcessImageName: ngentask.exe, Pid: 8072, TotalTime: 180, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 5% 2026-04-26T12:17:51.496 ProcessImageName: ngentask.exe, Pid: 7508, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 6% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 2452, TotalTime: 108, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: MicrosoftEdge_X64_147.0.3912.86_147.0.3912.72.exe, Pid: 5464, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{A3CE9A20-F1B4-42E1-818A-6175F0A64676}\EDGEMITMP_A0CEA.tmp\setup.exe, EstimatedImpact: 74% 2026-04-26T12:17:51.496 ProcessImageName: OfficeC2RClient.exe, Pid: 6244, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8853795B-7A73-4BA7-9888-DB36A082B34E, EstimatedImpact: 1% 2026-04-26T12:17:51.496 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: dasHost.exe, Pid: 5304, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: taskhostw.exe, Pid: 7084, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-04-26T12:17:51.496 ProcessImageName: svchost.exe, Pid: 3704, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\312ef17b129f7a558900d74158c40459f81c67d2\content.phf, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: AggregatorHost.exe, Pid: 5484, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-04-26T12:17:51.496 ProcessImageName: brynhildr.exe, Pid: 4112, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-26T12:24:11.668 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T12:39:16.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T12:54:21.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T13:09:26.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T13:24:31.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T13:39:36.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T13:54:41.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T14:09:46.667 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T14:17:51.510 ProcessImageName: setup.exe, Pid: 2232, TotalTime: 6427, Count: 396, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.86\EBWebView\x86\EmbeddedBrowserWebView.dll, EstimatedImpact: 19% 2026-04-26T14:17:51.510 ProcessImageName: SrTasks.exe, Pid: 5688, TotalTime: 2895, Count: 395, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 16% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 3308, TotalTime: 1483, Count: 2, MaxTime: 765, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-04-26T14:17:51.510 ProcessImageName: WmiPrvSE.exe, Pid: 1668, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 1432, TotalTime: 290, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 3724, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll, EstimatedImpact: 100% 2026-04-26T14:17:51.510 ProcessImageName: ngentask.exe, Pid: 8072, TotalTime: 180, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 5% 2026-04-26T14:17:51.510 ProcessImageName: ngentask.exe, Pid: 7508, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 6% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 2452, TotalTime: 108, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: MicrosoftEdge_X64_147.0.3912.86_147.0.3912.72.exe, Pid: 5464, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{A3CE9A20-F1B4-42E1-818A-6175F0A64676}\EDGEMITMP_A0CEA.tmp\setup.exe, EstimatedImpact: 74% 2026-04-26T14:17:51.510 ProcessImageName: OfficeC2RClient.exe, Pid: 6244, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8853795B-7A73-4BA7-9888-DB36A082B34E, EstimatedImpact: 1% 2026-04-26T14:17:51.510 ProcessImageName: dasHost.exe, Pid: 5304, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: taskhostw.exe, Pid: 7084, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-04-26T14:17:51.510 ProcessImageName: svchost.exe, Pid: 3704, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\312ef17b129f7a558900d74158c40459f81c67d2\content.phf, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: AggregatorHost.exe, Pid: 5484, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-04-26T14:17:51.510 ProcessImageName: brynhildr.exe, Pid: 4112, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-26T14:24:51.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T14:39:56.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T14:55:01.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T15:10:06.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T15:25:11.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T15:40:16.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T15:55:21.666 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T16:10:26.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T16:17:51.509 ProcessImageName: setup.exe, Pid: 2232, TotalTime: 6427, Count: 396, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.86\EBWebView\x86\EmbeddedBrowserWebView.dll, EstimatedImpact: 19% 2026-04-26T16:17:51.509 ProcessImageName: SrTasks.exe, Pid: 5688, TotalTime: 2895, Count: 395, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 16% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 3308, TotalTime: 1483, Count: 2, MaxTime: 765, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-04-26T16:17:51.509 ProcessImageName: WmiPrvSE.exe, Pid: 1668, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 1432, TotalTime: 290, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 3724, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll, EstimatedImpact: 100% 2026-04-26T16:17:51.509 ProcessImageName: ngentask.exe, Pid: 8072, TotalTime: 180, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 5% 2026-04-26T16:17:51.509 ProcessImageName: ngentask.exe, Pid: 7508, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 6% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 2452, TotalTime: 108, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: MicrosoftEdge_X64_147.0.3912.86_147.0.3912.72.exe, Pid: 5464, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{A3CE9A20-F1B4-42E1-818A-6175F0A64676}\EDGEMITMP_A0CEA.tmp\setup.exe, EstimatedImpact: 74% 2026-04-26T16:17:51.509 ProcessImageName: OfficeC2RClient.exe, Pid: 6244, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8853795B-7A73-4BA7-9888-DB36A082B34E, EstimatedImpact: 1% 2026-04-26T16:17:51.509 ProcessImageName: dasHost.exe, Pid: 5304, TotalTime: 90, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: taskhostw.exe, Pid: 7084, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-04-26T16:17:51.509 ProcessImageName: svchost.exe, Pid: 3704, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\312ef17b129f7a558900d74158c40459f81c67d2\content.phf, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: AggregatorHost.exe, Pid: 5484, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-04-26T16:17:51.509 ProcessImageName: brynhildr.exe, Pid: 4112, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-26T16:25:31.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T16:40:36.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T16:55:41.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T17:10:46.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T17:25:51.665 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T17:40:56.664 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T17:56:01.627 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T18:11:06.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T18:17:51.423 ProcessImageName: setup.exe, Pid: 2232, TotalTime: 6427, Count: 396, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.86\EBWebView\x86\EmbeddedBrowserWebView.dll, EstimatedImpact: 19% 2026-04-26T18:17:51.423 ProcessImageName: SrTasks.exe, Pid: 5688, TotalTime: 2895, Count: 395, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 16% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 3308, TotalTime: 1483, Count: 2, MaxTime: 765, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-04-26T18:17:51.423 ProcessImageName: WmiPrvSE.exe, Pid: 1668, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 1432, TotalTime: 335, Count: 19, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 3724, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E7FE190-BE38-4928-90D6-88899E757A20}\mpengine.dll, EstimatedImpact: 100% 2026-04-26T18:17:51.423 ProcessImageName: ngentask.exe, Pid: 8072, TotalTime: 180, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 5% 2026-04-26T18:17:51.423 ProcessImageName: ngentask.exe, Pid: 7508, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 6% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 2452, TotalTime: 108, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: dasHost.exe, Pid: 5304, TotalTime: 105, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: MicrosoftEdge_X64_147.0.3912.86_147.0.3912.72.exe, Pid: 5464, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{A3CE9A20-F1B4-42E1-818A-6175F0A64676}\EDGEMITMP_A0CEA.tmp\setup.exe, EstimatedImpact: 74% 2026-04-26T18:17:51.423 ProcessImageName: OfficeC2RClient.exe, Pid: 6244, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8853795B-7A73-4BA7-9888-DB36A082B34E, EstimatedImpact: 1% 2026-04-26T18:17:51.423 ProcessImageName: taskhostw.exe, Pid: 5508, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: taskhostw.exe, Pid: 7084, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 3704, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\312ef17b129f7a558900d74158c40459f81c67d2\content.phf, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: dllhost.exe, Pid: 5128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: svchost.exe, Pid: 3216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT7496.tmp, EstimatedImpact: 5% 2026-04-26T18:17:51.423 ProcessImageName: AggregatorHost.exe, Pid: 5484, TotalTime: 15, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-04-26T18:17:51.423 ProcessImageName: brynhildr.exe, Pid: 4112, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-26T18:26:11.567 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T18:41:16.548 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T18:56:21.534 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T19:11:26.523 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T19:26:31.515 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T19:41:36.509 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T19:56:41.505 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T20:11:46.501 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-26T20:15:05.204 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\B4613952-C141-4656-9EBC-89CEF08A6B321fe4.1dcd5b95dd56a57 2026-04-26T20:15:05.297 Verifying engine and signature files (source: 0) ... 2026-04-26T20:15:05.297 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpengine.dll] due to PPL. 2026-04-26T20:15:05.297 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasbase.vdm] (file in cache) 2026-04-26T20:15:05.297 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-26T20:15:05.313 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasdlta.vdm] 2026-04-26T20:15:05.313 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpavbase.vdm] (file in cache) 2026-04-26T20:15:05.313 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-26T20:15:05.329 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpavdlta.vdm] 2026-04-26T20:15:05.485 [Engine] IsHybridMode: 0 2026-04-26T20:15:05.485 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-26T20:15:05.501 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-349B5FCDAA3369859BFA2155C416F3FA80871CFA.bin): 0x00000002 2026-04-26T20:15:05.501 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-349B5FCDAA3369859BFA2155C416F3FA80871CFA.bin) 2026-04-26T20:15:05.501 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-26T20:15:05.501 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-26T20:15:05.501 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-26T20:15:05.501 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-26T20:15:17.219 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-26T20:15:17.219 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-04-26T20:15:17.219 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB0EEC8020, lRefCount: 5, hr=0 2026-04-26T20:15:17.219 [Engine] New active engine 00007FFB08878020 replacing engine 00007FFB0EEC8020. Number of active engines: 2 2026-04-26T20:15:17.235 EngineInit:Global ASOC is enabled 2026-04-26T20:15:17.235 EngineInit:ASOO is enabled for developer volumes 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-26T20:15:17.297 MpWriteUupSignatureVersion 1.449.311.0, hr = 0 2026-04-26T20:15:17.297 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-26T20:15:17.313 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-26T20:15:17.313 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-26T20:15:17.313 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-26T20:15:17.313 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-26T20:15:17.313 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-26T20:15:17.329 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-26T20:15:17.329 [Plugin] Initializing RTP plugin state... 2026-04-26T20:15:17.329 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-26T20:15:17.329 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎26‎-‎2026 10:17:51 Last Perf:‎04‎-‎26‎-‎2026 10:17:51 First RTP Scan:‎04‎-‎26‎-‎2026 10:17:51 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1649 Misses:7003 BM Queue:0,13,0 Proc:0,13,0 File:0,7,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:9758 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:277975888 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:14 TotalStreamCon:6316 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:23361 TotalHits:332339 InstanceCacheInserts:520 InstanceCacheUpdates:0 InstanceCacheDeletes:16 InstanceCacheHits:30 InstanceCacheMisses:8308 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (433/217) Success: 217, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-29-2026 17:07:27 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/29/2026 17:07:27.974382100 UTC (13687 ms since boot) 2026-04-29T17:07:28.005 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-29T17:07:28.050 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-29T17:07:28.050 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-29T17:07:28.108 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260429-170728-00000003-fffffffeffffffff.bin ... 2026-04-29T17:07:28.157 [WPP] Trace session started - MpWppTracing-20260429-170728-00000003-fffffffeffffffff.bin 2026-04-29T17:07:28.165 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-29T17:07:28.165 [RbM] Rollback manager succesfully initialized. 2026-04-29T17:07:28.165 [RbM] Rollback manager EnableRollbackManager called. 2026-04-29T17:07:28.175 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-29T17:07:28.175 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-29T17:07:28.175 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-29T17:07:28.175 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-29T17:07:28.175 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-29T17:07:28.180 MdCoreSvc is supported in this platform and OS 2026-04-29T17:07:28.180 MdCoreSvc is supported in this platform and OS 2026-04-29T17:07:28.180 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-29T17:07:28.180 [PlatUpd] Starting MdCoreSvc service 2026-04-29T17:07:28.215 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-29T17:07:32.059 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-29T17:07:32.059 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-29T17:07:32.059 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-29T17:07:32.059 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-29T17:07:32.059 [PlatUpd] CSP platform update started 2026-04-29T17:07:32.059 [PlatUpd] Defender MDM CSP platform update not required 2026-04-29T17:07:32.059 [PlatUpd] WMI/PS provider platform update started 2026-04-29T17:07:32.059 [PlatUpd] WMI/PS provider platform update not required 2026-04-29T17:07:32.059 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-29T17:07:32.059 MdCoreSvc is supported in this platform and OS 2026-04-29T17:07:32.059 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-29T17:07:32.059 [PlatUpd] Starting MdCoreSvc service 2026-04-29T17:07:32.059 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-29T17:07:32.075 [TS] Troublshooting mode is not available! 2026-04-29T17:07:32.075 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-29T17:07:32.075 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-29T17:07:32.090 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-29T17:07:32.090 [Service] Enabling AutoLoggers ... 2026-04-29T17:07:32.090 [Service] Enabling AMSI registration ... 2026-04-29T17:07:32.090 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-29T17:07:32.106 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 44880 Number of invalid entries is 0 Number of inserts issued is 1577353 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6461 Number of lookups is 107547016 Number of lookup misses is 5159777 Number of fast lookup misses is 54814249 Number of false fast lookups is 5159772 Number of invalidations is 731246 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-29T17:07:32.106 Verifying license file... 2026-04-29T17:07:32.106 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-04-29T17:07:32.122 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-29T17:07:32.122 Loaded module#0 MpComServer. 2026-04-29T17:07:32.122 Loaded module#1 StartupPolicies. 2026-04-29T17:07:32.122 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-29T17:07:32.122 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-29T17:07:32.122 COM server initialized successfully. 2026-04-29T17:07:32.137 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-29T17:07:32.137 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-29T17:07:32.137 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-29T17:07:32.153 [RTP] [RTP] FilterCommunicator object 0x000001729906EDA0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-29T17:07:32.153 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-29T17:07:32.153 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-29T17:07:32.153 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-29T17:07:32.153 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-29T17:07:32.153 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-29T17:07:32.153 [RTP] [RTP] FilterCommunicator object 0x000001729909EBB0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-29T17:07:32.153 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-29T17:07:32.153 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-29T17:07:32.153 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-29T17:07:32.153 [RTP] [RTP] StartCommunication 0x000001729906EDA0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-29T17:07:32.153 [init][RTP] RTPPlugin initialization completed 2026-04-29T17:07:32.153 OS boot count = 2 2026-04-29T17:07:32.153 OS Install = 0 2026-04-29T17:07:32.168 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-29T17:07:32.168 [KSL] Entering CKSLEngine::Initialize. 2026-04-29T17:07:32.168 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-29T17:07:32.168 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-29T17:07:32.168 [KSL] MpInstallKslD: hr=0x1 2026-04-29T17:07:32.168 [KSL] MpRegisterKslD: hr=0 2026-04-29T17:07:32.184 [KSL] MpStartKslD: hr=0 2026-04-29T17:07:32.184 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-29T17:07:32.184 Loading engine... 2026-04-29T17:07:32.200 Verifying engine and signature files (source: 1) ... 2026-04-29T17:07:32.200 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpengine.dll] due to PPL. 2026-04-29T17:07:32.200 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasbase.vdm] (file in cache) 2026-04-29T17:07:32.200 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasdlta.vdm] (file in cache) 2026-04-29T17:07:32.200 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpavbase.vdm] (file in cache) 2026-04-29T17:07:32.200 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpavdlta.vdm] (file in cache) 2026-04-29T17:07:32.247 [Engine] IsHybridMode: 0 2026-04-29T17:07:32.247 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-29T17:07:32.278 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-349B5FCDAA3369859BFA2155C416F3FA80871CFA.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-29T17:07:39.059 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-29T17:07:39.059 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-29T17:07:39.059 [Engine] New active engine 00007FFC566D8020 (no old engine). Number of active engines: 1 2026-04-29T17:07:39.059 EngineInit:Global ASOC is enabled 2026-04-29T17:07:39.059 EngineInit:ASOO is enabled for developer volumes 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.137 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.153 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d85011e6cf683d0d7999ae4d04e4e77b1084c8e7 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a84107a452bb96c9cf6d591005753f5c7bd3859 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ab5c3a07fe160d584c762ce17dd691017b1a535c Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2508d7a2588d7edbe0a263b3fd7837b3e4c9c433 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2a8211f476deca5d6fc03814e403bcf1012dbfa1 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\61800682a94d00c47adb66133e955adb2fdfac18 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cf2778fe357efdbe2e426c87cba41a061baccc87 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:14 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\32649ccda90b58c40ce31f292945a4fe03988f41 Dynamic Signature Compilation Timestamp:04-18-2026 22:30:15 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.153 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5b40b1a60b3671e1f5d44f82a3d5fb78283368ad Dynamic Signature Compilation Timestamp:04-18-2026 22:55:21 Persistence Type:Duration Time remaining:50065408 2026-04-29T17:07:39.168 MpWriteUupSignatureVersion 1.449.311.0, hr = 0 2026-04-29T17:07:39.184 [SigStatUpd] CSignatureStatus: back to good 2026-04-29T17:07:39.184 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-29T17:07:39.200 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-29T17:07:39.200 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-29T17:07:39.200 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-29T17:07:39.200 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-29T17:07:39.200 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-29T17:07:39.215 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-29T17:07:39.215 [Plugin] Initializing RTP plugin state... 2026-04-29T17:07:39.215 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-29T17:07:39.215 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2298 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13007 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2582 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-29T17:07:39.215 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4} 2026-04-29T17:07:39.215 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:07:39.215 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:07:39.215 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:07:39.215 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-29T17:07:39.215 MdCoreSvc is supported in this platform and OS 2026-04-29T17:07:39.215 Engine loaded! 2026-04-29T17:07:39.215 [DLP] Create FeatureControlState instance 2026-04-29T17:07:39.215 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-29T17:07:39.215 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-29T17:07:39.215 RegisterSModeChangeListener: hr = 0x1 2026-04-29T17:07:39.215 RegisterHybridModeChangeListener: hr = 0 2026-04-29T17:07:39.231 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-29T17:07:39.231 [SigReleaseHb] Initialized with Stage 0 2026-04-29T17:07:39.231 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-29T17:07:39.231 [SCC][CID=24953_5432] Initializing ... 2026-04-29T17:07:39.231 [SCC][CID=24953_5432] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-29T17:07:39.231 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-29T17:07:39.231 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-29T17:07:39.231 [NRI] Stopping NIS service ... 2026-04-29T17:07:39.231 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-29T17:07:39.231 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.311.0 AV Signature Version: 1.449.311.0 ************************************************************ 2026-04-29T17:07:39.247 Resource usage Monitoring is enabled 2026-04-29T17:07:39.247 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-29T17:07:39.247 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-29T17:07:39.247 Job Notification: New process added to job (4732) 2026-04-29T17:07:39.262 Job Notification: New process added to job (7620) 2026-04-29T17:07:39.262 Job Notification: New process added to job (7628) 2026-04-29T17:07:39.262 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7620] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7628]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-29T17:07:39.325 Job Notification: Process exited from job (7620) 2026-04-29T17:07:39.325 Job Notification: Process exited from job (7628) 2026-04-29T17:07:39.325 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-29T17:07:39.340 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-29T17:07:39.340 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-29T17:07:39.340 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-29T17:07:39.340 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-29T17:07:39.340 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-29T17:07:39.340 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-29T17:07:39.340 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-29T17:07:39.340 [RTP] Generating the base plugin configuration ... 2026-04-29T17:07:39.340 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-29T17:07:39.340 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:07:39.340 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-29T17:07:39.340 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-29T17:07:39.340 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:07:39.340 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-29T17:07:39.340 [RTP] [RTP] StartCommunication 0x000001729909EBB0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-29T17:07:39.356 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-29T17:07:39.356 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-29T17:07:39.684 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:39.684 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-29T17:07:39.684 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-29T17:07:39.684 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-29T17:07:40.028 [AutoPurge] Verification Routine tasks have started. 2026-04-29T17:07:40.028 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-29T17:07:40.231 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-29T17:07:40.247 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-29T17:07:40.262 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-29T17:07:40.606 Job Notification: New process added to job (7816) 2026-04-29T17:07:40.606 Task(GetDeviceTicket -AccessKey D1F2922C-6C5C-D47C-7655-4CDB86966EA9 ) launched as network service 2026-04-29T17:07:40.950 Job Notification: Process exited from job (7816) 2026-04-29T17:07:41.012 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-04-29T17:07:41.012 [Cloud] Start of cloud request. Passive mode: 0 2026-04-29T17:07:41.012 [Cloud] Queued cloud request. 2026-04-29T17:07:41.012 [Cloud] Dequeued cloud request. 2026-04-29T17:07:41.028 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-29T17:07:41.028 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-29T17:07:41.028 [AutoPurge] Verification Routine tasks have ended. 2026-04-29T17:07:41.340 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-04-29T17:07:41.340 [Cloud] End of cloud request. 2026-04-29T17:07:41.481 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-29T17:07:41.497 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-29T17:07:41.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-29T17:07:41.512 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-29T17:07:41.512 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-29T17:07:41.512 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-29T17:07:41.512 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-29T17:07:41.512 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-29T17:07:41.512 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-29T17:07:41.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:41.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:41.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:07:42.262 [RTP] Duplicating the current plugin configuration object... 2026-04-29T17:07:42.262 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-29T17:07:42.262 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-04-29T17:07:42.262 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:07:42.262 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-29T17:07:42.262 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-04-29T17:07:56.590 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\3B4A382B-4DF0-4639-8A1E-F891E75EB8811c10.1dcd7fab8883715 2026-04-29T17:07:56.715 Verifying engine and signature files (source: 0) ... 2026-04-29T17:07:56.715 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpengine.dll] due to PPL. 2026-04-29T17:07:56.715 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasbase.vdm] (file in cache) 2026-04-29T17:07:56.715 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-29T17:07:56.731 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasdlta.vdm] 2026-04-29T17:07:56.731 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavbase.vdm] (file in cache) 2026-04-29T17:07:56.731 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-29T17:07:56.747 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavdlta.vdm] 2026-04-29T17:07:56.903 [Engine] IsHybridMode: 0 2026-04-29T17:07:56.903 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-29T17:07:56.903 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-02E3AAD8667BDE71092BADD1689704D926C359B4.bin): 0x00000002 2026-04-29T17:07:56.918 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-02E3AAD8667BDE71092BADD1689704D926C359B4.bin) 2026-04-29T17:07:56.918 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-29T17:07:56.918 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-29T17:07:56.918 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-29T17:07:56.918 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-29T17:08:08.778 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-29T17:08:08.778 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-29T17:08:08.793 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFC566D8020, lRefCount: 6, hr=0 2026-04-29T17:08:08.793 [Engine] New active engine 00007FFC51D98020 replacing engine 00007FFC566D8020. Number of active engines: 2 2026-04-29T17:08:08.793 EngineInit:Global ASOC is enabled 2026-04-29T17:08:08.793 EngineInit:ASOO is enabled for developer volumes 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.856 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-29T17:08:08.872 MpWriteUupSignatureVersion 1.449.357.0, hr = 0 2026-04-29T17:08:08.872 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-29T17:08:08.887 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-29T17:08:08.887 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-29T17:08:08.887 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-29T17:08:08.887 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-29T17:08:08.887 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-29T17:08:08.903 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-29T17:08:08.903 [Plugin] Initializing RTP plugin state... 2026-04-29T17:08:08.903 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-29T17:08:08.903 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎29‎-‎2026 19:07:39 Last Perf:‎04‎-‎29‎-‎2026 19:07:39 First RTP Scan:‎04‎-‎29‎-‎2026 19:07:39 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:262 Misses:520 BM Queue:0,9,0 Proc:0,9,0 File:0,7,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:799 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:708652 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2591 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14845 TotalHits:954 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2907 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (25/7) Success: 7, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-29T17:08:08.903 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8} 2026-04-29T17:08:08.903 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-29T17:08:08.903 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{021BF8C9-A27A-4CB8-AC6F-9D5DEEFD1E09} removed 2026-04-29T17:08:08.903 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4}\mpasbase.vdm in use, hr=0x80070020 2026-04-29T17:08:08.903 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.903 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.903 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.903 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.903 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-29-2026 17:08:08 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-29-2026 17:08:08 2026-04-29T17:08:08.903 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-29T17:08:08.903 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-29T17:08:08.918 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:08:08.918 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-29T17:08:08.918 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-29T17:08:08.918 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.918 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.918 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.918 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-29T17:08:08.918 MdCoreSvc is supported in this platform and OS Signature updated on 04-29-2026 17:08:08 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.357.0 AV Signature Version: 1.449.357.0 ************************************************************ 2026-04-29T17:08:08.918 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-29T17:08:08.918 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\3B4A382B-4DF0-4639-8A1E-F891E75EB8811c10.1dcd7fab8883715 2026-04-29T17:08:08.997 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-29T17:08:08.997 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-29T17:08:09.262 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-29T17:08:09.262 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-29T17:08:09.262 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-29T17:08:09.262 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-29T17:08:09.262 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-29T17:08:09.262 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:08:09.262 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-29T17:08:09.372 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-29T17:08:09.372 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-29T17:08:09.372 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-29T17:08:32.122 Process scan (postsignatureupdatescan) started. 2026-04-29T17:08:40.043 [Engine] Engine 00007FFC566D8020 no longer in use. Number of active engines: 1 2026-04-29T17:08:40.137 ProcessImageName: taskhostw.exe, Pid: 7332, TotalTime: 562, Count: 2, MaxTime: 531, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-04-29T17:08:40.137 ProcessImageName: WmiPrvSE.exe, Pid: 3024, TotalTime: 390, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 19% 2026-04-29T17:08:40.137 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-29T17:08:40.153 [Engine] RSIG_UNLOADENGINE, 00007FFC566D8020, err=0x0 2026-04-29T17:08:40.168 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A4F3A71D-202A-4B62-99CE-76D985FAFEE4} removed 2026-04-29T17:08:47.715 Process scan (postsignatureupdatescan) completed. 2026-04-29T17:09:36.325 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:09:36.325 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-29T17:09:36.325 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:11:48.947 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3936, FileId: 0x20000000c3d6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:39.232 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T17:12:41.196 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-29T17:12:41.196 [RTP] Duplicating the current plugin configuration object... 2026-04-29T17:12:41.196 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-29T17:12:41.196 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-29T17:12:41.196 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-29T17:12:41.197 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-29T17:12:41.213 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-29T17:12:41.303 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-29T17:12:44.816 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #5109, FileId: 0x2e000000032a9a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:44.816 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #5110, FileId: 0x1900000001ad46, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:47.419 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-04-29T17:12:53.263 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5793, FileId: 0x200000000336ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.386 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5896, FileId: 0x4400000000d210, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.388 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5898, FileId: 0x4500000000d210, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.393 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5899, FileId: 0xbe00000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.394 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5900, FileId: 0x4f00000000d210, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.429 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5892, FileId: 0x4300000000d210, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:55.437 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5897, FileId: 0xb300000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.244 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5940, FileId: 0xc300000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.245 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5938, FileId: 0xc200000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.251 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5939, FileId: 0xea000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.280 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5937, FileId: 0xc100000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.313 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5948, FileId: 0xc800000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.314 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5949, FileId: 0xf0000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.316 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5947, FileId: 0xef000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.320 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5951, FileId: 0xc900000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.324 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5954, FileId: 0xf1000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.376 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5959, FileId: 0xcd00000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.377 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5958, FileId: 0xf3000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.380 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5956, FileId: 0xf2000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.424 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5957, FileId: 0xcb00000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.565 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5984, FileId: 0xf8000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.565 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5983, FileId: 0xd000000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.571 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5981, FileId: 0xcf00000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:56.574 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5982, FileId: 0xf7000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:57.988 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6100, FileId: 0xd400000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:58.023 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6101, FileId: 0xfb000000005022, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:58.872 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 5250 units 2026-04-29T17:12:59.063 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\8fbdce3b-afd5-4b1c-9c85-f5564c3be7f8. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6225, FileId: 0xfa0000000035cd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.067 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6223, FileId: 0x7200000000c71b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.427 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6239, FileId: 0x52000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.430 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6238, FileId: 0x50000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.438 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6240, FileId: 0x2b000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.450 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6241, FileId: 0x30000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.451 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6242, FileId: 0x57000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.454 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6243, FileId: 0x31000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.456 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6246, FileId: 0x5c000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.456 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6247, FileId: 0x34000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.458 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6245, FileId: 0x32000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.460 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6248, FileId: 0x35000000012294, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.871 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6280, FileId: 0xd700000000681a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:12:59.895 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\a782740d-c1b1-4af5-8d6b-7d35ec6455c8. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6283, FileId: 0x10000000000142c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:08.862 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-29T17:13:12.924 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj672FC19DF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6669, FileId: 0x4f0000000135a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:12.942 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj42B28891C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6671, FileId: 0x500000000135a9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:12.947 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF52C4298F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6672, FileId: 0x4a000000013157, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.018 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj618C6F954. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6677, FileId: 0x350000000135ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.042 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj15583B95A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6678, FileId: 0x370000000135ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.124 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA9D52098C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6682, FileId: 0x380000000135ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.198 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBB6282928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6689, FileId: 0x390000000135ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.294 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5D24509B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6693, FileId: 0x590000000135c4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:13.363 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj46CE58900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6698, FileId: 0x3b0000000135ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.076 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCE104791F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6765, FileId: 0x1030000000135da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.182 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D162C987. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6772, FileId: 0x1040000000135da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.204 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj66ABF19F7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6781, FileId: 0x1e0000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.219 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5888679C5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6782, FileId: 0x1f0000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.301 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC41E0A943. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6787, FileId: 0x210000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.302 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9ED2DE9CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6786, FileId: 0x1070000000135da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.540 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj97CFE29A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6800, FileId: 0x230000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.542 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9FE473991. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6796, FileId: 0x61000000013805, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.563 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCD7237994. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6805, FileId: 0x240000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.573 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE9C8F7943. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6807, FileId: 0x1180000000135da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.587 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj15A8F791A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6810, FileId: 0x250000000137c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.660 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFD425791D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6819, FileId: 0x62000000013805, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.682 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj16C4F391E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6828, FileId: 0x2a600000000031e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.704 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD7425797E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6830, FileId: 0x45000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.718 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8537DA962. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6832, FileId: 0x46000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.743 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA2CC6B967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6837, FileId: 0x47000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.761 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF108F49E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6840, FileId: 0x48000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.796 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE4871D967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6846, FileId: 0x49000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.797 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj371BD5997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6847, FileId: 0x4a000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.807 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC734199B3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6850, FileId: 0x4b000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.846 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjABEB8495C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6854, FileId: 0x4d000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.909 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAF6C2592E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6856, FileId: 0x4e000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.937 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1EF4809A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6858, FileId: 0x4f000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:15.974 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB3C4B591E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6869, FileId: 0x50000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.060 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4463799EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6878, FileId: 0x3f000000013844, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.069 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj881944939. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6883, FileId: 0x53000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.184 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4F0FD8984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6887, FileId: 0x64000000013805, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.200 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj43230F9EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6888, FileId: 0x55000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.215 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj756A0E90A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6889, FileId: 0x56000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.231 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3B7CC297A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6890, FileId: 0x57000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.248 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF9C3219F1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6892, FileId: 0x58000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.295 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj257B049B8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6893, FileId: 0x65000000013805, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.316 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB0DC169D0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6894, FileId: 0x5a000000010078, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.373 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj57C91990D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6898, FileId: 0x17b000000000474, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:16.396 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD7AD99950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6901, FileId: 0x17c000000000474, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:27.496 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7145, FileId: 0xc400000000a418, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:27.557 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7147, FileId: 0x56000000010dd4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:13:27.707 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7153, FileId: 0x790000000130d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:14:27.815 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7942, FileId: 0x6900000000f4db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:16:20.385 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8646, FileId: 0x7f00000001b3f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:17:39.245 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-29T17:17:39.245 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-29T17:17:39.269 Job Notification: New process added to job (14996) 2026-04-29T17:17:39.274 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-29T17:17:39.278 Aggressive catchup quick scan threshold: 2910011842503 / 25920000000000 2026-04-29T17:17:39.282 Job Notification: New process added to job (3120) 2026-04-29T17:17:39.297 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:14996] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3120]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-29T17:17:39.348 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 36499262(ms) from now at 05:25 (03:25 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-29T17:17:39.393 Job Notification: New process added to job (9556) 2026-04-29T17:17:39.396 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-29T17:17:39.399 Job Notification: New process added to job (9616) 2026-04-29T17:17:39.408 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:9556] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:9616]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-29T17:17:39.791 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-29T17:17:39.792 [RTP] Duplicating the current plugin configuration object... 2026-04-29T17:17:39.792 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-29T17:17:39.792 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-29T17:17:39.792 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:17:39.792 [RTP] No config change detected. Not updating plugin configuration. 2026-04-29T17:17:39.792 [RTP] No config changes found. No configuration switch. 2026-04-29T17:17:39.792 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-29T17:17:45.080 Job Notification: Process exited from job (9556) 2026-04-29T17:17:45.082 Job Notification: Process exited from job (9616) 2026-04-29T17:17:45.151 Job Notification: Process exited from job (14996) 2026-04-29T17:17:45.152 Job Notification: Process exited from job (3120) 2026-04-29T17:23:18.286 [RTP] [Mini-filter] OpenWithoutRead notification (981, 10076, \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe) sent successfully. 2026-04-29T17:23:27.746 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #11161, FileId: 0x9000000001c58f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:23:27.791 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #11165, FileId: 0x53000000024ef9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:24:12.806 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #11343, FileId: 0x3f000000024ee6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:26:22.591 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #11434, FileId: 0xe200000000aace, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:27:44.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T17:27:51.067 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12304, FileId: 0x9f00000002503f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:27:52.236 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-29T17:27:52.236 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-29T17:27:52.236 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-29T17:27:52.236 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-29T17:27:52.236 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-29T17:27:52.316 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-04-29T17:27:52.336 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:AD7E54EA-2192-4BF5-8960-5A22BC2D11CE, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-29T17:27:52.336 Scheduled scan with Id AD7E54EA-2192-4BF5-8960-5A22BC2D11CE configured CPU priority: normal (LowCpuPriority: 0) 2026-04-29T17:27:52.336 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-29T17:27:52.336 [SFC] System file cache build is not needed (already completed) 2026-04-29T17:27:52.416 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-04-29T17:27:52.591 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-04-29T17:27:52.616 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-29T17:27:52.636 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-04-29T17:27:52.781 [AutoPurge] Cleanup Routine tasks have started. 2026-04-29T17:27:52.806 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-29T17:27:52.811 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-29T17:27:52.811 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-29-2026 17:27:52 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-29-2026 17:27:52 2026-04-29T17:27:52.841 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-29T17:27:52.841 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-29T17:27:52.841 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-29T17:27:52.841 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-29T17:27:52.846 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-29T17:27:53.096 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-04-29T17:27:53.617 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-04-29T17:27:53.649 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-04-29T17:27:53.741 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-04-29T17:27:53.761 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-04-29T17:27:54.239 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-04-29T17:27:54.326 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-04-29T17:27:54.361 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:27:54.371 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-29T17:27:54.371 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:27:54.477 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-29T17:27:54.501 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-04-29T17:27:54.696 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-04-29T17:27:54.738 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-04-29T17:27:54.806 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-04-29T17:27:55.001 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-04-29T17:27:55.191 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-04-29T17:27:55.361 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-04-29T17:27:55.566 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-29T17:27:55.577 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:27:55.609 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-04-29T17:27:55.871 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-04-29T17:27:55.971 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-04-29T17:27:56.537 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-04-29T17:27:56.887 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-04-29T17:27:56.942 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-04-29T17:27:57.376 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-04-29T17:27:57.576 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-04-29T17:27:58.126 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-04-29T17:27:58.151 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-29T17:27:58.226 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:27:58.476 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-29T17:27:58.601 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-29T17:27:58.761 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-04-29T17:27:58.986 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-04-29T17:27:59.071 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-04-29T17:27:59.087 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-04-29T17:27:59.126 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-29T17:27:59.571 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-04-29T17:27:59.677 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-29T17:27:59.911 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-04-29T17:28:00.109 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-04-29T17:28:00.766 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-04-29T17:28:00.786 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-04-29T17:28:01.083 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-29T17:28:01.156 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-04-29T17:28:01.781 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-04-29T17:28:01.819 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-04-29T17:28:01.819 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:01.826 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-04-29T17:28:01.899 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-04-29T17:28:01.979 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-04-29T17:28:02.101 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-04-29T17:28:02.446 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-04-29T17:28:02.576 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-04-29T17:28:02.666 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-04-29T17:28:02.691 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:02.712 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-04-29T17:28:02.756 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-04-29T17:28:02.876 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-29T17:28:02.946 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-04-29T17:28:02.971 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-04-29T17:28:02.986 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-04-29T17:28:03.326 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-04-29T17:28:03.591 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-04-29T17:28:03.596 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-04-29T17:28:03.919 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-04-29T17:28:03.996 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-04-29T17:28:04.588 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-04-29T17:28:04.836 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:04.941 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-29T17:28:05.281 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-04-29T17:28:05.306 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-04-29T17:28:05.779 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-04-29T17:28:05.859 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-04-29T17:28:05.866 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-04-29T17:28:05.986 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-04-29T17:28:05.996 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-29T17:28:06.036 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-04-29T17:28:06.461 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-04-29T17:28:06.516 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-29T17:28:06.631 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-04-29T17:28:06.671 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-04-29T17:28:06.836 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-04-29T17:28:06.996 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-04-29T17:28:07.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-04-29T17:28:07.116 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-04-29T17:28:07.261 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-04-29T17:28:07.581 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:07.939 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-04-29T17:28:07.996 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-04-29T17:28:08.006 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:08.083 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:08.846 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:08.947 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:09.296 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-04-29T17:28:09.341 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-04-29T17:28:09.501 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-04-29T17:28:09.603 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-04-29T17:28:09.656 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:09.671 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-04-29T17:28:10.081 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-04-29T17:28:10.176 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-04-29T17:28:10.268 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-04-29T17:28:10.366 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-04-29T17:28:10.386 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-04-29T17:28:10.506 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-04-29T17:28:10.661 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-04-29T17:28:10.796 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-04-29T17:28:10.881 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-04-29T17:28:10.906 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-04-29T17:28:10.916 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-04-29T17:28:11.181 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-04-29T17:28:11.186 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-04-29T17:28:11.356 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-04-29T17:28:11.909 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-04-29T17:28:12.196 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-04-29T17:28:12.260 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-04-29T17:28:12.711 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-04-29T17:28:12.791 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-04-29T17:28:12.856 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-04-29T17:28:12.927 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-04-29T17:28:13.051 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-04-29T17:28:13.056 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-29T17:28:13.221 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-04-29T17:28:13.446 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-04-29T17:28:13.455 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-04-29T17:28:13.736 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-04-29T17:28:13.869 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-04-29T17:28:14.188 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-04-29T17:28:14.316 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-29T17:28:14.486 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-04-29T17:28:14.887 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-04-29T17:28:14.976 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-04-29T17:28:15.011 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-04-29T17:28:15.271 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-04-29T17:28:15.287 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-29T17:28:15.421 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-04-29T17:28:15.496 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-04-29T17:28:15.686 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-04-29T17:28:15.806 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-04-29T17:28:15.815 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:16.111 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-04-29T17:28:16.401 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-04-29T17:28:16.437 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-04-29T17:28:16.479 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-29T17:28:16.597 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-04-29T17:28:16.903 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-04-29T17:28:16.980 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:17.001 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-04-29T17:28:17.139 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:17.726 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-04-29T17:28:17.881 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-04-29T17:28:17.996 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-04-29T17:28:18.396 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-04-29T17:28:18.426 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-04-29T17:28:18.441 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-04-29T17:28:18.756 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-04-29T17:28:19.026 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-04-29T17:28:19.061 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-04-29T17:28:19.225 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-04-29T17:28:19.381 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-04-29T17:28:19.391 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-04-29T17:28:19.626 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-04-29T17:28:19.811 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-04-29T17:28:19.831 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-04-29T17:28:19.951 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-29T17:28:20.366 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-04-29T17:28:20.440 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-04-29T17:28:20.451 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-04-29T17:28:20.696 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-04-29T17:28:21.283 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-04-29T17:28:21.441 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-04-29T17:28:21.537 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-04-29T17:28:21.569 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-04-29T17:28:21.759 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-04-29T17:28:21.861 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-04-29T17:28:21.906 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-29T17:28:22.047 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:22.186 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-04-29T17:28:22.361 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-04-29T17:28:22.501 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-04-29T17:28:22.746 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-04-29T17:28:23.011 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-04-29T17:28:23.037 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-04-29T17:28:23.136 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-04-29T17:28:23.891 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-04-29T17:28:24.423 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-04-29T17:28:24.455 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-29T17:28:24.536 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-04-29T17:28:24.576 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-04-29T17:28:25.237 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-04-29T17:28:25.777 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-04-29T17:28:25.841 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-04-29T17:28:26.063 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-04-29T17:28:26.349 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-04-29T17:28:26.401 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-04-29T17:28:26.763 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-04-29T17:28:26.851 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-04-29T17:28:26.916 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-04-29T17:28:26.961 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-04-29T17:28:27.076 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-04-29T17:28:27.521 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-04-29T17:28:27.609 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-04-29T17:28:27.901 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-04-29T17:28:27.960 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-04-29T17:28:27.971 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-04-29T17:28:28.761 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-29T17:28:29.081 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-04-29T17:28:29.261 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-04-29T17:28:29.511 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-04-29T17:28:29.642 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:29.681 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-04-29T17:28:29.690 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:29.746 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-04-29T17:28:29.876 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-04-29T17:28:29.941 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-04-29T17:28:30.026 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-04-29T17:28:30.131 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-04-29T17:28:30.153 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-04-29T17:28:30.166 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-04-29T17:28:30.217 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-04-29T17:28:30.226 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-04-29T17:28:30.509 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-29T17:28:30.516 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-04-29T17:28:30.566 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-04-29T17:28:30.666 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-04-29T17:28:30.801 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-04-29T17:28:31.306 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-04-29T17:28:31.596 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-04-29T17:28:31.876 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-04-29T17:28:32.041 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-04-29T17:28:32.131 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:32.319 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-04-29T17:28:32.669 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-04-29T17:28:32.749 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-04-29T17:28:32.938 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-04-29T17:28:33.049 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-04-29T17:28:33.301 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-04-29T17:28:33.406 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-04-29T17:28:33.477 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-04-29T17:28:33.531 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-04-29T17:28:33.551 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-04-29T17:28:33.557 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-04-29T17:28:33.637 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:33.986 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-04-29T17:28:34.001 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-04-29T17:28:34.241 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-04-29T17:28:34.556 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-04-29T17:28:34.718 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-04-29T17:28:35.381 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-04-29T17:28:35.851 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-04-29T17:28:35.926 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-04-29T17:28:35.991 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-04-29T17:28:36.791 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-29T17:28:37.191 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-04-29T17:28:37.586 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-04-29T17:28:37.636 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\systemresources\mmcndmgr.dll.mun", hr=0x800710da 2026-04-29T17:28:37.886 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-04-29T17:28:38.221 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-04-29T17:28:38.308 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-04-29T17:28:38.351 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-04-29T17:28:38.476 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-04-29T17:28:38.563 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-04-29T17:28:38.596 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-04-29T17:28:38.751 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-04-29T17:28:38.861 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-04-29T17:28:39.105 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-04-29T17:28:39.141 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-04-29T17:28:39.966 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-04-29T17:28:40.271 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-04-29T17:28:40.391 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:40.538 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-04-29T17:28:41.006 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-04-29T17:28:41.121 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-04-29T17:28:41.186 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-04-29T17:28:41.216 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-04-29T17:28:41.299 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-04-29T17:28:41.326 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:41.476 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-04-29T17:28:41.546 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-04-29T17:28:41.667 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-04-29T17:28:41.741 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-04-29T17:28:41.851 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:41.970 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-04-29T17:28:42.369 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-04-29T17:28:42.471 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-04-29T17:28:42.687 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-04-29T17:28:42.956 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-04-29T17:28:43.061 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-04-29T17:28:43.467 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-04-29T17:28:43.591 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-04-29T17:28:43.911 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-04-29T17:28:44.321 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-04-29T17:28:44.791 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-04-29T17:28:45.146 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-04-29T17:28:45.286 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-04-29T17:28:45.412 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-04-29T17:28:46.011 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-04-29T17:28:46.223 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-04-29T17:28:46.246 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-04-29T17:28:46.351 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:46.496 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-04-29T17:28:46.511 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-04-29T17:28:47.591 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-04-29T17:28:47.636 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-04-29T17:28:47.721 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-04-29T17:28:48.046 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-04-29T17:28:48.119 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-04-29T17:28:48.376 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-04-29T17:28:48.471 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-04-29T17:28:48.519 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-04-29T17:28:48.541 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-04-29T17:28:48.695 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-04-29T17:28:49.491 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-04-29T17:28:49.747 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-04-29T17:28:49.763 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-04-29T17:28:49.821 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-04-29T17:28:50.067 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-04-29T17:28:50.176 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-04-29T17:28:50.541 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-04-29T17:28:50.547 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:50.550 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-04-29T17:28:50.826 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-04-29T17:28:51.006 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-04-29T17:28:51.616 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-04-29T17:28:51.766 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-04-29T17:28:52.101 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-04-29T17:28:52.383 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-04-29T17:28:52.421 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-04-29T17:28:52.479 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-04-29T17:28:53.481 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-04-29T17:28:53.520 Engine:Setting original file name "_Project Import.exe" for "c:\program files\microsoft office\root\office16\projimpt.exe", hr=0x800710da 2026-04-29T17:28:53.656 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-04-29T17:28:53.701 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-04-29T17:28:53.911 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-04-29T17:28:53.971 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-04-29T17:28:54.066 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-04-29T17:28:54.146 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-04-29T17:28:54.326 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-04-29T17:28:54.347 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-04-29T17:28:54.379 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-04-29T17:28:54.618 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-04-29T17:28:54.666 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-04-29T17:28:54.746 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-04-29T17:28:54.786 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-04-29T17:28:54.791 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-04-29T17:28:55.121 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-04-29T17:28:55.281 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-04-29T17:28:55.341 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-04-29T17:28:55.371 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-04-29T17:28:55.756 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-04-29T17:28:55.886 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-04-29T17:28:55.910 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-04-29T17:28:55.926 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-04-29T17:28:56.246 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-04-29T17:28:56.666 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-04-29T17:28:56.781 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:56.911 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-04-29T17:28:57.046 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-04-29T17:28:57.140 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-04-29T17:28:57.316 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-04-29T17:28:57.427 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-04-29T17:28:57.546 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-04-29T17:28:57.686 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-04-29T17:28:57.746 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-04-29T17:28:57.786 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-04-29T17:28:58.051 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-04-29T17:28:58.156 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-04-29T17:28:58.171 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-04-29T17:28:58.186 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-04-29T17:28:58.821 Engine:Setting original file name "uasp.sys" for "c:\windows\system32\driverstore\filerepository\uaspstor.inf_amd64_ead2ec56d8760a84\uaspstor.sys", hr=0x800710da 2026-04-29T17:28:58.866 OriginalFileName Maintenance::9919 files in Moac, 248 skipped (cached), 1 filename set 2026-04-29T17:28:58.866 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-29T17:29:01.626 Engine:Triggered AR EMS scan 2026-04-29T17:29:01.636 Engine:EMS scan for process: lsass pid: 748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.671 Engine:EMS scan for process: svchost pid: 956, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.696 Engine:EMS scan for process: svchost pid: 680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.701 Engine:EMS scan for process: svchost pid: 552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.706 Engine:EMS scan for process: svchost pid: 1176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.716 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.721 Engine:EMS scan for process: svchost pid: 1336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.727 Engine:EMS scan for process: svchost pid: 1344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.727 Engine:EMS scan for process: svchost pid: 1364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.741 Engine:EMS scan for process: svchost pid: 1372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.746 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.751 Engine:EMS scan for process: svchost pid: 1536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.759 Engine:EMS scan for process: svchost pid: 1544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.759 Engine:EMS scan for process: svchost pid: 1580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.766 Engine:EMS scan for process: svchost pid: 1616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.776 Engine:EMS scan for process: svchost pid: 1624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.781 Engine:EMS scan for process: svchost pid: 1744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.781 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.786 Engine:EMS scan for process: svchost pid: 1900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.791 Engine:EMS scan for process: svchost pid: 2136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.796 Engine:EMS scan for process: svchost pid: 2212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.801 Engine:EMS scan for process: svchost pid: 2324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.801 Engine:EMS scan for process: svchost pid: 2332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.807 Engine:EMS scan for process: svchost pid: 2356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.807 Engine:EMS scan for process: svchost pid: 2364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.816 Engine:EMS scan for process: svchost pid: 2492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.821 Engine:EMS scan for process: svchost pid: 2544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.823 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.826 Engine:EMS scan for process: svchost pid: 2632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.831 Engine:EMS scan for process: svchost pid: 2676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.836 Engine:EMS scan for process: svchost pid: 2964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.840 Engine:EMS scan for process: svchost pid: 2108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.846 Engine:EMS scan for process: svchost pid: 2260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.851 Engine:EMS scan for process: svchost pid: 3100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.861 Engine:EMS scan for process: svchost pid: 3520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.866 Engine:EMS scan for process: svchost pid: 3708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.872 Engine:EMS scan for process: svchost pid: 3716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.876 Engine:EMS scan for process: svchost pid: 3860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.881 Engine:EMS scan for process: svchost pid: 3880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.891 Engine:EMS scan for process: svchost pid: 3924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.919 Engine:EMS scan for process: svchost pid: 3932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.926 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.931 Engine:EMS scan for process: svchost pid: 4208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.936 Engine:EMS scan for process: svchost pid: 4332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.951 Engine:EMS scan for process: svchost pid: 4372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.961 Engine:EMS scan for process: svchost pid: 4616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.967 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.972 Engine:EMS scan for process: svchost pid: 4684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.976 Engine:EMS scan for process: svchost pid: 4780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.983 Engine:EMS scan for process: svchost pid: 5248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.986 Engine:EMS scan for process: svchost pid: 6016, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.991 Engine:EMS scan for process: dllhost pid: 6024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.991 Engine:EMS scan for process: svchost pid: 6256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.996 Engine:EMS scan for process: svchost pid: 6724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:01.999 Engine:EMS scan for process: svchost pid: 6728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.006 Engine:EMS scan for process: svchost pid: 6828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.015 Engine:EMS scan for process: svchost pid: 5620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.021 Engine:EMS scan for process: svchost pid: 1920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.031 Engine:EMS scan for process: svchost pid: 5572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.036 Engine:EMS scan for process: svchost pid: 7152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.036 Engine:EMS scan for process: svchost pid: 5392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.041 Engine:EMS scan for process: svchost pid: 1848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.051 Engine:EMS scan for process: svchost pid: 2892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.063 Engine:EMS scan for process: svchost pid: 3132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.071 Engine:EMS scan for process: svchost pid: 6040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.073 Engine:EMS scan for process: explorer pid: 5900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.141 Engine:EMS scan for process: svchost pid: 7160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.146 Engine:EMS scan for process: svchost pid: 3944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.151 Engine:EMS scan for process: svchost pid: 6768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.156 Engine:EMS scan for process: svchost pid: 8912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.159 Engine:EMS scan for process: dllhost pid: 9168, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.159 Engine:EMS scan for process: svchost pid: 9368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.171 Engine:EMS scan for process: svchost pid: 13908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.176 Engine:EMS scan for process: svchost pid: 13396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.186 Engine:EMS scan for process: svchost pid: 8760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.191 Engine:EMS scan for process: svchost pid: 14788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.196 Engine:EMS scan for process: svchost pid: 11788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.201 Engine:EMS scan for process: svchost pid: 6896, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.207 Engine:EMS scan for process: svchost pid: 14672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.207 Engine:EMS scan for process: svchost pid: 7532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:29:02.216 Engine:EMS scan for process: svchost pid: 5920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-29T17:32:59.086 QuickScan:ScanID:AD7E54EA-2192-4BF5-8960-5A22BC2D11CE: Quick scan finished with error 0 2026-04-29T17:32:59.606 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-29T17:32:59.606 [RTP] Duplicating the current plugin configuration object... 2026-04-29T17:32:59.606 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-29T17:32:59.606 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-29T17:32:59.606 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-29T17:32:59.606 [RTP] No config change detected. Not updating plugin configuration. 2026-04-29T17:32:59.606 [RTP] No config changes found. No configuration switch. 2026-04-29T17:32:59.606 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-29T17:33:01.115 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:33:01.116 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-29T17:33:01.116 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-29T17:38:34.309 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #13450, FileId: 0xde00000000146c, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T17:38:36.456 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-04-29T17:38:36.456 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-04-29T17:38:36.456 [RTP] Duplicating the current plugin configuration object... 2026-04-29T17:38:36.456 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-29T17:38:36.456 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-29T17:38:36.456 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-29T17:38:36.456 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-29T17:38:37.837 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-04-29T17:38:37.916 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-04-29T17:38:38.137 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-04-29T17:38:38.137 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-04-29T17:42:49.237 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T17:57:54.247 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T18:02:55.467 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23725, FileId: 0x13f000000006b38, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T18:07:39.237 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-29T18:10:23.857 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24180, FileId: 0xdd000000013a9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-29T18:12:59.247 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T18:28:04.248 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T18:43:09.248 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T18:58:14.248 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T19:08:08.798 ProcessImageName: CCC.exe, Pid: 2016, TotalTime: 29094, Count: 579, MaxTime: 1750, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: explorer.exe, Pid: 5900, TotalTime: 6561, Count: 124, MaxTime: 1406, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: AcroCEF.exe, Pid: 13756, TotalTime: 4164, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 28% 2026-04-29T19:08:08.798 ProcessImageName: OneDriveUpdaterService.exe, Pid: 9040, TotalTime: 3559, Count: 6, MaxTime: 1781, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 9% 2026-04-29T19:08:08.798 ProcessImageName: dllhost.exe, Pid: 9168, TotalTime: 3207, Count: 95, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 61% 2026-04-29T19:08:08.798 ProcessImageName: AsPowerBar.exe, Pid: 10480, TotalTime: 2973, Count: 18, MaxTime: 1218, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 6% 2026-04-29T19:08:08.798 ProcessImageName: DipAwayMode.exe, Pid: 2500, TotalTime: 2882, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: firefox.exe, Pid: 13648, TotalTime: 2056, Count: 171, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 52% 2026-04-29T19:08:08.798 ProcessImageName: MOM.exe, Pid: 11636, TotalTime: 2039, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: DeviceCensus.exe, Pid: 9980, TotalTime: 1654, Count: 6, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 27% 2026-04-29T19:08:08.798 ProcessImageName: taskhostw.exe, Pid: 9976, TotalTime: 1645, Count: 24, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveSetup.exe, EstimatedImpact: 28% 2026-04-29T19:08:08.798 ProcessImageName: AISuite3.exe, Pid: 2572, TotalTime: 1397, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 12% 2026-04-29T19:08:08.798 ProcessImageName: websockify.exe, Pid: 11872, TotalTime: 926, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-04-29T19:08:08.798 ProcessImageName: WmiPrvSE.exe, Pid: 3120, TotalTime: 679, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-04-29T19:08:08.798 ProcessImageName: sdiagnhost.exe, Pid: 12440, TotalTime: 569, Count: 27, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\c1881247023b94d4c29e588b4e115061\Microsoft.PowerShell.Commands.Management.ni.dll, EstimatedImpact: 29% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 10356, TotalTime: 524, Count: 13, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6253.tmp, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: firefox.exe, Pid: 13420, TotalTime: 482, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13436, EstimatedImpact: 8% 2026-04-29T19:08:08.798 ProcessImageName: powershell.exe, Pid: 8432, TotalTime: 432, Count: 24, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-04-29T19:08:08.798 ProcessImageName: FileCoAuth.exe, Pid: 9124, TotalTime: 409, Count: 34, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0002\FileSyncSessions.dll, EstimatedImpact: 5% 2026-04-29T19:08:08.798 ProcessImageName: AdobeCollabSync.exe, Pid: 14584, TotalTime: 394, Count: 32, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: TeamViewer.exe, Pid: 7976, TotalTime: 348, Count: 32, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\prefs.js, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: FileCoAuth.exe, Pid: 5936, TotalTime: 318, Count: 19, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-29T19:08:08.798 ProcessImageName: backgroundTaskHost.exe, Pid: 8940, TotalTime: 315, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 10% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 1336, TotalTime: 305, Count: 23, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 956, TotalTime: 281, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 680, TotalTime: 280, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: TabTip.exe, Pid: 6904, TotalTime: 248, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 49% 2026-04-29T19:08:08.798 ProcessImageName: AdobeARM.exe, Pid: 6964, TotalTime: 226, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\UCB\AdobeARM_UCB.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: FileSyncConfig.exe, Pid: 13408, TotalTime: 212, Count: 20, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveTelemetryStable.dll, EstimatedImpact: 80% 2026-04-29T19:08:08.798 ProcessImageName: taskhostw.exe, Pid: 7888, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_5f00f307-74d8-4b20-b879-6aac0076f3f9\result\results.xsl, EstimatedImpact: 69% 2026-04-29T19:08:08.798 ProcessImageName: backgroundTaskHost.exe, Pid: 10152, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1776496858, EstimatedImpact: 15% 2026-04-29T19:08:08.798 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 2332, TotalTime: 155, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 53% 2026-04-29T19:08:08.798 ProcessImageName: ngentask.exe, Pid: 8528, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: RuntimeBroker.exe, Pid: 8904, TotalTime: 140, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDrive.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: backgroundTaskHost.exe, Pid: 12080, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\310091\1777051031, EstimatedImpact: 16% 2026-04-29T19:08:08.798 ProcessImageName: SecurityHealthHost.exe, Pid: 8428, TotalTime: 135, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 11% 2026-04-29T19:08:08.798 ProcessImageName: RuntimeBroker.exe, Pid: 9628, TotalTime: 121, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\fcd069ab-a45a-420d-928c-6420118fd2d6.down_data, EstimatedImpact: 3% 2026-04-29T19:08:08.798 ProcessImageName: WhatsApp.Root.exe, Pid: 11928, TotalTime: 120, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat.LOG1, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: armsvc.exe, Pid: 4224, TotalTime: 120, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 41% 2026-04-29T19:08:08.798 ProcessImageName: ngentask.exe, Pid: 11944, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 1900, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: Acrobat.exe, Pid: 5860, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 8% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 9396, TotalTime: 106, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: firefox.exe, Pid: 12440, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 6% 2026-04-29T19:08:08.798 ProcessImageName: SrTasks.exe, Pid: 1892, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 3% 2026-04-29T19:08:08.798 ProcessImageName: SDXHelper.exe, Pid: 14224, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: ngentask.exe, Pid: 13652, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: ngentask.exe, Pid: 1084, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: OneDriveSetup.exe, Pid: 1664, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDrive.Sync.Service.exe, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: taskhostw.exe, Pid: 9244, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-04-29T19:08:08.798 ProcessImageName: PhoneExperienceHost.exe, Pid: 10108, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 9708, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-2002.log->(UTF-16LE), EstimatedImpact: 3% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 1848, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: taskhostw.exe, Pid: 768, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 53% 2026-04-29T19:08:08.798 ProcessImageName: SDXHelper.exe, Pid: 996, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: AdobeARM.exe, Pid: 11904, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\Execute\20283\RdrServicesUpdater2_x64.exe, EstimatedImpact: 5% 2026-04-29T19:08:08.798 ProcessImageName: AcroCEF.exe, Pid: 14148, TotalTime: 61, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: FileCoAuth.exe, Pid: 3140, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-29.1724.3140.1.aodl, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: AcroCEF.exe, Pid: 14820, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: runonce.exe, Pid: 11692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: Acrobat.exe, Pid: 13852, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-04-29T19:08:08.798 ProcessImageName: BackgroundTransferHost.exe, Pid: 1136, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\577e60ec-ed17-433a-b90c-62ec15e56563.up_meta_secure, EstimatedImpact: 15% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 2392, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-1927.log, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 9180, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-2010.log, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: backgroundTaskHost.exe, Pid: 9852, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 41% 2026-04-29T19:08:08.798 ProcessImageName: RuntimeBroker.exe, Pid: 8780, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 22% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 2512, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-1916.log, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: winlogon.exe, Pid: 4260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\pin_eoa.cur, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: OfficeC2RClient.exe, Pid: 12816, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: SDXHelper.exe, Pid: 2124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 3% 2026-04-29T19:08:08.798 ProcessImageName: svchost.exe, Pid: 13396, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 7060, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 13568, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 6% 2026-04-29T19:08:08.798 ProcessImageName: backgroundTaskHost.exe, Pid: 9288, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: AdobeCollabSync.exe, Pid: 6936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Locale\de_DE\AdobeCollabSync.DEU, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 5556, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\windows-app-web-link[1], EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: RUXIMICS.exe, Pid: 7416, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: SDXHelper.exe, Pid: 7044, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-04-29T19:08:08.798 ProcessImageName: DismHost.exe, Pid: 14880, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 1% 2026-04-29T19:08:08.798 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 9584, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: ADNotificationManager.exe, Pid: 10852, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\3N7TXZ6E\UNKNOWN[1].htm, EstimatedImpact: 0% 2026-04-29T19:08:08.798 ProcessImageName: AggregatorHost.exe, Pid: 5520, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-29T19:13:19.248 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T19:28:24.239 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T19:43:29.249 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T19:58:34.239 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T20:13:39.250 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T20:28:44.240 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T20:43:49.240 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T20:58:54.251 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-29T21:08:08.801 ProcessImageName: CCC.exe, Pid: 2016, TotalTime: 29094, Count: 579, MaxTime: 1750, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: explorer.exe, Pid: 5900, TotalTime: 6561, Count: 124, MaxTime: 1406, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: AcroCEF.exe, Pid: 13756, TotalTime: 4164, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 28% 2026-04-29T21:08:08.801 ProcessImageName: OneDriveUpdaterService.exe, Pid: 9040, TotalTime: 3559, Count: 6, MaxTime: 1781, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 9% 2026-04-29T21:08:08.801 ProcessImageName: dllhost.exe, Pid: 9168, TotalTime: 3207, Count: 95, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 61% 2026-04-29T21:08:08.801 ProcessImageName: AsPowerBar.exe, Pid: 10480, TotalTime: 2973, Count: 18, MaxTime: 1218, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 6% 2026-04-29T21:08:08.801 ProcessImageName: DipAwayMode.exe, Pid: 2500, TotalTime: 2882, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: firefox.exe, Pid: 13648, TotalTime: 2056, Count: 171, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 52% 2026-04-29T21:08:08.801 ProcessImageName: MOM.exe, Pid: 11636, TotalTime: 2039, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: DeviceCensus.exe, Pid: 9980, TotalTime: 1654, Count: 6, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 27% 2026-04-29T21:08:08.801 ProcessImageName: taskhostw.exe, Pid: 9976, TotalTime: 1645, Count: 24, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveSetup.exe, EstimatedImpact: 28% 2026-04-29T21:08:08.801 ProcessImageName: AISuite3.exe, Pid: 2572, TotalTime: 1397, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 12% 2026-04-29T21:08:08.801 ProcessImageName: websockify.exe, Pid: 11872, TotalTime: 926, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-04-29T21:08:08.801 ProcessImageName: WmiPrvSE.exe, Pid: 3120, TotalTime: 679, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-04-29T21:08:08.801 ProcessImageName: sdiagnhost.exe, Pid: 12440, TotalTime: 569, Count: 27, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\c1881247023b94d4c29e588b4e115061\Microsoft.PowerShell.Commands.Management.ni.dll, EstimatedImpact: 29% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 10356, TotalTime: 524, Count: 13, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6253.tmp, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: firefox.exe, Pid: 13420, TotalTime: 482, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13436, EstimatedImpact: 8% 2026-04-29T21:08:08.801 ProcessImageName: powershell.exe, Pid: 8432, TotalTime: 432, Count: 24, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-04-29T21:08:08.801 ProcessImageName: FileCoAuth.exe, Pid: 9124, TotalTime: 409, Count: 34, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0002\FileSyncSessions.dll, EstimatedImpact: 5% 2026-04-29T21:08:08.801 ProcessImageName: AdobeCollabSync.exe, Pid: 14584, TotalTime: 394, Count: 32, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: TeamViewer.exe, Pid: 7976, TotalTime: 348, Count: 32, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\prefs.js, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 1336, TotalTime: 335, Count: 25, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: FileCoAuth.exe, Pid: 5936, TotalTime: 318, Count: 19, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-29T21:08:08.801 ProcessImageName: backgroundTaskHost.exe, Pid: 8940, TotalTime: 315, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 10% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 956, TotalTime: 281, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.062.0402.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 680, TotalTime: 280, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: TabTip.exe, Pid: 6904, TotalTime: 248, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 49% 2026-04-29T21:08:08.801 ProcessImageName: AdobeARM.exe, Pid: 6964, TotalTime: 226, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\UCB\AdobeARM_UCB.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: dllhost.exe, Pid: 6024, TotalTime: 215, Count: 8, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01000C9.log, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: FileSyncConfig.exe, Pid: 13408, TotalTime: 212, Count: 20, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveTelemetryStable.dll, EstimatedImpact: 80% 2026-04-29T21:08:08.801 ProcessImageName: taskhostw.exe, Pid: 7888, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_5f00f307-74d8-4b20-b879-6aac0076f3f9\result\results.xsl, EstimatedImpact: 69% 2026-04-29T21:08:08.801 ProcessImageName: backgroundTaskHost.exe, Pid: 10152, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1776496858, EstimatedImpact: 15% 2026-04-29T21:08:08.801 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 171, Count: 2, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 2332, TotalTime: 155, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\BOOTVID.DLL, EstimatedImpact: 53% 2026-04-29T21:08:08.801 ProcessImageName: ngentask.exe, Pid: 8528, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: RuntimeBroker.exe, Pid: 8904, TotalTime: 140, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDrive.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: backgroundTaskHost.exe, Pid: 12080, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\310091\1777051031, EstimatedImpact: 16% 2026-04-29T21:08:08.801 ProcessImageName: SecurityHealthHost.exe, Pid: 8428, TotalTime: 135, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 11% 2026-04-29T21:08:08.801 ProcessImageName: RuntimeBroker.exe, Pid: 9628, TotalTime: 121, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\fcd069ab-a45a-420d-928c-6420118fd2d6.down_data, EstimatedImpact: 3% 2026-04-29T21:08:08.801 ProcessImageName: WhatsApp.Root.exe, Pid: 11928, TotalTime: 120, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat.LOG1, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: armsvc.exe, Pid: 4224, TotalTime: 120, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 41% 2026-04-29T21:08:08.801 ProcessImageName: ngentask.exe, Pid: 11944, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 1900, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: Acrobat.exe, Pid: 5860, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 8% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 9396, TotalTime: 106, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: firefox.exe, Pid: 12440, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 6% 2026-04-29T21:08:08.801 ProcessImageName: SrTasks.exe, Pid: 1892, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\restore\MachineGuid.txt, EstimatedImpact: 3% 2026-04-29T21:08:08.801 ProcessImageName: SDXHelper.exe, Pid: 14224, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: ngentask.exe, Pid: 13652, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: ngentask.exe, Pid: 1084, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: OneDriveSetup.exe, Pid: 1664, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDrive.Sync.Service.exe, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: taskhostw.exe, Pid: 9244, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-04-29T21:08:08.801 ProcessImageName: PhoneExperienceHost.exe, Pid: 10108, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 9708, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-2002.log->(UTF-16LE), EstimatedImpact: 3% 2026-04-29T21:08:08.801 ProcessImageName: taskhostw.exe, Pid: 768, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 53% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 1848, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: SDXHelper.exe, Pid: 996, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: AdobeARM.exe, Pid: 11904, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\Execute\20283\RdrServicesUpdater2_x64.exe, EstimatedImpact: 5% 2026-04-29T21:08:08.801 ProcessImageName: AcroCEF.exe, Pid: 14148, TotalTime: 61, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: FileCoAuth.exe, Pid: 3140, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-29.1724.3140.1.aodl, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: AcroCEF.exe, Pid: 14820, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: runonce.exe, Pid: 11692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: Acrobat.exe, Pid: 13852, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-04-29T21:08:08.801 ProcessImageName: BackgroundTransferHost.exe, Pid: 1136, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\577e60ec-ed17-433a-b90c-62ec15e56563.up_meta_secure, EstimatedImpact: 15% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 9180, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-2010.log, EstimatedImpact: 2% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 2392, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-1927.log, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: backgroundTaskHost.exe, Pid: 9852, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 41% 2026-04-29T21:08:08.801 ProcessImageName: RuntimeBroker.exe, Pid: 8780, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 22% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 2512, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260429-1916.log, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: winlogon.exe, Pid: 4260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\pin_eoa.cur, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: OfficeC2RClient.exe, Pid: 12816, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: SDXHelper.exe, Pid: 2124, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 3% 2026-04-29T21:08:08.801 ProcessImageName: svchost.exe, Pid: 13396, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: SDXHelper.exe, Pid: 8328, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-29T21:08:08.801 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 7060, TotalTime: 15, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 13568, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 6% 2026-04-29T21:08:08.801 ProcessImageName: backgroundTaskHost.exe, Pid: 9288, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: AdobeCollabSync.exe, Pid: 6936, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Locale\de_DE\AdobeCollabSync.DEU, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: RUXIMICS.exe, Pid: 7416, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 5556, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\windows-app-web-link[1], EstimatedImpact: 0% 2026-04-29T21:08:08.801 ProcessImageName: DismHost.exe, Pid: 14880, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 1% 2026-04-29T21:08:08.801 ProcessImageName: SDXHelper.exe, Pid: 7044, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 04-30-2026 09:07:13 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 04/30/2026 09:07:13.896271300 UTC (14609 ms since boot) 2026-04-30T09:07:13.908 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-04-30T09:07:13.908 WARNING: the previous service shutdown was not expected. 2026-04-30T09:07:13.973 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-30T09:07:13.973 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-04-30T09:07:14.014 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260430-090714-00000003-fffffffeffffffff.bin ... 2026-04-30T09:07:14.092 [WPP] Trace session started - MpWppTracing-20260430-090714-00000003-fffffffeffffffff.bin 2026-04-30T09:07:14.092 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-04-30T09:07:14.092 [RbM] Rollback manager succesfully initialized. 2026-04-30T09:07:14.092 [RbM] Rollback manager EnableRollbackManager called. 2026-04-30T09:07:14.108 [RbM] Rollback manager EnableRollbackManager completed. 2026-04-30T09:07:14.108 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-04-30T09:07:14.108 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-04-30T09:07:14.108 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-04-30T09:07:14.108 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-04-30T09:07:14.108 MdCoreSvc is supported in this platform and OS 2026-04-30T09:07:14.108 MdCoreSvc is supported in this platform and OS 2026-04-30T09:07:14.108 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-30T09:07:14.108 [PlatUpd] Starting MdCoreSvc service 2026-04-30T09:07:14.155 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-04-30T09:07:17.624 [PlatUpd] MpAddMpUxRegistration succeeded 2026-04-30T09:07:17.624 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-04-30T09:07:17.624 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-04-30T09:07:17.624 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-04-30T09:07:17.624 [PlatUpd] CSP platform update started 2026-04-30T09:07:17.624 [PlatUpd] Defender MDM CSP platform update not required 2026-04-30T09:07:17.624 [PlatUpd] WMI/PS provider platform update started 2026-04-30T09:07:17.624 [PlatUpd] WMI/PS provider platform update not required 2026-04-30T09:07:17.624 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-04-30T09:07:17.624 MdCoreSvc is supported in this platform and OS 2026-04-30T09:07:17.624 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-04-30T09:07:17.624 [PlatUpd] Starting MdCoreSvc service 2026-04-30T09:07:17.624 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-04-30T09:07:17.624 [TS] Troublshooting mode is not available! 2026-04-30T09:07:17.624 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-30T09:07:17.624 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-04-30T09:07:17.639 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-04-30T09:07:17.639 [Service] Enabling AutoLoggers ... 2026-04-30T09:07:17.639 [Service] Enabling AMSI registration ... 2026-04-30T09:07:17.639 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-04-30T09:07:17.671 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 44880 Number of invalid entries is 0 Number of inserts issued is 1577353 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6461 Number of lookups is 107547016 Number of lookup misses is 5159777 Number of fast lookup misses is 54814249 Number of false fast lookups is 5159772 Number of invalidations is 731246 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-04-30T09:07:17.671 Verifying license file... 2026-04-30T09:07:17.671 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll]. File not in cache (0x1) 2026-04-30T09:07:17.686 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] 2026-04-30T09:07:17.702 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-04-30T09:07:17.702 Loaded module#0 MpComServer. 2026-04-30T09:07:17.702 Loaded module#1 StartupPolicies. 2026-04-30T09:07:17.702 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-04-30T09:07:17.702 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-30T09:07:17.717 COM server initialized successfully. 2026-04-30T09:07:17.717 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-04-30T09:07:17.733 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-04-30T09:07:17.733 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-04-30T09:07:17.749 [RTP] [RTP] FilterCommunicator object 0x00000174366A3310 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-30T09:07:17.749 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-04-30T09:07:17.749 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-30T09:07:17.749 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-30T09:07:17.749 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-04-30T09:07:17.749 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-30T09:07:17.749 [RTP] [RTP] FilterCommunicator object 0x00000174366A3520 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-30T09:07:17.749 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-04-30T09:07:17.749 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-04-30T09:07:17.749 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-04-30T09:07:17.749 [RTP] [RTP] StartCommunication 0x00000174366A3310 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-04-30T09:07:17.749 [init][RTP] RTPPlugin initialization completed 2026-04-30T09:07:17.749 OS boot count = 2 2026-04-30T09:07:17.749 OS Install = 0 2026-04-30T09:07:17.764 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-04-30T09:07:17.764 [KSL] Entering CKSLEngine::Initialize. 2026-04-30T09:07:17.764 [KSL] Leaving CKSLEngine::Initialize(0). 2026-04-30T09:07:17.764 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-04-30T09:07:17.764 [KSL] MpInstallKslD: hr=0x1 2026-04-30T09:07:17.764 [KSL] MpRegisterKslD: hr=0 2026-04-30T09:07:17.764 [KSL] MpStartKslD: hr=0 2026-04-30T09:07:17.764 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-30T09:07:17.764 Loading engine... 2026-04-30T09:07:17.780 Verifying engine and signature files (source: 1) ... 2026-04-30T09:07:17.780 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpengine.dll] due to PPL. 2026-04-30T09:07:17.780 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasbase.vdm]. File not in cache (0x1) 2026-04-30T09:07:18.718 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasbase.vdm] 2026-04-30T09:07:18.718 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-30T09:07:18.733 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasdlta.vdm] 2026-04-30T09:07:18.733 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavbase.vdm]. File not in cache (0x1) 2026-04-30T09:07:19.155 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavbase.vdm] 2026-04-30T09:07:19.155 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-30T09:07:19.186 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpavdlta.vdm] 2026-04-30T09:07:19.218 [Engine] IsHybridMode: 0 2026-04-30T09:07:19.218 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-30T09:07:19.249 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-02E3AAD8667BDE71092BADD1689704D926C359B4.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-30T09:07:25.374 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-30T09:07:25.374 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-30T09:07:25.374 [Engine] New active engine 00007FFB033F8020 (no old engine). Number of active engines: 1 2026-04-30T09:07:25.389 EngineInit:Global ASOC is enabled 2026-04-30T09:07:25.389 EngineInit:ASOO is enabled for developer volumes 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.467 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:07:25.499 MpWriteUupSignatureVersion 1.449.357.0, hr = 0 2026-04-30T09:07:25.499 [SigStatUpd] CSignatureStatus: back to good 2026-04-30T09:07:25.499 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-30T09:07:25.530 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-30T09:07:25.530 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-30T09:07:25.530 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-30T09:07:25.530 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-30T09:07:25.530 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-30T09:07:25.530 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-30T09:07:25.530 [Plugin] Initializing RTP plugin state... 2026-04-30T09:07:25.530 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-30T09:07:25.530 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2042 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11488 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2305 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-30T09:07:25.530 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8} 2026-04-30T09:07:25.530 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:07:25.530 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:07:25.530 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:07:25.530 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-30T09:07:25.546 MdCoreSvc is supported in this platform and OS 2026-04-30T09:07:25.546 Engine loaded! 2026-04-30T09:07:25.546 [DLP] Create FeatureControlState instance 2026-04-30T09:07:25.546 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-04-30T09:07:25.546 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-04-30T09:07:25.546 RegisterSModeChangeListener: hr = 0x1 2026-04-30T09:07:25.546 RegisterHybridModeChangeListener: hr = 0 2026-04-30T09:07:25.561 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-04-30T09:07:25.561 [SigReleaseHb] Initialized with Stage 0 2026-04-30T09:07:25.561 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-04-30T09:07:25.561 [SCC][CID=26281_5376] Initializing ... 2026-04-30T09:07:25.561 [SCC][CID=26281_5376] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-04-30T09:07:25.561 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-30T09:07:25.561 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-30T09:07:25.561 [NRI] Stopping NIS service ... 2026-04-30T09:07:25.561 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-04-30T09:07:25.561 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). 2026-04-30T09:07:25.561 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.357.0 AV Signature Version: 1.449.357.0 ************************************************************ 2026-04-30T09:07:25.561 Resource usage Monitoring is enabled 2026-04-30T09:07:25.561 Job Notification: New process added to job (4508) 2026-04-30T09:07:25.561 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-04-30T09:07:25.592 Job Notification: New process added to job (7020) 2026-04-30T09:07:25.592 Job Notification: New process added to job (7052) 2026-04-30T09:07:25.608 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7020] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7052]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-30T09:07:25.655 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-30T09:07:25.655 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-30T09:07:25.671 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-30T09:07:25.671 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-30T09:07:25.671 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-30T09:07:25.671 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-30T09:07:25.671 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-30T09:07:25.671 [RTP] Generating the base plugin configuration ... 2026-04-30T09:07:25.671 [RTP] Path exclusion changed, new size in bytes: 2 2026-04-30T09:07:25.671 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:07:25.671 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-04-30T09:07:25.671 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-04-30T09:07:25.671 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:07:25.671 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-30T09:07:25.671 Job Notification: Process exited from job (7020) 2026-04-30T09:07:25.671 [RTP] [RTP] StartCommunication 0x00000174366A3520 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-04-30T09:07:25.671 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-04-30T09:07:25.671 Job Notification: Process exited from job (7052) 2026-04-30T09:07:25.671 [PlatUpd] WMI MOF schema validation completed successfully 2026-04-30T09:07:25.671 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-04-30T09:07:25.999 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-30T09:07:25.999 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-30T09:07:25.999 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-30T09:07:26.061 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:07:28.639 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:07:28.639 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:07:28.639 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-04-30T09:07:28.639 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-30T09:07:28.639 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-04-30T09:08:17.702 Process scan (poststartupscan) started. 2026-04-30T09:08:17.702 Process scan (poststartupscan) completed. 2026-04-30T09:08:18.202 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-30T09:08:18.218 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-30T09:08:20.796 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:08:20.796 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:08:20.796 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-04-30T09:08:20.796 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-30T09:08:20.796 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-04-30T09:09:17.311 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:09:17.327 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:09:17.327 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:09:37.155 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\A18C3345-A192-4FF4-8BFC-B18579028ACCfd8.1dcd881107443d7 2026-04-30T09:09:37.264 Verifying engine and signature files (source: 0) ... 2026-04-30T09:09:37.264 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpengine.dll] due to PPL. 2026-04-30T09:09:37.264 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasbase.vdm] (file in cache) 2026-04-30T09:09:37.264 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasdlta.vdm]. File not in cache (0x1) 2026-04-30T09:09:37.280 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasdlta.vdm] 2026-04-30T09:09:37.280 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavbase.vdm] (file in cache) 2026-04-30T09:09:37.280 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavdlta.vdm]. File not in cache (0x1) 2026-04-30T09:09:37.296 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavdlta.vdm] 2026-04-30T09:09:37.452 [Engine] IsHybridMode: 0 2026-04-30T09:09:37.452 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-04-30T09:09:37.452 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A020D9AE8DD4588340B6570DA8644AFBC6B134B5.bin): 0x00000002 2026-04-30T09:09:37.467 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A020D9AE8DD4588340B6570DA8644AFBC6B134B5.bin) 2026-04-30T09:09:37.467 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-04-30T09:09:37.467 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-04-30T09:09:37.467 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-04-30T09:09:37.467 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-04-30T09:09:49.436 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-04-30T09:09:49.436 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-04-30T09:09:49.452 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB033F8020, lRefCount: 5, hr=0 2026-04-30T09:09:49.452 [Engine] New active engine 00007FFAFE8A8020 replacing engine 00007FFB033F8020. Number of active engines: 2 2026-04-30T09:09:49.452 EngineInit:Global ASOC is enabled 2026-04-30T09:09:49.452 EngineInit:ASOO is enabled for developer volumes 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-04-30T09:09:49.514 MpWriteUupSignatureVersion 1.449.367.0, hr = 0 2026-04-30T09:09:49.514 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-04-30T09:09:49.546 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-04-30T09:09:49.546 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-04-30T09:09:49.546 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-04-30T09:09:49.546 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-04-30T09:09:49.546 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-30T09:09:49.546 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-04-30T09:09:49.546 [Plugin] Initializing RTP plugin state... 2026-04-30T09:09:49.546 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-04-30T09:09:49.546 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎04‎-‎30‎-‎2026 11:07:25 Last Perf:‎04‎-‎30‎-‎2026 11:07:25 First RTP Scan:‎04‎-‎30‎-‎2026 11:07:25 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:297 Misses:198 BM Queue:0,8,0 Proc:0,8,0 File:0,3,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:533 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:1553980 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2272 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12405 TotalHits:2182 InstanceCacheInserts:16 InstanceCacheUpdates:0 InstanceCacheDeletes:14 InstanceCacheHits:0 InstanceCacheMisses:2590 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (57/25) Success: 25, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-04-30T09:09:49.546 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7} 2026-04-30T09:09:49.546 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpasbase.vdm in use, hr=0x80070020 2026-04-30T09:09:49.561 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-30T09:09:49.561 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{816776A1-4D07-44A3-8407-C838B9649453} removed 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:04-30-2026 09:09:49 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-30-2026 09:09:49 2026-04-30T09:09:49.561 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-04-30T09:09:49.561 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-04-30T09:09:49.561 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:09:49.561 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-04-30T09:09:49.561 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-04-30T09:09:49.561 MdCoreSvc is supported in this platform and OS Signature updated on 04-30-2026 09:09:49 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.367.0 AV Signature Version: 1.449.367.0 ************************************************************ 2026-04-30T09:09:49.561 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-04-30T09:09:49.561 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\A18C3345-A192-4FF4-8BFC-B18579028ACCfd8.1dcd881107443d7 2026-04-30T09:09:49.655 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-04-30T09:09:49.655 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-04-30T09:09:49.921 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-30T09:09:49.936 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-30T09:09:49.936 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-30T09:09:49.936 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-30T09:09:49.936 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-30T09:09:49.936 [Engine] Engine 00007FFB033F8020 no longer in use. Number of active engines: 1 2026-04-30T09:09:49.936 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:09:49.936 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-04-30T09:09:50.014 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 140, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8}\mpengine.dll, EstimatedImpact: 1% 2026-04-30T09:09:50.014 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-04-30T09:09:50.014 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T09:09:50.030 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-04-30T09:09:50.030 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-04-30T09:09:50.030 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-04-30T09:09:50.046 [Engine] RSIG_UNLOADENGINE, 00007FFB033F8020, err=0x0 2026-04-30T09:09:50.046 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{74EE12D2-3719-4290-A5CC-3EF44E304FF8} removed 2026-04-30T09:09:51.561 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:09:51.561 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:09:51.561 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:12:25.561 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T09:14:49.499 [RbM] Setting Last known good engine candidate. hr = 0 2026-04-30T09:17:11.749 [AutoPurge] Verification Routine tasks have started. 2026-04-30T09:17:11.749 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-30T09:17:11.905 [AutoPurge] Cleanup Routine tasks have started. 2026-04-30T09:17:11.921 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-30T09:17:11.921 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-30T09:17:11.921 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-30-2026 09:17:11 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-30-2026 09:17:11 2026-04-30T09:17:11.936 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-30T09:17:11.936 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-30T09:17:11.936 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-30T09:17:11.936 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-30T09:17:11.936 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-30T09:17:12.014 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:10E5E627-51ED-4B3D-971E-565E65D784D5, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-30T09:17:12.014 Scheduled scan with Id 10E5E627-51ED-4B3D-971E-565E65D784D5 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-30T09:17:12.014 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-30T09:17:12.014 [SFC] System file cache build is not needed (already completed) 2026-04-30T09:17:12.030 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-30T09:17:12.030 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-30T09:17:12.061 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-30T09:17:12.077 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-30T09:17:12.077 [AutoPurge] Verification Routine tasks have ended. 2026-04-30T09:17:12.124 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-30T09:17:12.124 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-30T09:17:12.124 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-30T09:17:12.124 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-30T09:17:12.124 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-30T09:17:12.124 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-30T09:17:12.686 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #1892, FileId: 0xb0000000102d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:17:14.014 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:17:14.030 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:17:14.030 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-30T09:17:25.577 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-04-30T09:17:25.577 Timer callback: Initializating/verifying scheduled tasks ... 2026-04-30T09:17:25.592 Job Notification: New process added to job (1816) 2026-04-30T09:17:25.592 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-04-30T09:17:25.608 Job Notification: New process added to job (5132) 2026-04-30T09:17:25.624 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:1816] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5132]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-30T09:17:25.671 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 54387524(ms) from now at 02:23 (00:23 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-30T09:17:25.717 Job Notification: New process added to job (6664) 2026-04-30T09:17:25.717 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-04-30T09:17:25.717 Job Notification: New process added to job (3768) 2026-04-30T09:17:25.733 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6664] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3768]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-04-30T09:17:26.202 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-30T09:17:26.217 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-30T09:17:26.217 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:17:26.217 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:17:26.217 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-30T09:17:26.217 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-30T09:17:26.217 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-30T09:17:26.217 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:17:26.217 [RTP] No config change detected. Not updating plugin configuration. 2026-04-30T09:17:26.217 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-30T09:17:26.217 [RTP] No config changes found. No configuration switch. 2026-04-30T09:17:26.217 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-30T09:17:26.217 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-30T09:17:26.217 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-30T09:17:26.217 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-30T09:17:26.217 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-30T09:17:26.217 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-30T09:17:26.217 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-30T09:17:26.217 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-30T09:17:26.217 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-30T09:17:26.217 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-30T09:17:26.217 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-30T09:17:26.233 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:17:26.233 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:17:26.233 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:17:28.796 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:17:28.796 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:17:28.796 [RTP] Updating plugin configuration due to recent config changes (0x41e) ... 2026-04-30T09:17:28.796 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-30T09:17:28.796 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x208 2026-04-30T09:17:30.639 RPC Rundown called on ScanID: 10E5E627-51ED-4B3D-971E-565E65D784D5 2026-04-30T09:17:30.639 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:10E5E627-51ED-4B3D-971E-565E65D784D5. bRemoveFromList(ClientKilled):1 2026-04-30T09:17:30.655 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:10E5E627-51ED-4B3D-971E-565E65D784D5 2026-04-30T09:17:30.655 QuickScan:ScanID:10E5E627-51ED-4B3D-971E-565E65D784D5: Scan was stopped 2026-04-30T09:17:30.655 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:10E5E627-51ED-4B3D-971E-565E65D784D5 2026-04-30T09:17:30.655 QuickScan:ScanID:10E5E627-51ED-4B3D-971E-565E65D784D5: Quick scan aborted by callback after end stage 2026-04-30T09:17:30.655 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:10E5E627-51ED-4B3D-971E-565E65D784D5 2026-04-30T09:17:30.655 OnDemandScanWorker: Scan Cancelled! scanId:10E5E627-51ED-4B3D-971E-565E65D784D5, hr = 0x80508018 2026-04-30T09:17:32.655 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:17:32.655 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:17:32.655 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:17:38.608 Job Notification: Process exited from job (6664) 2026-04-30T09:17:38.608 Job Notification: Process exited from job (3768) 2026-04-30T09:17:38.686 Job Notification: Process exited from job (1816) 2026-04-30T09:17:38.686 Job Notification: Process exited from job (5132) 2026-04-30T09:18:17.702 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-30T09:18:23.780 Process scan (postsignatureupdatescan) completed. 2026-04-30T09:19:11.405 [RTP] 7 newly mounted volumes accumulated, forcing a config update ... 2026-04-30T09:19:11.405 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:19:11.405 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:19:11.405 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-04-30T09:19:11.405 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-04-30T09:19:11.405 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-04-30T09:19:11.421 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-04-30T09:19:12.108 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-04-30T09:19:43.022 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5325, FileId: 0x68000000028933, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF068315B, sigsha=3b4863129d0d1afbcbee84275299c87de3d6d4ee, cached=false, source=2, resourceid=0x16b61975 2026-04-30T09:20:17.038 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-30T09:20:17.038 [Cloud] Start of cloud request. Passive mode: 0 2026-04-30T09:20:17.038 [Cloud] Queued cloud request. 2026-04-30T09:20:17.038 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-30T09:20:17.038 [Cloud] Dequeued cloud request. 2026-04-30T09:20:17.038 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\837928c47aefabd6c7e8cd57d62504ed7c99616e Dynamic Signature Compilation Timestamp:04-30-2026 09:20:17 Persistence Type:Duration Time remaining:1728000000 2026-04-30T09:20:17.575 [Cloud] End of cloud request. 2026-04-30T09:20:17.575 RTSD:RTSD recieved, rescanning impacted resources 2026-04-30T09:20:17.576 Dynamic signature received 2026-04-30T09:20:18.128 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:20:47.419 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #7008, FileId: 0x6d000000029696, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:24:07.370 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7510, FileId: 0x4600000002973e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:26:28.134 [AutoPurge] Routine task for Cache Maintenance has started. 2026-04-30T09:26:28.134 [AutoPurge] Routine task for Cache Maintenance ... 2026-04-30T09:26:28.134 [AutoPurge] Routine task for MpSFCBuild ... 2026-04-30T09:26:28.134 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-04-30T09:26:28.134 [AutoPurge] MpSignalMaintenanceMode ... 2026-04-30T09:26:28.134 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-04-30T09:26:28.150 [AutoPurge] Verification Routine tasks have started. 2026-04-30T09:26:28.150 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-04-30T09:26:28.150 [AutoPurge] Cleanup Routine tasks have started.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-04-30T09:26:28.165 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-04-30T09:26:28.165 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:93AD69A0-0475-4048-88F4-1AEB3934B5F6, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-04-30T09:26:28.165 Scheduled scan with Id 93AD69A0-0475-4048-88F4-1AEB3934B5F6 configured CPU priority: normal (LowCpuPriority: 0) 2026-04-30T09:26:28.165 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-04-30T09:26:28.165 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:04-30-2026 09:26:28 2026-04-30T09:26:28.181 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-04-30T09:26:28.181 [SFC] System file cache build is not needed (already completed) Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:04-30-2026 09:26:28 2026-04-30T09:26:28.181 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-04-30T09:26:28.181 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-04-30T09:26:28.181 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-04-30T09:26:28.181 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-04-30T09:26:28.181 [AutoPurge] Cleanup Routine tasks have ended. 2026-04-30T09:26:28.368 EnsureProtectedFolderAcls(), hr = 0x0 2026-04-30T09:26:28.368 [AutoPurge] MpReinforceServiceAcls: 0 2026-04-30T09:26:28.400 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-04-30T09:26:28.415 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-04-30T09:26:28.415 [AutoPurge] Verification Routine tasks have ended. 2026-04-30T09:26:29.150 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8258, FileId: 0x4700000002973e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-04-30T09:26:30.181 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:26:30.181 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:26:30.196 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:26:59.851 Engine:Triggered AR EMS scan 2026-04-30T09:26:59.851 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.867 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.883 Engine:EMS scan for process: svchost pid: 800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.883 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.898 Engine:EMS scan for process: svchost pid: 1220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.898 Engine:EMS scan for process: svchost pid: 1260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.898 Engine:EMS scan for process: svchost pid: 1388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.898 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.914 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.914 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.914 Engine:EMS scan for process: svchost pid: 1460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.914 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.929 Engine:EMS scan for process: svchost pid: 1568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.929 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.929 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.929 Engine:EMS scan for process: svchost pid: 1772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.945 Engine:EMS scan for process: svchost pid: 1964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.945 Engine:EMS scan for process: svchost pid: 1124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.945 Engine:EMS scan for process: svchost pid: 1952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.945 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.961 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.976 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.976 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.976 Engine:EMS scan for process: svchost pid: 2700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.976 Engine:EMS scan for process: svchost pid: 2916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.992 Engine:EMS scan for process: svchost pid: 2996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.992 Engine:EMS scan for process: svchost pid: 3056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:26:59.992 Engine:EMS scan for process: svchost pid: 3084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.008 Engine:EMS scan for process: svchost pid: 3592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.008 Engine:EMS scan for process: svchost pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.008 Engine:EMS scan for process: svchost pid: 3684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.023 Engine:EMS scan for process: svchost pid: 3700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.039 Engine:EMS scan for process: svchost pid: 3832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.039 Engine:EMS scan for process: svchost pid: 3864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.039 Engine:EMS scan for process: svchost pid: 2604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.055 Engine:EMS scan for process: svchost pid: 3572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.055 Engine:EMS scan for process: svchost pid: 4128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.055 Engine:EMS scan for process: svchost pid: 4164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.055 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.070 Engine:EMS scan for process: svchost pid: 4184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.070 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.086 Engine:EMS scan for process: svchost pid: 4472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.086 Engine:EMS scan for process: svchost pid: 4528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.086 Engine:EMS scan for process: svchost pid: 5156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.086 Engine:EMS scan for process: svchost pid: 5800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.101 Engine:EMS scan for process: dllhost pid: 5836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.101 Engine:EMS scan for process: svchost pid: 5884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.101 Engine:EMS scan for process: svchost pid: 4712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.117 Engine:EMS scan for process: svchost pid: 3720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.117 Engine:EMS scan for process: svchost pid: 3272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.117 Engine:EMS scan for process: svchost pid: 1472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.133 Engine:EMS scan for process: svchost pid: 6616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.133 Engine:EMS scan for process: svchost pid: 2860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.133 Engine:EMS scan for process: svchost pid: 988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.133 Engine:EMS scan for process: svchost pid: 2324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.133 Engine:EMS scan for process: svchost pid: 6800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.148 Engine:EMS scan for process: svchost pid: 1196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.148 Engine:EMS scan for process: svchost pid: 3464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.148 Engine:EMS scan for process: svchost pid: 4268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.164 Engine:EMS scan for process: svchost pid: 7024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.164 Engine:EMS scan for process: svchost pid: 4668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.164 Engine:EMS scan for process: svchost pid: 5780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.179 Engine:EMS scan for process: svchost pid: 4100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.179 Engine:EMS scan for process: svchost pid: 1660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.195 Engine:EMS scan for process: explorer pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.226 Engine:EMS scan for process: svchost pid: 1916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.242 Engine:EMS scan for process: svchost pid: 5812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.242 Engine:EMS scan for process: svchost pid: 7308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.242 Engine:EMS scan for process: dllhost pid: 8036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.242 Engine:EMS scan for process: svchost pid: 10748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.258 Engine:EMS scan for process: svchost pid: 6232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.258 Engine:EMS scan for process: svchost pid: 8752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:00.258 Engine:EMS scan for process: svchost pid: 6320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-04-30T09:27:29.944 ExpensiveFile:Scan time for `\\?\C:\Program Files\Microsoft Office\root\Office16\livecapture.bundle` is 8187 units 2026-04-30T09:27:30.573 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T09:30:29.961 QuickScan:ScanID:93AD69A0-0475-4048-88F4-1AEB3934B5F6: Quick scan finished with error 0 2026-04-30T09:30:30.497 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-04-30T09:30:30.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 32 2026-04-30T09:30:30.512 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:30:30.512 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:30:30.512 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 2 2026-04-30T09:30:30.512 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-04-30T09:30:30.512 [RTP] No config change detected. Not updating plugin configuration. 2026-04-30T09:30:30.512 [RTP] No config changes found. No configuration switch. 2026-04-30T09:30:30.512 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-04-30T09:30:30.512 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:30:30.512 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:30:30.512 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 4 2026-04-30T09:30:30.512 [RTP] No config change detected. Not updating plugin configuration. 2026-04-30T09:30:30.512 [RTP] No config changes found. No configuration switch. 2026-04-30T09:30:30.512 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 8 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 16 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 1024 2026-04-30T09:30:30.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 2048 2026-04-30T09:30:30.512 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-04-30T09:30:30.512 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-04-30T09:30:30.512 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-04-30T09:30:30.512 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-04-30T09:30:30.512 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-04-30T09:30:30.512 [RTP] [RtpConfig] Config change detected, type: 64 2026-04-30T09:30:30.512 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:30:30.528 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:30:30.528 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T09:30:30.575 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 58989962(ms) from now at 03:53 (01:53 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-04-30T09:30:31.981 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:30:31.981 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-04-30T09:30:31.997 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-04-30T09:30:33.090 [RTP] Duplicating the current plugin configuration object... 2026-04-30T09:30:33.090 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-04-30T09:30:33.090 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-04-30T09:30:33.090 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-04-30T09:30:33.090 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-04-30T09:31:06.908 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8E3C89E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9270, FileId: 0x9e0000000297f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:06.955 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEBBBA0970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9273, FileId: 0x230000000297fb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:06.955 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD1B18394F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9274, FileId: 0xa00000000297f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.002 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj540F849FA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9278, FileId: 0x1b000000029822, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.072 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB2846D9C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9280, FileId: 0x1c000000029822, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.161 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4A63F29DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9286, FileId: 0xa90000000297f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.179 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAE77489AD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9289, FileId: 0x2000000002981f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.210 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD846F298B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9302, FileId: 0xab0000000297f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.226 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAB35B5934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9303, FileId: 0x2100000002981f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:07.257 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB66AED9C5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9304, FileId: 0x1900000002982b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:21.563 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9463, FileId: 0x2c00000001c596, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:21.641 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9467, FileId: 0x2a000000029705, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:21.766 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9471, FileId: 0x430000000297f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:31:34.364 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #9519, FileId: 0x2b0000000137c1, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:32:21.903 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9523, FileId: 0x480000000004f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:34:09.162 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #9602, FileId: 0x790000000070ee, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:41:21.844 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9773, FileId: 0x1a00000001c0d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:41:21.844 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9775, FileId: 0x400000000298a5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:42:11.273 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9795, FileId: 0x5e0000000298a3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T09:42:35.576 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T09:55:53.710 [RTP] [Mini-filter] OpenWithoutRead notification (1112, 10026, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-04-30T09:57:40.574 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T09:58:22.528 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10628, FileId: 0x19200000000343c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T10:03:50.556 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10658, FileId: 0xd5000000005fc2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T10:07:25.573 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-04-30T10:12:45.564 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T10:27:50.563 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T10:42:55.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T10:58:00.564 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T11:09:49.463 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T11:09:49.463 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7130, Count: 134, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T11:09:49.463 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T11:09:49.463 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T11:09:49.463 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T11:09:49.463 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T11:09:49.463 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T11:09:49.463 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T11:09:49.463 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T11:09:49.463 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T11:09:49.463 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 262, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 215, Count: 11, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T11:09:49.463 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T11:09:49.463 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T11:09:49.463 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: backgroundTaskHost.exe, Pid: 11004, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-30T11:09:49.463 ProcessImageName: ngentask.exe, Pid: 4416, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 5% 2026-04-30T11:09:49.463 ProcessImageName: SDXHelper.exe, Pid: 5876, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 3% 2026-04-30T11:09:49.463 ProcessImageName: RuntimeBroker.exe, Pid: 2600, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 4% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 4516, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 4% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 11004, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 3% 2026-04-30T11:09:49.463 ProcessImageName: Acrobat.exe, Pid: 8076, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 12% 2026-04-30T11:09:49.463 ProcessImageName: OpenWith.exe, Pid: 260, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 19% 2026-04-30T11:09:49.463 ProcessImageName: taskhostw.exe, Pid: 1868, TotalTime: 61, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-04-30T11:09:49.463 ProcessImageName: runonce.exe, Pid: 10700, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\desktop.ini, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: AcroCEF.exe, Pid: 6596, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: SDXHelper.exe, Pid: 10932, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 46, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-30T11:09:49.463 ProcessImageName: dllhost.exe, Pid: 1204, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 14% 2026-04-30T11:09:49.463 ProcessImageName: sihost.exe, Pid: 3568, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: backgroundTaskHost.exe, Pid: 8380, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 5% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 4108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1158.log, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: OneDriveLauncher.exe, Pid: 4140, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: taskhostw.exe, Pid: 1812, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 6132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1117.log, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: Acrobat.exe, Pid: 5124, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 13% 2026-04-30T11:09:49.463 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.0920.4224.1.aodl, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1203.log, EstimatedImpact: 1% 2026-04-30T11:09:49.463 ProcessImageName: TeamViewer_Service.exe, Pid: 4560, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: AdobeARM.exe, Pid: 11104, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-04-30T11:09:49.463 ProcessImageName: dllhost.exe, Pid: 5836, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: DismHost.exe, Pid: 1696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 5% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 6% 2026-04-30T11:09:49.463 ProcessImageName: ApplicationFrameHost.exe, Pid: 3260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: OfficeC2RClient.exe, Pid: 9524, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1126.log, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T11:09:49.463 ProcessImageName: svchost.exe, Pid: 6232, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-30T11:13:05.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T11:28:10.566 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T11:43:15.567 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T11:54:40.725 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11311, FileId: 0x72000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.725 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11308, FileId: 0x71000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.725 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11313, FileId: 0x7700000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.725 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11312, FileId: 0x73000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11316, FileId: 0x75000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11318, FileId: 0x76000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11319, FileId: 0x77000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11317, FileId: 0x7a00000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.756 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11322, FileId: 0x79000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.756 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11324, FileId: 0x7a000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.772 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11327, FileId: 0x7c000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.772 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11323, FileId: 0x7c00000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:40.772 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11328, FileId: 0x8000000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:41.147 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #11361, FileId: 0x7e000000010dbf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:54:41.147 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\151928b1-d9db-4c9b-a50e-e3506b17bf3b. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #11363, FileId: 0x14c00000000173b, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T11:58:20.570 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T12:13:25.572 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T12:28:30.570 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T12:43:35.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T12:52:11.494 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11693, FileId: 0x2a00000002968f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T12:52:56.963 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #11706, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab 2026-04-30T12:57:10.549 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12134, FileId: 0x2b00000002968f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T12:58:40.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T13:09:49.464 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T13:09:49.464 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7442, Count: 137, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T13:09:49.464 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T13:09:49.464 ProcessImageName: httpd.exe, Pid: 6596, TotalTime: 3004, Count: 147, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\noVNC\noVNC-1.2.0\core\rfb.js, EstimatedImpact: 2% 2026-04-30T13:09:49.464 ProcessImageName: httpd.exe, Pid: 9132, TotalTime: 2758, Count: 76, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 77% 2026-04-30T13:09:49.464 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T13:09:49.464 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T13:09:49.464 ProcessImageName: xampp-control.exe, Pid: 1592, TotalTime: 1841, Count: 7, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 39% 2026-04-30T13:09:49.464 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T13:09:49.464 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T13:09:49.464 ProcessImageName: mysqld.exe, Pid: 11888, TotalTime: 1081, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 61% 2026-04-30T13:09:49.464 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T13:09:49.464 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T13:09:49.464 ProcessImageName: firefox.exe, Pid: 7272, TotalTime: 601, Count: 56, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 46% 2026-04-30T13:09:49.464 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T13:09:49.464 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 262, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 260, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T13:09:49.464 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T13:09:49.464 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T13:09:49.464 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: backgroundTaskHost.exe, Pid: 11004, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-30T13:09:49.464 ProcessImageName: ngentask.exe, Pid: 4416, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 5% 2026-04-30T13:09:49.464 ProcessImageName: SDXHelper.exe, Pid: 5876, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 3% 2026-04-30T13:09:49.464 ProcessImageName: RuntimeBroker.exe, Pid: 2600, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 4% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 4516, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 4% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 11004, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 3% 2026-04-30T13:09:49.464 ProcessImageName: Acrobat.exe, Pid: 8076, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 12% 2026-04-30T13:09:49.464 ProcessImageName: OpenWith.exe, Pid: 260, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 19% 2026-04-30T13:09:49.464 ProcessImageName: taskhostw.exe, Pid: 1868, TotalTime: 61, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-04-30T13:09:49.464 ProcessImageName: runonce.exe, Pid: 10700, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\desktop.ini, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: AcroCEF.exe, Pid: 6596, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: SDXHelper.exe, Pid: 10932, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 46, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-30T13:09:49.464 ProcessImageName: dllhost.exe, Pid: 1204, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 14% 2026-04-30T13:09:49.464 ProcessImageName: sihost.exe, Pid: 3568, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: SDXHelper.exe, Pid: 9324, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-04-30T13:09:49.464 ProcessImageName: backgroundTaskHost.exe, Pid: 8380, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 5% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 4108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: dllhost.exe, Pid: 5836, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 6132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1117.log, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: OneDriveLauncher.exe, Pid: 4140, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: taskhostw.exe, Pid: 1812, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1158.log, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: Acrobat.exe, Pid: 5124, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 13% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1203.log, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 3356, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1452.log, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.0920.4224.1.aodl, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 9140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1457.log, EstimatedImpact: 1% 2026-04-30T13:09:49.464 ProcessImageName: TeamViewer_Service.exe, Pid: 4560, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: AdobeARM.exe, Pid: 11104, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-04-30T13:09:49.464 ProcessImageName: DismHost.exe, Pid: 1696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 5% 2026-04-30T13:09:49.464 ProcessImageName: ApplicationFrameHost.exe, Pid: 3260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 6% 2026-04-30T13:09:49.464 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 9524, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1126.log, EstimatedImpact: 0% 2026-04-30T13:09:49.464 ProcessImageName: svchost.exe, Pid: 6232, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-30T13:13:45.573 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T13:28:50.574 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T13:43:55.588 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T13:49:05.183 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13570, FileId: 0x8500000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.186 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13572, FileId: 0x4f00000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.186 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13573, FileId: 0x8600000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.193 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13574, FileId: 0x5000000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.201 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13571, FileId: 0x4e00000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.203 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13578, FileId: 0x5300000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.211 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13580, FileId: 0x8a00000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.211 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13581, FileId: 0x8b00000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.213 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13577, FileId: 0x5100000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.226 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13584, FileId: 0x5600000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.227 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13579, FileId: 0x8900000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.233 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13588, FileId: 0x5900000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.233 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13585, FileId: 0x8e00000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.658 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13623, FileId: 0x9100000000825c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:49:05.669 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\3555c099-3d6e-43f5-8048-71ae5faf4e43. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #13624, FileId: 0x4400000000edad, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T13:59:00.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T14:14:05.564 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T14:29:10.567 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T14:44:15.570 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T14:59:20.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T15:09:49.464 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T15:09:49.464 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7442, Count: 137, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T15:09:49.464 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T15:09:49.464 ProcessImageName: httpd.exe, Pid: 6596, TotalTime: 3004, Count: 147, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\noVNC\noVNC-1.2.0\core\rfb.js, EstimatedImpact: 2% 2026-04-30T15:09:49.464 ProcessImageName: httpd.exe, Pid: 9132, TotalTime: 2758, Count: 76, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 77% 2026-04-30T15:09:49.464 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T15:09:49.464 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T15:09:49.464 ProcessImageName: xampp-control.exe, Pid: 1592, TotalTime: 1841, Count: 7, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 39% 2026-04-30T15:09:49.464 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T15:09:49.464 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T15:09:49.464 ProcessImageName: mysqld.exe, Pid: 11888, TotalTime: 1081, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 61% 2026-04-30T15:09:49.464 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T15:09:49.464 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T15:09:49.464 ProcessImageName: firefox.exe, Pid: 7272, TotalTime: 601, Count: 56, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 46% 2026-04-30T15:09:49.464 ProcessImageName: WmiPrvSE.exe, Pid: 1608, TotalTime: 586, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T15:09:49.464 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T15:09:49.464 ProcessImageName: firefox.exe, Pid: 9496, TotalTime: 409, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\152e284c-f20d-454b-97c7-1f579527bf01, EstimatedImpact: 53% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 370, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 260, Count: 17, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T15:09:49.464 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T15:09:49.464 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T15:09:49.464 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T15:09:49.464 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: backgroundTaskHost.exe, Pid: 11004, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-30T15:09:49.464 ProcessImageName: ngentask.exe, Pid: 4416, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 5% 2026-04-30T15:09:49.464 ProcessImageName: SDXHelper.exe, Pid: 5876, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 3% 2026-04-30T15:09:49.464 ProcessImageName: RuntimeBroker.exe, Pid: 2600, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 4% 2026-04-30T15:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 4516, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 4% 2026-04-30T15:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 11004, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 3% 2026-04-30T15:09:49.464 ProcessImageName: Acrobat.exe, Pid: 8076, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 12% 2026-04-30T15:09:49.464 ProcessImageName: OpenWith.exe, Pid: 260, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 19% 2026-04-30T15:09:49.464 ProcessImageName: taskhostw.exe, Pid: 1868, TotalTime: 61, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-04-30T15:09:49.464 ProcessImageName: runonce.exe, Pid: 10700, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\desktop.ini, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: AcroCEF.exe, Pid: 6596, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-30T15:09:49.464 ProcessImageName: SDXHelper.exe, Pid: 10932, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 1% 2026-04-30T15:09:49.464 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 46, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-30T15:09:49.465 ProcessImageName: dllhost.exe, Pid: 1204, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 14% 2026-04-30T15:09:49.465 ProcessImageName: sihost.exe, Pid: 3568, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: SDXHelper.exe, Pid: 9324, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-04-30T15:09:49.465 ProcessImageName: backgroundTaskHost.exe, Pid: 8380, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 5% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 4108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1158.log, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: dllhost.exe, Pid: 5836, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: OneDriveLauncher.exe, Pid: 4140, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 6132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1117.log, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: taskhostw.exe, Pid: 1812, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: Acrobat.exe, Pid: 5124, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 13% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 3356, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1452.log, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.0920.4224.1.aodl, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 9140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1457.log, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1203.log, EstimatedImpact: 1% 2026-04-30T15:09:49.465 ProcessImageName: TeamViewer_Service.exe, Pid: 4560, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: AdobeARM.exe, Pid: 11104, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-04-30T15:09:49.465 ProcessImageName: ApplicationFrameHost.exe, Pid: 3260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 6% 2026-04-30T15:09:49.465 ProcessImageName: svchost.exe, Pid: 4164, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: DismHost.exe, Pid: 1696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 5% 2026-04-30T15:09:49.465 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: OfficeC2RClient.exe, Pid: 9524, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1126.log, EstimatedImpact: 0% 2026-04-30T15:09:49.465 ProcessImageName: svchost.exe, Pid: 6232, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-30T15:14:25.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T15:19:39.346 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #14185, FileId: 0x149000000004626, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T15:29:30.567 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T15:44:35.562 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T15:59:40.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T16:14:45.565 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T16:29:50.569 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{244FB976-AB68-9377-F0D9-969EC151B764} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:2088 ProcessCreationTime:134220271818994995 SessionID:1 CreationTime:04-30-2026 16:41:13 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-04-30T16:41:14.521 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-04-30T16:41:14.521 [Cloud] Start of cloud request. Passive mode: 0 2026-04-30T16:41:14.521 [Cloud] Queued cloud request. 2026-04-30T16:41:14.521 [Cloud] MpEngineCloudRequest(). hr = 0 2026-04-30T16:41:14.521 [Cloud] Dequeued cloud request. 2026-04-30T16:41:14.521 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-04-30T16:41:14.755 [Cloud] End of cloud request. 2026-04-30T16:41:15.271 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-04-30T16:44:55.560 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T17:00:00.560 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T17:09:49.473 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T17:09:49.473 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7442, Count: 137, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T17:09:49.473 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T17:09:49.473 ProcessImageName: httpd.exe, Pid: 6596, TotalTime: 3004, Count: 147, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\noVNC\noVNC-1.2.0\core\rfb.js, EstimatedImpact: 2% 2026-04-30T17:09:49.473 ProcessImageName: httpd.exe, Pid: 9132, TotalTime: 2758, Count: 76, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 77% 2026-04-30T17:09:49.473 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T17:09:49.473 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T17:09:49.473 ProcessImageName: xampp-control.exe, Pid: 1592, TotalTime: 1841, Count: 7, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 39% 2026-04-30T17:09:49.473 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T17:09:49.473 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T17:09:49.473 ProcessImageName: mysqld.exe, Pid: 11888, TotalTime: 1081, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 61% 2026-04-30T17:09:49.473 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T17:09:49.473 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T17:09:49.473 ProcessImageName: firefox.exe, Pid: 7272, TotalTime: 601, Count: 56, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 46% 2026-04-30T17:09:49.473 ProcessImageName: WmiPrvSE.exe, Pid: 1608, TotalTime: 586, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T17:09:49.473 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T17:09:49.473 ProcessImageName: firefox.exe, Pid: 9496, TotalTime: 409, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\152e284c-f20d-454b-97c7-1f579527bf01, EstimatedImpact: 53% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 370, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 305, Count: 21, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T17:09:49.473 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T17:09:49.473 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T17:09:49.473 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: backgroundTaskHost.exe, Pid: 11004, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-30T17:09:49.473 ProcessImageName: ngentask.exe, Pid: 4416, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 5% 2026-04-30T17:09:49.473 ProcessImageName: SDXHelper.exe, Pid: 5876, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 3% 2026-04-30T17:09:49.473 ProcessImageName: RuntimeBroker.exe, Pid: 2600, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 4% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 4516, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 4% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 11004, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 3% 2026-04-30T17:09:49.473 ProcessImageName: FileCoAuth.exe, Pid: 4272, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.1519.4272.1.aodl, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: Acrobat.exe, Pid: 8076, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 12% 2026-04-30T17:09:49.473 ProcessImageName: OpenWith.exe, Pid: 260, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 19% 2026-04-30T17:09:49.473 ProcessImageName: taskhostw.exe, Pid: 1868, TotalTime: 61, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-04-30T17:09:49.473 ProcessImageName: runonce.exe, Pid: 10700, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\desktop.ini, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: AcroCEF.exe, Pid: 6596, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: SDXHelper.exe, Pid: 10932, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 46, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-30T17:09:49.473 ProcessImageName: dllhost.exe, Pid: 1204, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 14% 2026-04-30T17:09:49.473 ProcessImageName: sihost.exe, Pid: 3568, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: dllhost.exe, Pid: 5836, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: SDXHelper.exe, Pid: 9324, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-04-30T17:09:49.473 ProcessImageName: dasHost.exe, Pid: 5332, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 16% 2026-04-30T17:09:49.473 ProcessImageName: backgroundTaskHost.exe, Pid: 8380, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 5% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 4108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1158.log, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 6132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1117.log, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: OneDriveLauncher.exe, Pid: 4140, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: taskhostw.exe, Pid: 1812, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: Acrobat.exe, Pid: 5124, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 13% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 9140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1457.log, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1203.log, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.0920.4224.1.aodl, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 3356, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1452.log, EstimatedImpact: 1% 2026-04-30T17:09:49.473 ProcessImageName: TeamViewer_Service.exe, Pid: 4560, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: AdobeARM.exe, Pid: 11104, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-04-30T17:09:49.473 ProcessImageName: ApplicationFrameHost.exe, Pid: 3260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: DismHost.exe, Pid: 1696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 5% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 4164, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 6% 2026-04-30T17:09:49.473 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 0, Count: 9, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: OfficeC2RClient.exe, Pid: 9524, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1126.log, EstimatedImpact: 0% 2026-04-30T17:09:49.473 ProcessImageName: svchost.exe, Pid: 6232, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-04-30T17:13:15.711 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj57BFA59BE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15332, FileId: 0x1e000000033412, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.711 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2FD2949FE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15333, FileId: 0x1f000000033412, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.727 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6C12F990B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15334, FileId: 0x20000000033412, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.743 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBD290B9CC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15335, FileId: 0x21000000033412, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.758 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj49FEC09FE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15336, FileId: 0x240000000334d5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.758 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7645779AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15337, FileId: 0x2c0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.961 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26743D99B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15338, FileId: 0x1b000000033539, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.977 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6BE06E961. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15339, FileId: 0x300000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.977 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8790829EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15340, FileId: 0x310000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:15.993 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11EEFD944. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15341, FileId: 0x320000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.008 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj87FBF29BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15342, FileId: 0x330000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.024 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1FF4E09A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15343, FileId: 0x340000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.040 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj961FD1997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15344, FileId: 0x350000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.040 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB905E298B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15345, FileId: 0x360000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.055 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5392CC941. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15346, FileId: 0x370000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.071 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEDDC50966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15347, FileId: 0x380000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.086 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD2E23F9CA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15348, FileId: 0x390000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.102 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE5C173907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15349, FileId: 0x3a0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.118 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D7085993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15350, FileId: 0x3b0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.196 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8DD7F89F1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15351, FileId: 0x3c0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.211 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC82582976. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15352, FileId: 0x3d0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.227 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1D3C359A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15353, FileId: 0x3e0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.227 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj009E109D9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15354, FileId: 0x3f0000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.243 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj271D2F98C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15355, FileId: 0x3d0000000334d5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.258 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA0B2D0971. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15356, FileId: 0x3e0000000334d5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.352 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj625F84938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15357, FileId: 0x430000000334d5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.352 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3176C9945. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15358, FileId: 0x410000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.368 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj05E0EA91C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15359, FileId: 0x420000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.383 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBBDAA4966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15360, FileId: 0x430000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.399 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7B107D9D0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15361, FileId: 0x440000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.415 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11BBA892D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15362, FileId: 0x450000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.430 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8AD01D9FA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15363, FileId: 0x460000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:16.446 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8BD05900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15364, FileId: 0x470000000334dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:30.650 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15365, FileId: 0x410000000330ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:30.760 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15367, FileId: 0x340000000333ef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:44.495 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15369, FileId: 0x210000000331fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:13:44.495 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15371, FileId: 0x310000000333c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T17:15:05.573 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T17:30:10.559 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T17:45:15.568 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T18:00:20.568 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T18:15:25.563 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T18:30:30.561 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T18:45:35.621 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T18:54:40.222 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16875, FileId: 0x5f00000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.222 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16878, FileId: 0x6000000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.222 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16873, FileId: 0x59000000025011, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.222 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16880, FileId: 0x6100000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.250 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16874, FileId: 0x5e00000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.251 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16883, FileId: 0x5f000000025011, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.253 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16884, FileId: 0x6500000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.268 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16882, FileId: 0x6300000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T18:54:40.907 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16960, FileId: 0x7600000001c664, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T19:00:40.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x15582e9d 2026-04-30T19:09:49.587 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T19:09:49.587 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7676, Count: 138, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T19:09:49.587 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T19:09:49.587 ProcessImageName: httpd.exe, Pid: 6596, TotalTime: 3004, Count: 147, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\noVNC\noVNC-1.2.0\core\rfb.js, EstimatedImpact: 2% 2026-04-30T19:09:49.587 ProcessImageName: httpd.exe, Pid: 9132, TotalTime: 2758, Count: 76, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 77% 2026-04-30T19:09:49.587 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T19:09:49.587 ProcessImageName: firefox.exe, Pid: 9956, TotalTime: 2150, Count: 221, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 70% 2026-04-30T19:09:49.587 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T19:09:49.587 ProcessImageName: xampp-control.exe, Pid: 1592, TotalTime: 1841, Count: 7, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 39% 2026-04-30T19:09:49.587 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T19:09:49.587 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T19:09:49.587 ProcessImageName: mysqld.exe, Pid: 11888, TotalTime: 1081, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 61% 2026-04-30T19:09:49.587 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T19:09:49.587 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T19:09:49.587 ProcessImageName: firefox.exe, Pid: 7272, TotalTime: 601, Count: 56, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 46% 2026-04-30T19:09:49.587 ProcessImageName: WmiPrvSE.exe, Pid: 1608, TotalTime: 586, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T19:09:49.587 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T19:09:49.587 ProcessImageName: firefox.exe, Pid: 9496, TotalTime: 409, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\152e284c-f20d-454b-97c7-1f579527bf01, EstimatedImpact: 53% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 370, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 335, Count: 27, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T19:09:49.587 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 5928, TotalTime: 187, Count: 2, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOE5D8.tmp, EstimatedImpact: 40% 2026-04-30T19:09:49.587 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T19:09:49.587 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T19:09:49.587 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T19:09:49.587 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.587 ProcessImageName: backgroundTaskHost.exe, Pid: 11004, TotalTime: 105, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 6% 2026-04-30T19:09:49.587 ProcessImageName: ngentask.exe, Pid: 4416, TotalTime: 105, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 5% 2026-04-30T19:09:49.587 ProcessImageName: SDXHelper.exe, Pid: 5876, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B8E6BD80-2214-4EA8-A0E9-33120EA4DC99, EstimatedImpact: 3% 2026-04-30T19:09:49.588 ProcessImageName: RuntimeBroker.exe, Pid: 2600, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 4% 2026-04-30T19:09:49.588 ProcessImageName: OfficeC2RClient.exe, Pid: 4516, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 4% 2026-04-30T19:09:49.588 ProcessImageName: OfficeC2RClient.exe, Pid: 11004, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 3% 2026-04-30T19:09:49.588 ProcessImageName: Acrobat.exe, Pid: 8076, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 12% 2026-04-30T19:09:49.588 ProcessImageName: FileCoAuth.exe, Pid: 4272, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.1519.4272.1.aodl, EstimatedImpact: 1% 2026-04-30T19:09:49.588 ProcessImageName: OpenWith.exe, Pid: 260, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 19% 2026-04-30T19:09:49.588 ProcessImageName: taskhostw.exe, Pid: 1868, TotalTime: 61, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-04-30T19:09:49.588 ProcessImageName: runonce.exe, Pid: 10700, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\desktop.ini, EstimatedImpact: 0% 2026-04-30T19:09:49.588 ProcessImageName: AcroCEF.exe, Pid: 6596, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-04-30T19:09:49.588 ProcessImageName: SDXHelper.exe, Pid: 10932, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 1% 2026-04-30T19:09:49.588 ProcessImageName: OfficeC2RClient.exe, Pid: 9592, TotalTime: 46, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 2% 2026-04-30T19:09:49.588 ProcessImageName: dllhost.exe, Pid: 1204, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 14% 2026-04-30T19:09:49.588 ProcessImageName: sihost.exe, Pid: 3568, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: dllhost.exe, Pid: 5836, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: svchost.exe, Pid: 7024, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource->(UTF-8), EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: SDXHelper.exe, Pid: 9324, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-04-30T19:09:49.589 ProcessImageName: backgroundTaskHost.exe, Pid: 8380, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 5% 2026-04-30T19:09:49.589 ProcessImageName: dasHost.exe, Pid: 5332, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 16% 2026-04-30T19:09:49.589 ProcessImageName: AggregatorHost.exe, Pid: 5320, TotalTime: 30, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 4108, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E08E7483-A183-4797-ADD7-D0CCFEFA1B5F, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: taskhostw.exe, Pid: 1812, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: OneDriveLauncher.exe, Pid: 4140, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1158.log, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 6132, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1117.log, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: Acrobat.exe, Pid: 5124, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 13% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1203.log, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 9140, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1457.log, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: FileCoAuth.exe, Pid: 4224, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-04-30.0920.4224.1.aodl, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 3356, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1452.log, EstimatedImpact: 1% 2026-04-30T19:09:49.589 ProcessImageName: SDXHelper.exe, Pid: 10212, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-04-30T19:09:49.589 ProcessImageName: TeamViewer_Service.exe, Pid: 4560, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: AdobeARM.exe, Pid: 11104, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-04-30T19:09:49.589 ProcessImageName: svchost.exe, Pid: 4164, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 6% 2026-04-30T19:09:49.589 ProcessImageName: ApplicationFrameHost.exe, Pid: 3260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: DismHost.exe, Pid: 1696, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 5% 2026-04-30T19:09:49.589 ProcessImageName: OfficeC2RClient.exe, Pid: 9524, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260430-1126.log, EstimatedImpact: 0% 2026-04-30T19:09:49.589 ProcessImageName: svchost.exe, Pid: 6232, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% Internal signature match:subtype=Lowfi, sigseq=0x0000157EDBC612FC, sigsha=d5f1909a20fbb89ca049ea3ac446bcfd3acf514e, cached=false, source=2, resourceid=0x83429d94 2026-04-30T19:15:45.687 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T19:30:50.715 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T19:45:55.737 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T20:01:00.737 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T20:16:05.754 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T20:31:10.761 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T20:46:15.772 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T20:49:05.282 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18378, FileId: 0x3300000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-04-30T21:01:20.774 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-04-30T21:09:49.684 ProcessImageName: CCC.exe, Pid: 12004, TotalTime: 30796, Count: 574, MaxTime: 2109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 45% 2026-04-30T21:09:49.684 ProcessImageName: explorer.exe, Pid: 3680, TotalTime: 7706, Count: 142, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: AcroCEF.exe, Pid: 4984, TotalTime: 3607, Count: 174, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 29% 2026-04-30T21:09:49.684 ProcessImageName: DipAwayMode.exe, Pid: 2980, TotalTime: 3319, Count: 17, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: AsPowerBar.exe, Pid: 11608, TotalTime: 3209, Count: 18, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 36% 2026-04-30T21:09:49.684 ProcessImageName: httpd.exe, Pid: 6596, TotalTime: 3004, Count: 147, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\01_myWebApps\noVNC\noVNC-1.2.0\core\rfb.js, EstimatedImpact: 2% 2026-04-30T21:09:49.684 ProcessImageName: httpd.exe, Pid: 9132, TotalTime: 2758, Count: 76, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 77% 2026-04-30T21:09:49.684 ProcessImageName: dllhost.exe, Pid: 8036, TotalTime: 2667, Count: 77, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\HY7Q5X92I3_105, EstimatedImpact: 40% 2026-04-30T21:09:49.684 ProcessImageName: firefox.exe, Pid: 9956, TotalTime: 2150, Count: 221, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 70% 2026-04-30T21:09:49.684 ProcessImageName: MOM.exe, Pid: 11576, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 48% 2026-04-30T21:09:49.684 ProcessImageName: xampp-control.exe, Pid: 1592, TotalTime: 1841, Count: 7, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 39% 2026-04-30T21:09:49.684 ProcessImageName: AISuite3.exe, Pid: 876, TotalTime: 1632, Count: 19, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-04-30T21:09:49.684 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 2652, TotalTime: 1297, Count: 69, MaxTime: 875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDrive.Sync.Service.dll, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: DeviceCensus.exe, Pid: 4340, TotalTime: 1154, Count: 7, MaxTime: 593, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-04-30T21:09:49.684 ProcessImageName: mysqld.exe, Pid: 11888, TotalTime: 1081, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 61% 2026-04-30T21:09:49.684 ProcessImageName: websockify.exe, Pid: 11596, TotalTime: 896, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-04-30T21:09:49.684 ProcessImageName: WmiPrvSE.exe, Pid: 5712, TotalTime: 724, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 82% 2026-04-30T21:09:49.684 ProcessImageName: firefox.exe, Pid: 7272, TotalTime: 601, Count: 56, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 46% 2026-04-30T21:09:49.684 ProcessImageName: WmiPrvSE.exe, Pid: 1608, TotalTime: 586, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T21:09:49.684 ProcessImageName: WmiPrvSE.exe, Pid: 9004, TotalTime: 585, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 89% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 3700, TotalTime: 546, Count: 2, MaxTime: 546, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: FileCoAuth.exe, Pid: 10048, TotalTime: 457, Count: 25, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 4% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 425, Count: 36, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: firefox.exe, Pid: 9496, TotalTime: 409, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\152e284c-f20d-454b-97c7-1f579527bf01, EstimatedImpact: 53% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 2416, TotalTime: 370, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: TeamViewer.exe, Pid: 4428, TotalTime: 288, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 1% 2026-04-30T21:09:49.684 ProcessImageName: WhatsApp.Root.exe, Pid: 1340, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: AdobeCollabSync.exe, Pid: 4868, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-04-30.log, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 972, TotalTime: 217, Count: 3, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: brynhildr.exe, Pid: 3920, TotalTime: 187, Count: 4, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 5928, TotalTime: 187, Count: 2, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOE5D8.tmp, EstimatedImpact: 40% 2026-04-30T21:09:49.684 ProcessImageName: ngentask.exe, Pid: 1660, TotalTime: 181, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 13% 2026-04-30T21:09:49.684 ProcessImageName: PhoneExperienceHost.exe, Pid: 9644, TotalTime: 166, Count: 18, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 0% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 4100, TotalTime: 155, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteams.exe, EstimatedImpact: 11% 2026-04-30T21:09:49.684 ProcessImageName: backgroundTaskHost.exe, Pid: 11908, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 16% 2026-04-30T21:09:49.684 ProcessImageName: SecurityHealthHost.exe, Pid: 12140, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-04-30T21:09:49.684 ProcessImageName: firefox.exe, Pid: 5456, TotalTime: 135, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa02720, EstimatedImpact: 18% 2026-04-30T21:09:49.684 ProcessImageName: svchost.exe, Pid: 800, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-01-2026 09:46:27 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/01/2026 09:46:27.718500900 UTC (14421 ms since boot) 2026-05-01T09:46:27.720 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-01T09:46:27.735 WARNING: the previous service shutdown was not expected. 2026-05-01T09:46:27.735 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-01T09:46:27.735 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-01T09:46:27.798 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260501-094627-00000003-fffffffeffffffff.bin ... 2026-05-01T09:46:27.907 [WPP] Trace session started - MpWppTracing-20260501-094627-00000003-fffffffeffffffff.bin 2026-05-01T09:46:27.923 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-01T09:46:27.923 [RbM] Rollback manager succesfully initialized. 2026-05-01T09:46:27.923 [RbM] Rollback manager EnableRollbackManager called. 2026-05-01T09:46:27.923 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-01T09:46:27.923 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-01T09:46:27.923 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-01T09:46:27.923 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-01T09:46:27.923 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-01T09:46:27.923 MdCoreSvc is supported in this platform and OS 2026-05-01T09:46:27.923 MdCoreSvc is supported in this platform and OS 2026-05-01T09:46:27.923 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-01T09:46:27.923 [PlatUpd] Starting MdCoreSvc service 2026-05-01T09:46:27.985 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-01T09:46:31.579 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-01T09:46:31.579 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-01T09:46:31.579 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-01T09:46:31.579 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-01T09:46:31.579 [PlatUpd] CSP platform update started 2026-05-01T09:46:31.579 [PlatUpd] Defender MDM CSP platform update not required 2026-05-01T09:46:31.579 [PlatUpd] WMI/PS provider platform update started 2026-05-01T09:46:31.579 [PlatUpd] WMI/PS provider platform update not required 2026-05-01T09:46:31.579 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-01T09:46:31.579 MdCoreSvc is supported in this platform and OS 2026-05-01T09:46:31.579 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-01T09:46:31.579 [PlatUpd] Starting MdCoreSvc service 2026-05-01T09:46:31.579 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-01T09:46:31.579 [TS] Troublshooting mode is not available! 2026-05-01T09:46:31.579 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-01T09:46:31.579 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-01T09:46:31.595 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-01T09:46:31.595 [Service] Enabling AutoLoggers ... 2026-05-01T09:46:31.610 [Service] Enabling AMSI registration ... 2026-05-01T09:46:31.610 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-01T09:46:31.626 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 44880 Number of invalid entries is 0 Number of inserts issued is 1577353 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6461 Number of lookups is 107547016 Number of lookup misses is 5159777 Number of fast lookup misses is 54814249 Number of false fast lookups is 5159772 Number of invalidations is 731246 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-01T09:46:31.626 Verifying license file... 2026-05-01T09:46:31.626 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll]. File not in cache (0x1) 2026-05-01T09:46:31.657 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] 2026-05-01T09:46:31.673 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-01T09:46:31.673 Loaded module#0 MpComServer. 2026-05-01T09:46:31.673 Loaded module#1 StartupPolicies. 2026-05-01T09:46:31.673 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-01T09:46:31.673 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-01T09:46:31.673 COM server initialized successfully. 2026-05-01T09:46:31.673 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-01T09:46:31.689 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-01T09:46:31.689 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-01T09:46:31.704 [RTP] [RTP] FilterCommunicator object 0x000001CC99109F10 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-01T09:46:31.704 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-01T09:46:31.704 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-01T09:46:31.704 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-01T09:46:31.704 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-01T09:46:31.704 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-01T09:46:31.704 [RTP] [RTP] FilterCommunicator object 0x000001CC9910A120 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-01T09:46:31.704 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-01T09:46:31.704 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-01T09:46:31.704 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-01T09:46:31.704 [RTP] [RTP] StartCommunication 0x000001CC99109F10 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-01T09:46:31.704 [init][RTP] RTPPlugin initialization completed 2026-05-01T09:46:31.704 OS boot count = 2 2026-05-01T09:46:31.704 OS Install = 0 2026-05-01T09:46:31.720 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-01T09:46:31.720 [KSL] Entering CKSLEngine::Initialize. 2026-05-01T09:46:31.720 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-01T09:46:31.720 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-01T09:46:31.720 [KSL] MpInstallKslD: hr=0x1 2026-05-01T09:46:31.720 [KSL] MpRegisterKslD: hr=0 2026-05-01T09:46:31.735 [KSL] MpStartKslD: hr=0 2026-05-01T09:46:31.735 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-01T09:46:31.735 Loading engine... 2026-05-01T09:46:31.735 Verifying engine and signature files (source: 1) ... 2026-05-01T09:46:31.735 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpengine.dll] due to PPL. 2026-05-01T09:46:31.735 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasbase.vdm]. File not in cache (0x1) 2026-05-01T09:46:32.689 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasbase.vdm] 2026-05-01T09:46:32.689 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-01T09:46:32.720 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasdlta.vdm] 2026-05-01T09:46:32.720 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavbase.vdm]. File not in cache (0x1) 2026-05-01T09:46:33.157 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavbase.vdm] 2026-05-01T09:46:33.157 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-01T09:46:33.173 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpavdlta.vdm] 2026-05-01T09:46:33.235 [Engine] IsHybridMode: 0 2026-05-01T09:46:33.235 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-01T09:46:33.267 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A020D9AE8DD4588340B6570DA8644AFBC6B134B5.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-01T09:46:40.095 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-01T09:46:40.095 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-01T09:46:40.095 [Engine] New active engine 00007FF8312E8020 (no old engine). Number of active engines: 1 2026-05-01T09:46:40.110 EngineInit:Global ASOC is enabled 2026-05-01T09:46:40.110 EngineInit:ASOO is enabled for developer volumes 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.189 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b648a7136e496844ef6ef04555bef80e9695bb52 Dynamic Signature Compilation Timestamp:04-20-2026 09:34:24 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ba8b638a59158c67aad218bb5e8c306de4a0501 Dynamic Signature Compilation Timestamp:04-20-2026 17:12:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99ba0a09d1bc911801cedc65156d2cf1c148c699 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6c0bfa799a49c01ca1118735aed319c8ba59e577 Dynamic Signature Compilation Timestamp:04-20-2026 22:02:12 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e7aec615ff0a9f52f229899a96ade4530bf88e2c Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a18f70d260ee13916f059b52cd5c5d04ae794ad Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d181c9c68a5c760657d05fd355f829eb17dfd89e Dynamic Signature Compilation Timestamp:04-21-2026 07:28:05 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f62e090107b04d9f5367cba829a7d55546b75dc3 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:06 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9920e681a469146a76a702bf87deb6e4b50c18d2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:06 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3d7e5716dfacfdcb913a3a51c0a9dd801620d7c9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\15024a8c62ebf2193da273f303376ebb5e192f59 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7eaa491246cf324fbf0488e302c5c78fd3237ff2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:07 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31a56b54b6c64dcee619761ff13da2b8fb84ebcb Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f9cc16be50890da474b4833fcea11dc0e8ee7f7f Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f763419f84cf610e7382ebcd5d132093a8b5cf42 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\761f0eb4add16d497c66cbc7ce62353afbcd8edc Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5d495e773a9c3f5df5b2885f0ac9a8ccae9104b2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e323afb58aa9eda56bbe42e9ffa629ad7529e5f6 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\28c3a498fd3d13b0703ffd2c428b01ea9ac00fac Dynamic Signature Compilation Timestamp:04-21-2026 07:28:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b34aa7643004a4868d9f83f57f75b05c9729e5f2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:10 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\93cc53a14baa40346794971c0fa29dc81f169c4c Dynamic Signature Compilation Timestamp:04-21-2026 07:28:10 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c67e08f2055b41f7f6eecbd04adaa57a45ca3987 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d54da2a146381dbf49405864bdd6933278629821 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6569becc09b660c62b7406aae1b1760d432d9c1 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bd4e2dfca6e14202b350f7a62516dc3f924cfa3f Dynamic Signature Compilation Timestamp:04-21-2026 07:28:11 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d917b8debc8178763db6db50a485c64ff770cb38 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\454f04897f28bd6e2611538a7dd0133a9b2424b5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\463be1d96f9a93839e0cc41871ef06bd13685f93 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:12 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46da5baedc7d9cf8658891d4084e8c6e633acdf3 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f031d4de0a781abe85d0a0a0f303a52bcda75439 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\20df2342d5821e5b3f518c2f3f7e8e8b93aaa05d Dynamic Signature Compilation Timestamp:04-21-2026 07:28:13 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48fe992a4c92c3c5bae304cb28692ca44215a931 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9f2c7d38e3af20f0bc434cf53f17c7d8a0b29be9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\220a9ae07083a25a19b5ebe4c919847b6d9d4700 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:14 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62a7befa6ff9122ba3b2b0ee3ff2bb4f19658302 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\59f81675cb32d990c32f79d387ff81cf077abeb9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\06bc47c7dca5da5812d723739503084c984cd8af Dynamic Signature Compilation Timestamp:04-21-2026 07:28:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\80a679da9de4bdeefc14d0433befdab62ceb9c5d Dynamic Signature Compilation Timestamp:04-21-2026 07:28:16 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9cce68d7fc65b3a5ffdedcc9756b0c1d66c018b8 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:26 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\455a92b509e470d2871948a21bb27f0e1535e62a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:26 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ac1a57b452e752ec23ce739a0b96f5aca98d7f5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:27 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8c217a73d98084f95a5bb6df43055cc1126115e5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:27 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3f4d4f37bbb5995ee48a1579d64d1e8e671f5ae8 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:28 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4e542b0bef7638a504a86ae42a203e87b98785d2 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:29 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a8ad41ae71d79e3a58729435761047af005d690a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:29 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdd2ff34e20bfc31834279846c4d740f89c0e426 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:30 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\961da9ff43b1d7ce4b44f691fe51862cd40f1cea Dynamic Signature Compilation Timestamp:04-21-2026 07:28:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7843de7e3717c4c1147095caeb09ef70e079f0a9 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\410d57215d0bb71340881e0ee21cf27161989f52 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\16eaa6e2dc20e9ea768e538fd280daff156d5fbc Dynamic Signature Compilation Timestamp:04-21-2026 07:28:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3c5ed6b8853a6dd3e0fee7dad9e575182c9045ee Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d9f0115c553a3736ba55b7547fdd68e74762fe8e Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\72eb101c9777fa8e1faac8bff01e0718aaf2f7d5 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d6db0a31747ca71d702be172edb58e75803cfe7a Dynamic Signature Compilation Timestamp:04-21-2026 07:28:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.220 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\481501cd0a2dc402571573be260a536e7151ce59 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\26527814d606f5b1fbaf207bc874b91c7d41cfa7 Dynamic Signature Compilation Timestamp:04-21-2026 07:28:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T09:46:40.235 MpWriteUupSignatureVersion 1.449.367.0, hr = 0 2026-05-01T09:46:40.235 [SigStatUpd] CSignatureStatus: back to good 2026-05-01T09:46:40.235 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-01T09:46:40.267 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-01T09:46:40.267 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-01T09:46:40.267 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-01T09:46:40.267 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-05-01T09:46:40.267 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValiditApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-01T09:46:40.282 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-01T09:46:40.282 [Plugin] Initializing RTP plugin state... 2026-05-01T09:46:40.282 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2378 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13661 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2674 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-01T09:46:40.282 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-01T09:46:40.282 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7} 2026-05-01T09:46:40.282 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:46:40.282 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:46:40.282 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:46:40.282 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-01T09:46:40.282 MdCoreSvc is supported in this platform and OS 2026-05-01T09:46:40.282 Engine loaded! 2026-05-01T09:46:40.282 [DLP] Create FeatureControlState instance 2026-05-01T09:46:40.282 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-01T09:46:40.282 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-01T09:46:40.282 RegisterSModeChangeListener: hr = 0x1 2026-05-01T09:46:40.282 RegisterHybridModeChangeListener: hr = 0 2026-05-01T09:46:40.298 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-01T09:46:40.298 [SigReleaseHb] Initialized with Stage 0 2026-05-01T09:46:40.298 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-01T09:46:40.298 [SCC][CID=27015_5388] Initializing ... 2026-05-01T09:46:40.298 [SCC][CID=27015_5388] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-01T09:46:40.314 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-01T09:46:40.314 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-01T09:46:40.314 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-01T09:46:40.314 [NRI] Stopping NIS service ... 2026-05-01T09:46:40.314 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-01T09:46:40.314 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.367.0 AV Signature Version: 1.449.367.0 ************************************************************ 2026-05-01T09:46:40.314 Resource usage Monitoring is enabled 2026-05-01T09:46:40.314 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-01T09:46:40.314 Job Notification: New process added to job (4688) 2026-05-01T09:46:40.314 Job Notification: New process added to job (7364) 2026-05-01T09:46:40.329 Job Notification: New process added to job (7376) 2026-05-01T09:46:40.329 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7364] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7376]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-01T09:46:40.407 Job Notification: Process exited from job (7364) 2026-05-01T09:46:40.407 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-01T09:46:40.407 Job Notification: Process exited from job (7376) 2026-05-01T09:46:40.407 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-01T09:46:40.407 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-01T09:46:40.423 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-01T09:46:40.423 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-01T09:46:40.423 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-01T09:46:40.423 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-01T09:46:40.423 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-01T09:46:40.423 [RTP] Generating the base plugin configuration ... 2026-05-01T09:46:40.423 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-01T09:46:40.423 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T09:46:40.423 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-01T09:46:40.423 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-01T09:46:40.423 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T09:46:40.423 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-01T09:46:40.423 [RTP] [RTP] StartCommunication 0x000001CC9910A120 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-01T09:46:40.423 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-01T09:46:40.423 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files\uvnc bvba\UltraVNC\logging.dll 2026-05-01T09:46:40.735 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-01T09:46:40.735 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-01T09:46:40.735 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-01T09:46:40.939 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T09:46:43.517 [RTP] Duplicating the current plugin configuration object... 2026-05-01T09:46:43.517 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T09:46:43.517 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-01T09:46:43.517 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-01T09:46:43.517 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-01T09:46:53.079 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7DE573F3-A3A3-422A-B24A-5C99E0F357521ea0.1dcd94f6f86b951 2026-05-01T09:46:53.189 Verifying engine and signature files (source: 0) ... 2026-05-01T09:46:53.189 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpengine.dll] due to PPL. 2026-05-01T09:46:53.189 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpasbase.vdm] (file in cache) 2026-05-01T09:46:53.189 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-01T09:46:53.204 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpasdlta.vdm] 2026-05-01T09:46:53.204 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpavbase.vdm] (file in cache) 2026-05-01T09:46:53.204 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-01T09:46:53.220 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpavdlta.vdm] 2026-05-01T09:46:53.407 [Engine] IsHybridMode: 0 2026-05-01T09:46:53.407 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-01T09:46:53.407 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7D16801563B66A010C67D7622C01BA4C6F289479.bin): 0x00000002 2026-05-01T09:46:53.423 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-7D16801563B66A010C67D7622C01BA4C6F289479.bin) 2026-05-01T09:46:53.423 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-01T09:46:53.423 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-01T09:46:53.423 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-01T09:46:53.423 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-05-01T09:47:06.959 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-01T09:47:06.959 [RTP] Duplicating the current plugin configuration object... 2026-05-01T09:47:06.959 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T09:47:06.959 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-01T09:47:06.959 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-01T09:47:06.959 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-01T09:47:07.318 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-01T09:47:08.115 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-01T09:47:31.707 Process scan (poststartupscan) started. 2026-05-01T09:47:31.708 Process scan (poststartupscan) completed. 2026-05-01T09:47:32.217 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-01T09:47:32.226 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-01T09:47:34.587 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3676, FileId: 0x2a000000032905, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:47:34.781 [RTP] Duplicating the current plugin configuration object... 2026-05-01T09:47:34.781 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T09:47:34.781 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-01T09:47:34.788 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-01T09:47:34.791 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-01T09:48:13.305 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-01T09:48:13.305 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-01T09:48:13.321 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF8312E8020, lRefCount: 5, hr=0 2026-05-01T09:48:13.321 [Engine] New active engine 00007FF82C678020 replacing engine 00007FF8312E8020. Number of active engines: 2 2026-05-01T09:48:13.321 EngineInit:Global ASOC is enabled 2026-05-01T09:48:13.321 EngineInit:ASOO is enabled for developer volumes 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.399 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.415 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T09:48:13.415 MpWriteUupSignatureVersion 1.449.383.0, hr = 0 2026-05-01T09:48:13.415 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-01T09:48:13.430 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-01T09:48:13.430 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-01T09:48:13.430 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-01T09:48:13.430 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-01T09:48:13.430 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-01T09:48:13.462 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-01T09:48:13.462 [Plugin] Initializing RTP plugin state... 2026-05-01T09:48:13.462 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎01‎-‎2026 11:46:40 Last Perf:‎05‎-‎01‎-‎2026 11:46:40 First RTP Scan:‎05‎-‎01‎-‎2026 11:46:40 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2003 Misses:3089 BM Queue:0,300,0 Proc:0,239,0 File:0,148,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5235 Pending:1 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:7723016 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6028 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:23088 TotalHits:11960 InstanceCacheInserts:278 InstanceCacheUpdates:0 InstanceCacheDeletes:40 InstanceCacheHits:0 InstanceCacheMisses:6958 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (525/123) Success: 123, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-01T09:48:13.462 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-01T09:48:13.462 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878} 2026-05-01T09:48:13.462 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7}\mpasbase.vdm in use, hr=0x80070020 2026-05-01T09:48:13.462 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-01T09:48:13.462 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{67C17419-5D67-42BC-91DD-A719ABEAD16C} removed 2026-05-01T09:48:13.462 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.462 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.462 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.462 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.477 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-01-2026 09:48:13 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-01-2026 09:48:13 2026-05-01T09:48:13.477 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-01T09:48:13.477 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-01T09:48:13.477 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T09:48:13.477 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-01T09:48:13.477 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T09:48:13.477 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.477 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.477 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.477 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-01T09:48:13.477 MdCoreSvc is supported in this platform and OS Signature updated on 05-01-2026 09:48:13 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.383.0 AV Signature Version: 1.449.383.0 ************************************************************ 2026-05-01T09:48:13.477 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-01T09:48:13.477 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\7DE573F3-A3A3-422A-B24A-5C99E0F357521ea0.1dcd94f6f86b951 2026-05-01T09:48:13.587 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-01T09:48:13.587 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-01T09:48:13.930 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-01T09:48:13.930 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-01T09:48:13.930 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-01T09:48:14.290 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-01T09:48:14.290 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-01T09:48:14.305 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-01T09:48:14.305 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-01T09:48:14.305 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-01T09:48:14.305 [Engine] Engine 00007FF8312E8020 no longer in use. Number of active engines: 1 2026-05-01T09:48:14.305 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T09:48:14.305 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-01T09:48:14.430 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15515, Count: 192, MaxTime: 2187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 72% 2026-05-01T09:48:14.430 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 7276, Count: 118, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 13% 2026-05-01T09:48:14.430 ProcessImageName: AsPowerBar.exe, Pid: 6944, TotalTime: 3974, Count: 18, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 24% 2026-05-01T09:48:14.430 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 2981, Count: 83, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 60% 2026-05-01T09:48:14.430 ProcessImageName: DipAwayMode.exe, Pid: 7384, TotalTime: 2150, Count: 15, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 11% 2026-05-01T09:48:14.430 ProcessImageName: MOM.exe, Pid: 12372, TotalTime: 2023, Count: 30, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 35% 2026-05-01T09:48:14.430 ProcessImageName: AISuite3.exe, Pid: 7020, TotalTime: 1353, Count: 21, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 6% 2026-05-01T09:48:14.430 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 998, Count: 6, MaxTime: 593, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 1% 2026-05-01T09:48:14.430 ProcessImageName: websockify.exe, Pid: 12400, TotalTime: 834, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 52% 2026-05-01T09:48:14.430 ProcessImageName: FileCoAuth.exe, Pid: 2720, TotalTime: 472, Count: 27, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileSyncSessions.dll, EstimatedImpact: 5% 2026-05-01T09:48:14.430 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 453, Count: 2, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-05-01T09:48:14.430 ProcessImageName: WmiPrvSE.exe, Pid: 4056, TotalTime: 435, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 20% 2026-05-01T09:48:14.430 ProcessImageName: TeamViewer.exe, Pid: 8076, TotalTime: 332, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 2% 2026-05-01T09:48:14.430 ProcessImageName: WhatsApp.Root.exe, Pid: 7788, TotalTime: 180, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 0% 2026-05-01T09:48:14.493 [Engine] RSIG_UNLOADENGINE, 00007FF8312E8020, err=0x0 2026-05-01T09:48:14.493 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04895652-63B3-4A11-BFF3-4437E876EFC7} removed 2026-05-01T09:48:30.565 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T09:48:30.565 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T09:48:30.565 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T09:48:51.153 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #6372, FileId: 0x50000000027fb2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:51:40.304 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T09:52:02.717 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7203, FileId: 0x51000000028245, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.204 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7398, FileId: 0x4800000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.204 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7399, FileId: 0x4000000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.204 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7397, FileId: 0x3f00000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.220 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7401, FileId: 0x4400000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.220 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7402, FileId: 0x4d00000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.220 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7403, FileId: 0x4e00000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.220 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7404, FileId: 0x5000000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.220 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7400, FileId: 0x4900000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.235 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7406, FileId: 0x5100000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.235 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7407, FileId: 0x5200000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.235 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7409, FileId: 0x4b00000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.251 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7405, FileId: 0x4900000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.564 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7445, FileId: 0x5500000000f33f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:52:28.579 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0ac623c5-0abc-467b-b8c8-aae4b910f7e2. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #7447, FileId: 0x3600000001ad28, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:53:13.380 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-01T09:56:40.307 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-01T09:56:40.307 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-01T09:56:40.323 Job Notification: New process added to job (2508) 2026-05-01T09:56:40.323 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-01T09:56:40.323 Aggressive catchup quick scan threshold: 882121527291 / 25920000000000 2026-05-01T09:56:40.339 Job Notification: New process added to job (2272) 2026-05-01T09:56:40.339 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:2508] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2272]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-01T09:56:40.401 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 51308709(ms) from now at 02:11 (00:11 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-01T09:56:40.464 Job Notification: New process added to job (8200) 2026-05-01T09:56:40.464 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-01T09:56:40.479 Job Notification: New process added to job (4064) 2026-05-01T09:56:40.479 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:8200] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4064]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-01T09:56:40.651 Job Notification: New process added to job (12936) 2026-05-01T09:56:40.651 Task(GetDeviceTicket -AccessKey 81F287EE-3D52-0177-4233-86A996590574 ) launched as network service 2026-05-01T09:56:40.854 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-01T09:56:40.854 [RTP] Duplicating the current plugin configuration object... 2026-05-01T09:56:40.854 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T09:56:40.854 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-01T09:56:40.854 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T09:56:40.854 [RTP] No config change detected. Not updating plugin configuration. 2026-05-01T09:56:40.854 [RTP] No config changes found. No configuration switch. 2026-05-01T09:56:40.854 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-01T09:56:41.011 Job Notification: Process exited from job (12936) 2026-05-01T09:56:41.073 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-01T09:56:41.073 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T09:56:41.073 [Cloud] Queued cloud request. 2026-05-01T09:56:41.073 [Cloud] Dequeued cloud request. 2026-05-01T09:56:41.073 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T09:56:41.370 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-01T09:56:41.370 [Cloud] End of cloud request. 2026-05-01T09:56:41.511 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T09:56:47.911 Job Notification: Process exited from job (8200) 2026-05-01T09:56:47.911 Job Notification: Process exited from job (4064) 2026-05-01T09:56:47.989 Job Notification: Process exited from job (2508) 2026-05-01T09:56:47.989 Job Notification: Process exited from job (2272) 2026-05-01T09:56:49.911 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-05-01T09:56:49.911 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-01T09:56:49.911 [RTP] Duplicating the current plugin configuration object... 2026-05-01T09:56:49.911 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T09:56:49.911 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-01T09:56:49.911 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-01T09:56:49.911 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-01T09:56:49.911 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-01T09:56:49.943 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-01T09:56:49.989 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\$Recycle.Bin\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-01T09:56:50.036 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-01T09:57:31.696 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-01T09:57:51.457 Process scan (postsignatureupdatescan) completed. 2026-05-01T09:58:07.681 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #9319, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:58:07.681 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #9320, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.054 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD8D59E910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9657, FileId: 0x61000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.085 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj365CE5913. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9661, FileId: 0x62000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.085 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB7887D959. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9663, FileId: 0x72000000013147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.179 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj58667C969. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9669, FileId: 0x34000000035b72, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.210 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE38F7B987. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9672, FileId: 0x65000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.532 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1BEAC971. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9688, FileId: 0x24000000035b80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.564 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDEE180912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9689, FileId: 0x70000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:01.767 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj41200C9F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9687, FileId: 0x6d000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:02.505 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E8CA4912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9749, FileId: 0x72000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:02.578 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE41F06947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9758, FileId: 0x73000000035aba, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:02.607 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1FCE8091C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9761, FileId: 0x49000000035ba6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:02.626 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjABC6B0927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9762, FileId: 0x4a000000035ba6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:15.789 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9893, FileId: 0x186000000006f26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:15.852 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9897, FileId: 0x1e0000000336e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T09:59:15.961 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9901, FileId: 0x74000000035468, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:00:16.034 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9934, FileId: 0xa5000000001180, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:02:03.328 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #9990, FileId: 0x6430000000006ff, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:06:45.303 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T10:07:02.609 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10876, FileId: 0x40000000035bb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:07:02.921 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-01T10:07:02.921 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-01T10:07:02.921 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-01T10:07:02.921 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-01T10:07:02.921 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-01T10:07:02.952 [RTP] [Mini-filter] OpenWithoutRead notification (1118, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-01T10:07:02.999 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-05-01T10:07:03.093 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:6ABE8624-B5F2-42A3-A88D-F37538396745, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-01T10:07:03.093 Scheduled scan with Id 6ABE8624-B5F2-42A3-A88D-F37538396745 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-01T10:07:03.093 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-01T10:07:03.093 [SFC] System file cache build is not needed (already completed) 2026-05-01T10:07:03.109 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-05-01T10:07:03.265 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-05-01T10:07:03.280 [AutoPurge] Cleanup Routine tasks have started. 2026-05-01T10:07:03.280 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-01T10:07:03.296 [AutoPurge] Verification Routine tasks have started. 2026-05-01T10:07:03.296 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-01T10:07:03.296 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-01T10:07:03.312 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-01T10:07:03.312 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) 2026-05-01T10:07:03.312 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-01-2026 10:07:03 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-01-2026 10:07:03 2026-05-01T10:07:03.343 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-01T10:07:03.343 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-01T10:07:03.343 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-01T10:07:03.343 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-01T10:07:03.343 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-01T10:07:03.562 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-01T10:07:03.577 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-01T10:07:03.609 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-01T10:07:03.624 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-01T10:07:03.624 [AutoPurge] Verification Routine tasks have ended. 2026-05-01T10:07:03.749 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-01T10:07:04.249 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-01T10:07:04.280 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-05-01T10:07:04.374 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-01T10:07:04.390 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-01T10:07:04.843 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-01T10:07:04.921 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-01T10:07:05.062 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-01T10:07:05.077 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-01T10:07:05.109 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:07:05.124 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T10:07:05.124 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:07:05.249 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-01T10:07:05.296 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-01T10:07:05.359 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-01T10:07:05.530 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:05.718 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-01T10:07:05.859 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-01T10:07:06.046 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-01T10:07:06.062 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:06.093 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-01T10:07:06.187 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-01T10:07:06.249 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-01T10:07:06.749 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-01T10:07:07.124 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-01T10:07:07.171 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:07.671 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-01T10:07:07.890 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-01T10:07:08.425 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:08.457 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-01T10:07:08.519 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:08.769 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-01T10:07:08.879 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-01T10:07:09.035 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-01T10:07:09.254 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-01T10:07:09.332 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-01T10:07:09.347 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-01T10:07:09.394 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-01T10:07:09.613 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-01T10:07:09.691 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-01T10:07:10.113 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-01T10:07:10.238 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-01T10:07:10.754 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-01T10:07:10.785 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-01T10:07:11.050 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-01T10:07:11.113 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-01T10:07:11.675 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-01T10:07:11.707 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-01T10:07:11.707 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:11.722 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-01T10:07:11.785 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-01T10:07:11.847 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-01T10:07:11.957 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-01T10:07:12.285 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-01T10:07:12.394 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-05-01T10:07:12.488 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-01T10:07:12.504 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:12.535 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-01T10:07:12.582 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-01T10:07:12.691 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-01T10:07:12.754 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-01T10:07:12.769 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-01T10:07:12.785 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-01T10:07:13.035 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-05-01T10:07:13.207 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-01T10:07:13.222 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-01T10:07:13.457 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-01T10:07:13.504 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-01T10:07:13.879 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-01T10:07:14.050 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:14.097 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-01T10:07:14.347 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-01T10:07:14.363 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-01T10:07:14.972 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-01T10:07:15.050 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-01T10:07:15.050 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-01T10:07:15.160 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-01T10:07:15.175 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-01T10:07:15.207 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-01T10:07:15.597 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-01T10:07:15.660 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-01T10:07:15.769 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-01T10:07:15.800 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-01T10:07:15.957 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-01T10:07:16.097 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-01T10:07:16.160 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-01T10:07:16.191 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-01T10:07:16.332 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-01T10:07:16.613 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:16.941 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-01T10:07:16.988 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-01T10:07:16.988 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:17.066 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:17.800 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:17.879 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:18.211 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-01T10:07:18.258 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-01T10:07:18.430 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-01T10:07:18.524 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-01T10:07:18.570 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:18.586 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-01T10:07:18.945 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-01T10:07:19.039 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-01T10:07:19.117 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-01T10:07:19.211 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-01T10:07:19.383 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-01T10:07:19.492 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-01T10:07:19.633 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-01T10:07:19.742 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-01T10:07:19.836 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-01T10:07:19.852 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-01T10:07:19.867 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-01T10:07:20.102 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-01T10:07:20.102 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-01T10:07:20.274 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-01T10:07:20.774 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-01T10:07:21.045 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-01T10:07:21.107 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-05-01T10:07:21.513 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-01T10:07:21.576 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-01T10:07:21.638 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-01T10:07:21.717 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-01T10:07:21.826 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-01T10:07:21.826 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-01T10:07:21.982 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-01T10:07:22.185 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-05-01T10:07:22.201 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-01T10:07:22.467 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-01T10:07:22.592 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-01T10:07:22.888 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-01T10:07:22.982 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-01T10:07:23.123 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-01T10:07:23.498 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-01T10:07:23.576 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-01T10:07:23.623 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-01T10:07:23.873 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-01T10:07:23.873 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-01T10:07:24.013 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-01T10:07:24.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-01T10:07:24.248 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-01T10:07:24.342 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-01T10:07:24.357 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:24.623 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-01T10:07:24.904 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-01T10:07:24.935 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-01T10:07:24.982 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-01T10:07:25.092 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-01T10:07:25.388 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-01T10:07:25.467 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:25.482 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-01T10:07:25.763 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:26.310 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-01T10:07:26.435 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-01T10:07:26.545 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-01T10:07:26.920 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-01T10:07:26.951 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-01T10:07:26.967 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-01T10:07:27.263 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-01T10:07:27.529 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-01T10:07:27.560 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-01T10:07:27.701 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-01T10:07:27.857 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-01T10:07:27.857 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-01T10:07:28.092 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-01T10:07:28.268 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-01T10:07:28.283 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-01T10:07:28.377 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-01T10:07:28.783 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-01T10:07:28.846 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-01T10:07:28.846 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-01T10:07:29.096 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-01T10:07:29.596 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-01T10:07:29.737 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-01T10:07:29.830 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-01T10:07:29.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-01T10:07:30.033 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-01T10:07:30.127 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-01T10:07:30.158 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-01T10:07:30.299 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:30.424 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-01T10:07:30.596 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-01T10:07:30.705 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-01T10:07:30.940 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-01T10:07:31.158 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-01T10:07:31.190 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-01T10:07:31.283 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-01T10:07:31.955 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-01T10:07:32.424 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-01T10:07:32.455 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-01T10:07:32.705 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-01T10:07:32.737 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-01T10:07:33.319 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-01T10:07:33.772 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-01T10:07:33.835 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-01T10:07:34.022 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-01T10:07:34.257 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-01T10:07:34.288 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-01T10:07:34.616 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-01T10:07:34.694 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-01T10:07:34.741 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-01T10:07:34.788 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-01T10:07:34.882 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-01T10:07:35.272 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-05-01T10:07:35.350 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-01T10:07:35.616 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-01T10:07:35.678 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-01T10:07:35.678 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-01T10:07:36.272 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-01T10:07:36.553 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-01T10:07:36.694 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-01T10:07:36.897 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:37.007 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:37.053 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-01T10:07:37.053 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:37.116 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-01T10:07:37.257 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-01T10:07:37.319 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-01T10:07:37.397 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-01T10:07:37.522 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-01T10:07:37.538 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-01T10:07:37.553 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-01T10:07:37.600 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-01T10:07:37.600 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-01T10:07:37.882 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-01T10:07:37.882 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-01T10:07:37.928 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-01T10:07:38.022 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-01T10:07:38.147 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-01T10:07:38.647 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-01T10:07:38.928 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-01T10:07:39.178 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-01T10:07:39.335 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-01T10:07:39.413 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:39.600 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-01T10:07:39.913 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-01T10:07:39.975 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-01T10:07:40.147 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-01T10:07:40.241 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-01T10:07:40.491 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.40781.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1326.6317.dll", hr=0x800710da 2026-05-01T10:07:40.569 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-01T10:07:40.632 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-01T10:07:40.678 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-01T10:07:40.710 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-01T10:07:40.710 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-01T10:07:40.772 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:41.042 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-01T10:07:41.058 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-01T10:07:41.245 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-05-01T10:07:41.558 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-01T10:07:41.698 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-01T10:07:42.230 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-01T10:07:42.573 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-01T10:07:42.636 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-01T10:07:42.683 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-01T10:07:43.136 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-01T10:07:43.495 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-01T10:07:43.839 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-01T10:07:43.886 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-01T10:07:44.120 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-01T10:07:44.386 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-01T10:07:44.464 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-01T10:07:44.511 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-05-01T10:07:44.620 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-01T10:07:44.683 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:44.714 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-01T10:07:44.839 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-05-01T10:07:44.933 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-01T10:07:45.183 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-01T10:07:45.214 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-01T10:07:45.948 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-01T10:07:46.183 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-01T10:07:46.277 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:46.402 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-01T10:07:46.808 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-01T10:07:46.902 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-01T10:07:46.964 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-01T10:07:46.980 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-01T10:07:47.042 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-01T10:07:47.058 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:47.183 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-01T10:07:47.245 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-01T10:07:47.339 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-01T10:07:47.417 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-01T10:07:47.495 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:07:47.605 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-01T10:07:47.902 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-01T10:07:47.980 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-01T10:07:48.136 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-01T10:07:48.343 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-01T10:07:48.437 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-01T10:07:48.828 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-01T10:07:48.922 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:49.218 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-01T10:07:49.593 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-01T10:07:49.953 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-01T10:07:50.265 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-05-01T10:07:50.390 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-01T10:07:50.500 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-01T10:07:51.047 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-01T10:07:51.234 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-01T10:07:51.250 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-01T10:07:51.343 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:51.468 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-01T10:07:51.484 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-01T10:07:51.640 Engine:Triggered AR EMS scan 2026-05-01T10:07:51.656 Engine:EMS scan for process: lsass pid: 768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.672 Engine:EMS scan for process: svchost pid: 984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.687 Engine:EMS scan for process: svchost pid: 804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.687 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.687 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.703 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.703 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.703 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.718 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.718 Engine:EMS scan for process: svchost pid: 1448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.718 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.718 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.734 Engine:EMS scan for process: svchost pid: 1584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.734 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.734 Engine:EMS scan for process: svchost pid: 1688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.734 Engine:EMS scan for process: svchost pid: 1740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.750 Engine:EMS scan for process: svchost pid: 1932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.750 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.750 Engine:EMS scan for process: svchost pid: 2096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.765 Engine:EMS scan for process: svchost pid: 2112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.765 Engine:EMS scan for process: svchost pid: 2184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.765 Engine:EMS scan for process: svchost pid: 2384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.765 Engine:EMS scan for process: svchost pid: 2412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.781 Engine:EMS scan for process: svchost pid: 2712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.797 Engine:EMS scan for process: svchost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.797 Engine:EMS scan for process: svchost pid: 3000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.797 Engine:EMS scan for process: svchost pid: 2248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.812 Engine:EMS scan for process: svchost pid: 2976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.812 Engine:EMS scan for process: svchost pid: 3172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.828 Engine:EMS scan for process: svchost pid: 3688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.828 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.828 Engine:EMS scan for process: svchost pid: 3844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.843 Engine:EMS scan for process: svchost pid: 3864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.843 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.859 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.859 Engine:EMS scan for process: svchost pid: 2264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.859 Engine:EMS scan for process: svchost pid: 4204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.859 Engine:EMS scan for process: svchost pid: 4220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.875 Engine:EMS scan for process: svchost pid: 4248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.890 Engine:EMS scan for process: svchost pid: 4416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.890 Engine:EMS scan for process: svchost pid: 4524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.890 Engine:EMS scan for process: svchost pid: 4620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.906 Engine:EMS scan for process: svchost pid: 4680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.906 Engine:EMS scan for process: svchost pid: 5216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.906 Engine:EMS scan for process: dllhost pid: 5904, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.922 Engine:EMS scan for process: svchost pid: 5992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.922 Engine:EMS scan for process: svchost pid: 6036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.922 Engine:EMS scan for process: svchost pid: 3384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.922 Engine:EMS scan for process: svchost pid: 788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.937 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.937 Engine:EMS scan for process: svchost pid: 3180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.953 Engine:EMS scan for process: svchost pid: 8136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.953 Engine:EMS scan for process: svchost pid: 8172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.968 Engine:EMS scan for process: svchost pid: 4500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.968 Engine:EMS scan for process: svchost pid: 7128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.968 Engine:EMS scan for process: svchost pid: 7732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:51.968 Engine:EMS scan for process: explorer pid: 3644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.031 Engine:EMS scan for process: svchost pid: 8068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.031 Engine:EMS scan for process: svchost pid: 8288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.047 Engine:EMS scan for process: svchost pid: 9064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.047 Engine:EMS scan for process: svchost pid: 6740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.047 Engine:EMS scan for process: svchost pid: 9224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.047 Engine:EMS scan for process: svchost pid: 10156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.062 Engine:EMS scan for process: dllhost pid: 10320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.062 Engine:EMS scan for process: svchost pid: 12988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.062 Engine:EMS scan for process: svchost pid: 13296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.078 Engine:EMS scan for process: svchost pid: 3584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.078 Engine:EMS scan for process: svchost pid: 9236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.078 Engine:EMS scan for process: svchost pid: 13188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.093 Engine:EMS scan for process: svchost pid: 10516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.093 Engine:EMS scan for process: svchost pid: 7860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.093 Engine:EMS scan for process: svchost pid: 2076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.093 Engine:EMS scan for process: svchost pid: 3260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.109 Engine:EMS scan for process: svchost pid: 6204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.125 Engine:EMS scan for process: svchost pid: 5436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.125 Engine:EMS scan for process: svchost pid: 4544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.125 Engine:EMS scan for process: svchost pid: 4332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.125 Engine:EMS scan for process: svchost pid: 4792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:07:52.422 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-01T10:07:52.453 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-01T10:07:52.531 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-01T10:07:52.812 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-01T10:07:52.828 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-05-01T10:07:53.062 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-01T10:07:53.156 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-01T10:07:53.218 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-01T10:07:53.234 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-01T10:07:53.390 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-01T10:07:54.203 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-01T10:07:54.547 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-01T10:07:54.562 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-01T10:07:54.625 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-01T10:07:54.922 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:55.031 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-01T10:07:55.422 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-01T10:07:55.422 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-01T10:07:55.422 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-01T10:07:55.718 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-01T10:07:55.890 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-01T10:07:56.515 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-01T10:07:56.656 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-01T10:07:57.000 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-05-01T10:07:57.125 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-01T10:07:57.172 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-05-01T10:07:57.218 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-01T10:07:58.172 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-01T10:07:58.207 Engine:Setting original file name "_Project Import.exe" for "c:\program files\microsoft office\root\office16\projimpt.exe", hr=0x800710da 2026-05-01T10:07:58.332 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-01T10:07:58.379 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-01T10:07:58.598 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-05-01T10:07:58.645 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-01T10:07:58.738 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-01T10:07:58.817 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-01T10:07:58.988 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-01T10:07:59.004 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-05-01T10:07:59.035 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-01T10:07:59.238 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-01T10:07:59.285 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-01T10:07:59.363 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-01T10:07:59.395 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-01T10:07:59.395 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-01T10:07:59.692 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-01T10:07:59.832 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-01T10:07:59.895 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-01T10:07:59.926 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-01T10:08:00.254 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-01T10:08:00.363 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-01T10:08:00.395 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-01T10:08:00.395 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-01T10:08:00.692 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-01T10:08:01.087 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-01T10:08:01.180 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-05-01T10:08:01.290 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-05-01T10:08:01.415 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-01T10:08:01.508 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-05-01T10:08:01.649 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-05-01T10:08:01.758 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-05-01T10:08:01.868 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-05-01T10:08:01.993 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-05-01T10:08:02.055 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-05-01T10:08:02.087 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-05-01T10:08:02.321 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-05-01T10:08:02.399 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-05-01T10:08:02.415 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-05-01T10:08:02.430 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-01T10:08:03.040 OriginalFileName Maintenance::9925 files in Moac, 248 skipped (cached), 1 filename set 2026-05-01T10:08:03.040 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-01T10:08:28.835 ExpensiveFile:Scan time for `\\?\C:\Program Files\Microsoft Office\root\Office16\livecapture.bundle` is 8671 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EBAD029E3, sigsha=a80b7cfbca5c0e7f9fba5768d931c4e463118bd7, cached=false, source=0, resourceid=0xefee283a Internal signature match:subtype=Lowfi, sigseq=0x0000157E6A855602, sigsha=0994c4a442027631466fa0fa9a785e5f4c9a4e22, cached=false, source=0, resourceid=0xefee283a Internal signature match:subtype=Lowfi, sigseq=0x0000157E79D31496, sigsha=ea85fbc31c099b374f0738a1e88ece004ab148bb, cached=false, source=0, resourceid=0xefee283a Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xefee283a 2026-05-01T10:08:46.052 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T10:08:46.052 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T10:08:46.052 [Cloud] Queued cloud request. 2026-05-01T10:08:46.052 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T10:08:46.052 [Cloud] Dequeued cloud request. 2026-05-01T10:08:46.052 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T10:08:46.458 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\57c248f31c3d21d7fce9de0ecb5244c3bcf8f3fb Dynamic Signature Compilation Timestamp:05-01-2026 10:08:45 Persistence Type:Duration Time remaining:1728000000 2026-05-01T10:08:46.458 [Cloud] End of cloud request. 2026-05-01T10:08:46.458 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T10:08:46.989 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-01T10:08:47.005 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-01T10:08:47.005 [RTP] Duplicating the current plugin configuration object... 2026-05-01T10:08:47.005 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T10:08:47.005 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-01T10:08:47.005 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T10:08:47.005 [RTP] No config change detected. Not updating plugin configuration. 2026-05-01T10:08:47.005 [RTP] No config changes found. No configuration switch. 2026-05-01T10:08:47.005 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-01T10:08:47.005 [RTP] Duplicating the current plugin configuration object... 2026-05-01T10:08:47.005 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T10:08:47.005 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-01T10:08:47.005 [RTP] No config change detected. Not updating plugin configuration. 2026-05-01T10:08:47.005 [RTP] No config changes found. No configuration switch. 2026-05-01T10:08:47.005 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-01T10:08:47.005 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T10:08:47.005 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-01T10:08:47.005 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-01T10:08:47.005 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-01T10:08:47.005 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-01T10:08:47.005 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-01T10:08:47.005 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-01T10:08:47.021 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T10:08:47.021 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T10:08:47.021 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T10:08:47.068 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 56117069(ms) from now at 03:44 (01:44 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-01T10:08:49.583 [RTP] Duplicating the current plugin configuration object... 2026-05-01T10:08:49.583 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T10:08:49.583 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-01T10:08:49.583 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-01T10:08:49.583 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-01T10:09:16.000 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14843, FileId: 0x21000000032ff4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:09:16.031 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14845, FileId: 0x2800000003300b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:11:30.288 RPC Rundown called on ScanID: 6ABE8624-B5F2-42A3-A88D-F37538396745 2026-05-01T10:11:30.288 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:6ABE8624-B5F2-42A3-A88D-F37538396745. bRemoveFromList(ClientKilled):1 2026-05-01T10:11:30.288 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:6ABE8624-B5F2-42A3-A88D-F37538396745 2026-05-01T10:11:30.288 QuickScan:ScanID:6ABE8624-B5F2-42A3-A88D-F37538396745: User scan error=000003e3 2026-05-01T10:11:30.288 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:6ABE8624-B5F2-42A3-A88D-F37538396745 2026-05-01T10:11:30.288 QuickScan:ScanID:6ABE8624-B5F2-42A3-A88D-F37538396745: Quick scan aborted by callback after end stage 2026-05-01T10:11:30.288 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:6ABE8624-B5F2-42A3-A88D-F37538396745 2026-05-01T10:11:30.288 OnDemandScanWorker: Scan Cancelled! scanId:6ABE8624-B5F2-42A3-A88D-F37538396745, hr = 0x80508018 2026-05-01T10:11:31.206 Engine:Process C:\Windows\System32\svchost.exe (PPID:4248:134221023866906491) is tainted: TaintType:0x4. TaintReason:C:\brynhildr30203\brynhildr.exe, EnableCfa:1 2026-05-01T10:11:32.318 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:11:32.333 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T10:11:32.333 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:11:32.333 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\vritra[1].htm. Process: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, Status: 0xc0000001, State: 0, ScanRequest #14910, FileId: 0x67000000010907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x4c233af3 2026-05-01T10:16:37.643 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:B4FA8ACB-606E-4D99-ACAE-71A6C50830B4, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-01T10:16:37.643 Scheduled scan with Id B4FA8ACB-606E-4D99-ACAE-71A6C50830B4 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-01T10:16:37.643 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-01T10:16:37.643 [SFC] System file cache build is not needed (already completed) 2026-05-01T10:16:38.914 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15679, FileId: 0x24000000032ff4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:16:39.649 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:16:39.664 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T10:16:39.664 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:16:40.430 Engine:Triggered AR EMS scan 2026-05-01T10:16:40.430 Engine:EMS scan for process: lsass pid: 768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.461 Engine:EMS scan for process: svchost pid: 984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.461 Engine:EMS scan for process: svchost pid: 804, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.477 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.477 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.477 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.477 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.492 Engine:EMS scan for process: svchost pid: 1584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 1688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 1740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 1932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.508 Engine:EMS scan for process: svchost pid: 2096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.524 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 2652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 2712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 3000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.539 Engine:EMS scan for process: svchost pid: 2248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.555 Engine:EMS scan for process: svchost pid: 2976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.555 Engine:EMS scan for process: svchost pid: 3172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.555 Engine:EMS scan for process: svchost pid: 3688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.555 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.555 Engine:EMS scan for process: svchost pid: 3844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.570 Engine:EMS scan for process: svchost pid: 3864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.570 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.570 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.570 Engine:EMS scan for process: svchost pid: 2264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.586 Engine:EMS scan for process: svchost pid: 4204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.586 Engine:EMS scan for process: svchost pid: 4220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.586 Engine:EMS scan for process: svchost pid: 4248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.602 Engine:EMS scan for process: svchost pid: 4416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.602 Engine:EMS scan for process: svchost pid: 4524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.602 Engine:EMS scan for process: svchost pid: 4620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.602 Engine:EMS scan for process: svchost pid: 4680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 5216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: dllhost pid: 5904, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 5992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 6036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 3384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.617 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.633 Engine:EMS scan for process: svchost pid: 3180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.633 Engine:EMS scan for process: svchost pid: 8136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.633 Engine:EMS scan for process: svchost pid: 8172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.649 Engine:EMS scan for process: svchost pid: 4500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.649 Engine:EMS scan for process: svchost pid: 7128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.664 Engine:EMS scan for process: svchost pid: 7732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.664 Engine:EMS scan for process: explorer pid: 3644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.711 Engine:EMS scan for process: svchost pid: 8068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.711 Engine:EMS scan for process: svchost pid: 8288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.711 Engine:EMS scan for process: svchost pid: 9064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.711 Engine:EMS scan for process: svchost pid: 6740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.727 Engine:EMS scan for process: svchost pid: 9224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.727 Engine:EMS scan for process: svchost pid: 10156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.727 Engine:EMS scan for process: dllhost pid: 10320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.727 Engine:EMS scan for process: svchost pid: 12988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.742 Engine:EMS scan for process: svchost pid: 13296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.742 Engine:EMS scan for process: svchost pid: 3584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.758 Engine:EMS scan for process: svchost pid: 9236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.758 Engine:EMS scan for process: svchost pid: 13188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.789 Engine:EMS scan for process: svchost pid: 10516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.789 Engine:EMS scan for process: svchost pid: 7860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.789 Engine:EMS scan for process: svchost pid: 6204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:40.836 Engine:EMS scan for process: svchost pid: 4792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-01T10:16:54.948 QuickScan:ScanID:B4FA8ACB-606E-4D99-ACAE-71A6C50830B4: Quick scan finished with error 0 2026-05-01T10:16:55.463 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-01T10:16:55.463 [RTP] Duplicating the current plugin configuration object... 2026-05-01T10:16:55.463 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T10:16:55.463 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-01T10:16:55.463 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T10:16:55.463 [RTP] No config change detected. Not updating plugin configuration. 2026-05-01T10:16:55.463 [RTP] No config changes found. No configuration switch. 2026-05-01T10:16:55.463 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-01T10:16:56.963 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:16:56.963 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T10:16:56.963 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T10:17:59.396 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #16431, FileId: 0x2000000000689c, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:18:02.927 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-05-01T10:18:02.927 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-05-01T10:18:02.927 [RTP] Duplicating the current plugin configuration object... 2026-05-01T10:18:02.927 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-01T10:18:02.927 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-01T10:18:02.927 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-01T10:18:02.927 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-01T10:18:03.021 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-05-01T10:18:03.240 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-05-01T10:18:03.240 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-05-01T10:18:15.308 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-05-01T10:18:16.042 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-05-01T10:21:50.302 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T10:36:55.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T10:45:28.821 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\__PSScriptPolicyTest_oh2gayph.cdr.psm1. Process: \Device\HarddiskVolume3\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, Status: 0xc0000001, State: 0, ScanRequest #18168, FileId: 0xb7000000005bfa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:46:40.302 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-05-01T10:48:23.927 Engine:Process C:\Windows\System32\svchost.exe (PPID:4248:134221023866906491) is tainted: TaintType:0x4. TaintReason:C:\brynhildr30203\brynhildr.exe, EnableCfa:1 2026-05-01T10:49:05.113 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18499, FileId: 0x1d6000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.129 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18497, FileId: 0x1d5000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.129 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18500, FileId: 0x5000000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.129 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18502, FileId: 0x1d8000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.145 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18506, FileId: 0x1da000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.145 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18507, FileId: 0x5500000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.145 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18505, FileId: 0x5300000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.160 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18510, FileId: 0x1dd000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.160 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18512, FileId: 0x1df000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.160 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18513, FileId: 0x5800000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.160 Bm signature throttled:0x000045b3435c1067 2026-05-01T10:49:05.160 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18514, FileId: 0x5900000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.160 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18511, FileId: 0x5700000000f425, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.176 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18518, FileId: 0x1e1000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.568 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18560, FileId: 0x1e2000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:49:05.584 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\1f6fa249-484d-47ff-8509-a7a1e74253a1. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #18563, FileId: 0x10a000000000117, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T10:52:00.309 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T11:02:28.580 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #18888, FileId: 0x4e00000000c68a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T11:04:45.868 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18947, FileId: 0x2600000001b24e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T11:07:05.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T11:22:10.303 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T11:37:15.312 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T11:48:13.329 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T11:48:13.329 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 9359, Count: 218, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T11:48:13.329 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T11:48:13.329 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T11:48:13.329 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T11:48:13.329 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T11:48:13.329 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T11:48:13.329 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T11:48:13.329 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T11:48:13.329 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T11:48:13.329 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T11:48:13.329 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T11:48:13.329 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T11:48:13.329 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 290, Count: 17, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 285, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-01.log, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 278, Count: 9, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T11:48:13.329 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T11:48:13.329 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T11:48:13.329 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T11:48:13.329 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T11:48:13.329 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T11:48:13.329 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T11:48:13.329 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T11:48:13.329 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T11:48:13.329 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T11:48:13.329 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T11:48:13.329 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T11:48:13.329 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T11:48:13.329 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T11:48:13.329 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T11:48:13.329 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T11:48:13.329 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T11:48:13.329 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T11:48:13.329 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T11:52:20.305 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T12:07:25.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T12:22:30.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T12:37:35.312 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T12:52:40.299 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T13:07:45.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T13:22:50.298 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T13:37:55.298 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T13:48:13.333 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T13:48:13.333 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 9359, Count: 218, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T13:48:13.333 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T13:48:13.333 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T13:48:13.333 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T13:48:13.333 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T13:48:13.333 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T13:48:13.333 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T13:48:13.333 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T13:48:13.333 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T13:48:13.333 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T13:48:13.333 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T13:48:13.333 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T13:48:13.333 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 350, Count: 21, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 285, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-01.log, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 278, Count: 9, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T13:48:13.333 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T13:48:13.333 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T13:48:13.333 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T13:48:13.333 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T13:48:13.333 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T13:48:13.333 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T13:48:13.333 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T13:48:13.333 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T13:48:13.333 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T13:48:13.333 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T13:48:13.333 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T13:48:13.333 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T13:48:13.333 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T13:48:13.333 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T13:48:13.333 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T13:48:13.333 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T13:48:13.333 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T13:48:13.333 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T13:48:13.333 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T13:48:13.333 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T13:48:13.333 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 1% 2026-05-01T13:48:13.334 ProcessImageName: dasHost.exe, Pid: 5404, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T13:48:13.334 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T13:48:13.334 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T13:48:13.334 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T13:48:13.334 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T13:48:13.334 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T13:48:13.334 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: AdobeARM.exe, Pid: 8084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-05-01T13:48:13.334 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T13:48:13.334 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T13:48:13.334 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T13:53:00.306 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T13:53:19.595 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #20451, FileId: 0x14000000099237, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:00:59.501 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21628, FileId: 0x620000000295fa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:08:05.300 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T14:11:12.971 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #22015, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 2026-05-01T14:11:38.442 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22350, FileId: 0x17000000099c8d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:20:43.706 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22900, FileId: 0x1dc00000000fad2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:23:10.304 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T14:29:33.570 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #23852, FileId: 0x1f00000001ad46, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:29:33.571 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #23853, FileId: 0xfd00000000103c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-01T14:34:54.988 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T14:34:54.988 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T14:34:54.988 [Cloud] Queued cloud request. 2026-05-01T14:34:54.988 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T14:34:54.988 [Cloud] Dequeued cloud request. 2026-05-01T14:34:54.988 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T14:34:55.716 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4baa2a975ac254332543642c124c275ba6e2567f Dynamic Signature Compilation Timestamp:05-01-2026 14:34:54 Persistence Type:Duration Time remaining:288000000 2026-05-01T14:34:55.717 [Cloud] End of cloud request. 2026-05-01T14:34:55.717 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T14:34:56.240 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T14:38:15.307 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T14:43:25.477 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #24990, FileId: 0x2a000000099776, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:43:25.478 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #24987, FileId: 0x10200000000103c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:51:02.989 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25342, FileId: 0xc0000000b5a18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T14:53:20.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T14:55:44.312 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25389, FileId: 0x100000000b5a17, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:00:01.490 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\Other1303.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #25569, FileId: 0xc0000000b5a24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:08:25.303 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2507f149 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2fa030f5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3929cb09 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b8625b3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1030c23b 2026-05-01T15:18:30.685 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:30.685 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:30.685 [Cloud] Queued cloud request. 2026-05-01T15:18:30.685 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:30.685 [Cloud] Dequeued cloud request. 2026-05-01T15:18:30.686 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:30.686 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:30.686 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:30.686 [Cloud] Queued cloud request. 2026-05-01T15:18:30.686 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:30.686 [Cloud] Dequeued cloud request. 2026-05-01T15:18:30.686 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:30.717 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:30.718 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:30.718 [Cloud] Queued cloud request. 2026-05-01T15:18:30.718 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:30.718 [Cloud] Dequeued cloud request. 2026-05-01T15:18:30.718 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:31.088 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a37ea34390297f37bd8babffa23b92908ec9666c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:31.089 [Cloud] End of cloud request. 2026-05-01T15:18:31.089 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:31.090 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae7f01fea3c6bf358dd91cbe01aa4dc093eb7ba5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:31.092 [Cloud] End of cloud request. 2026-05-01T15:18:31.092 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6a653b20 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0b2e1292 2026-05-01T15:18:31.169 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:31.169 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:31.169 [Cloud] Queued cloud request. 2026-05-01T15:18:31.169 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:31.169 [Cloud] Dequeued cloud request. 2026-05-01T15:18:31.169 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:31.179 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\64bff40ec98c3b3fd369ff52000b89bd43b57cf5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:31.180 [Cloud] End of cloud request. 2026-05-01T15:18:31.180 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:31.363 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\788d3a9ca7c5d6e99ba1b4cc20cb37de0d864e4c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:31.364 [Cloud] End of cloud request. 2026-05-01T15:18:31.365 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:31.513 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\1EB9F1DB-0000-0000-0000-402400000000-0.bin loaded. 2026-05-01T15:18:31.601 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9dac68eb 2026-05-01T15:18:32.239 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:32.239 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:32.239 [Cloud] Queued cloud request. 2026-05-01T15:18:32.239 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:32.239 [Cloud] Dequeued cloud request. 2026-05-01T15:18:32.239 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:32.477 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\524fb2b3d96687376a8913d40996d16b8cec431c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:32.478 [Cloud] End of cloud request. 2026-05-01T15:18:32.478 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe50d243b 2026-05-01T15:18:32.544 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:32.544 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:32.544 [Cloud] Queued cloud request. 2026-05-01T15:18:32.544 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:32.544 [Cloud] Dequeued cloud request. 2026-05-01T15:18:32.544 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:32.730 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3d75a6cf878a7ee62a5edf539662344805278263 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:32.732 [Cloud] End of cloud request. 2026-05-01T15:18:32.732 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6e00da19 2026-05-01T15:18:32.795 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:32.795 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:32.795 [Cloud] Queued cloud request. 2026-05-01T15:18:32.795 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:32.795 [Cloud] Dequeued cloud request. 2026-05-01T15:18:32.795 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:33.001 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:33.043 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e15df8806d3440074d0418d2ec7390f362977f56 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:33.044 [Cloud] End of cloud request. 2026-05-01T15:18:33.044 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x154b93d4 2026-05-01T15:18:33.090 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:33.090 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:33.090 [Cloud] Queued cloud request. 2026-05-01T15:18:33.090 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:33.090 [Cloud] Dequeued cloud request. 2026-05-01T15:18:33.090 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6327ac39779aea9af7c9d0c918328196857593c8 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:33.456 Dynamic signature received 2026-05-01T15:18:33.459 [Cloud] End of cloud request. 2026-05-01T15:18:33.459 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x98bdb6ef 2026-05-01T15:18:33.519 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:33.520 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:33.520 [Cloud] Queued cloud request. 2026-05-01T15:18:33.520 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:33.520 [Cloud] Dequeued cloud request. 2026-05-01T15:18:33.520 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:33.565 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:33.727 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\214c1a3f8a698565a1029f30e60865fba73e9b6c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:33.728 [Cloud] End of cloud request. 2026-05-01T15:18:33.728 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9d2b2ee6 2026-05-01T15:18:33.834 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:33.834 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:33.834 [Cloud] Queued cloud request. 2026-05-01T15:18:33.834 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:33.834 [Cloud] Dequeued cloud request. 2026-05-01T15:18:33.834 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:34.151 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fb81bf1c339b9e3b160a219505f0944a48b1aacb Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:34.152 [Cloud] End of cloud request. 2026-05-01T15:18:34.152 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08936cdd 2026-05-01T15:18:34.217 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:34.217 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:34.217 [Cloud] Queued cloud request. 2026-05-01T15:18:34.217 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:34.217 [Cloud] Dequeued cloud request. 2026-05-01T15:18:34.217 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:34.246 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:34.413 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5cbcc272052ff0eeb292e4a97e5f7ebc0f96b0c8 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:34.415 [Cloud] End of cloud request. 2026-05-01T15:18:34.415 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5a6a160b 2026-05-01T15:18:34.478 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:34.478 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:34.478 [Cloud] Queued cloud request. 2026-05-01T15:18:34.479 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:34.479 [Cloud] Dequeued cloud request. 2026-05-01T15:18:34.479 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:34.680 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9737ad241e76c23ed8cfb9ee33032ee3913f039b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:34.681 [Cloud] End of cloud request. 2026-05-01T15:18:34.681 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d98e7c3 2026-05-01T15:18:34.744 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:34.744 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:34.744 [Cloud] Queued cloud request. 2026-05-01T15:18:34.744 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:34.744 [Cloud] Dequeued cloud request. 2026-05-01T15:18:34.745 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:34.924 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\afde081964bfd3a6b88a4da92377919b4ef700dc Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:34.925 [Cloud] End of cloud request. 2026-05-01T15:18:34.925 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:34.926 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc5b1c585 2026-05-01T15:18:34.984 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:34.984 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:34.984 [Cloud] Queued cloud request. 2026-05-01T15:18:34.984 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:34.984 [Cloud] Dequeued cloud request. 2026-05-01T15:18:34.984 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:35.296 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f2b60685a96526c021d1caa8f1a78c5d8e19ccf6 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:35.298 [Cloud] End of cloud request. 2026-05-01T15:18:35.298 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d7386a5 2026-05-01T15:18:35.354 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:35.354 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:35.354 [Cloud] Queued cloud request. 2026-05-01T15:18:35.354 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:35.354 [Cloud] Dequeued cloud request. 2026-05-01T15:18:35.355 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:35.435 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:35.566 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\034f60842adaed83189cf99482259be99836cc56 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:35.566 [Cloud] End of cloud request. 2026-05-01T15:18:35.566 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x09f692c7 2026-05-01T15:18:35.615 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:35.615 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:35.615 [Cloud] Queued cloud request. 2026-05-01T15:18:35.615 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:35.615 [Cloud] Dequeued cloud request. 2026-05-01T15:18:35.615 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:35.810 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe71bd66759359e8c64560666e59a3abd5edab58 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:35.811 [Cloud] End of cloud request. 2026-05-01T15:18:35.811 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe7107927 2026-05-01T15:18:35.874 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:35.874 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:35.874 [Cloud] Queued cloud request. 2026-05-01T15:18:35.874 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:35.875 [Cloud] Dequeued cloud request. 2026-05-01T15:18:35.875 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:36.061 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3063d8dd7adee2d946e0c002d3f2198872dbb599 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:36.062 [Cloud] End of cloud request. 2026-05-01T15:18:36.062 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:36.085 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b5a8dbf 2026-05-01T15:18:36.123 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:36.123 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:36.123 [Cloud] Queued cloud request. 2026-05-01T15:18:36.123 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:36.123 [Cloud] Dequeued cloud request. 2026-05-01T15:18:36.123 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:36.418 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0c4fdd98f53695a914effd18ccad4af9057a79e9 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:36.420 [Cloud] End of cloud request. 2026-05-01T15:18:36.420 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcf06889f 2026-05-01T15:18:36.485 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:36.485 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:36.485 [Cloud] Queued cloud request. 2026-05-01T15:18:36.485 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:36.485 [Cloud] Dequeued cloud request. 2026-05-01T15:18:36.485 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:36.718 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1f9af6a92074546f32369f25e6494ac9c7b03fbe Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:36.719 [Cloud] End of cloud request. 2026-05-01T15:18:36.719 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x574737f0 2026-05-01T15:18:36.791 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:36.792 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:36.792 [Cloud] Queued cloud request. 2026-05-01T15:18:36.792 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:36.792 [Cloud] Dequeued cloud request. 2026-05-01T15:18:36.792 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:36.938 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:36.986 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6bb1155d754f3dd1ee70cd6c814db7379aef447 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:36.987 [Cloud] End of cloud request. 2026-05-01T15:18:36.987 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc0da79fe 2026-05-01T15:18:37.049 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:37.049 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:37.049 [Cloud] Queued cloud request. 2026-05-01T15:18:37.049 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:37.049 [Cloud] Dequeued cloud request. 2026-05-01T15:18:37.049 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\66d5d4220d590ef8181fb06b18ebf66f766e5058 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:37.367 Dynamic signature received 2026-05-01T15:18:37.368 [Cloud] End of cloud request. 2026-05-01T15:18:37.368 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3de92012 2026-05-01T15:18:37.429 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:37.429 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:37.429 [Cloud] Queued cloud request. 2026-05-01T15:18:37.429 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:37.429 [Cloud] Dequeued cloud request. 2026-05-01T15:18:37.429 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:37.510 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:37.650 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d54ae1180575335e42922a4ecc31680835039b82 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:37.651 [Cloud] End of cloud request. 2026-05-01T15:18:37.651 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xefec6f9e 2026-05-01T15:18:37.711 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:37.711 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:37.711 [Cloud] Queued cloud request. 2026-05-01T15:18:37.711 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:37.712 [Cloud] Dequeued cloud request. 2026-05-01T15:18:37.712 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:38.006 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d1ec32751554919a0e7dd28581fcf8c211d62432 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:38.006 [Cloud] End of cloud request. 2026-05-01T15:18:38.007 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5fd9381c 2026-05-01T15:18:38.069 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:38.069 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:38.069 [Cloud] Queued cloud request. 2026-05-01T15:18:38.069 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:38.069 [Cloud] Dequeued cloud request. 2026-05-01T15:18:38.070 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:38.165 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ed6c9b5dcdf0fb706bf704054e5a7bbb2b876135 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:38.404 Dynamic signature received 2026-05-01T15:18:38.405 [Cloud] End of cloud request. 2026-05-01T15:18:38.405 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe34c3b22 2026-05-01T15:18:38.467 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:38.467 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:38.467 [Cloud] Queued cloud request. 2026-05-01T15:18:38.467 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:38.467 [Cloud] Dequeued cloud request. 2026-05-01T15:18:38.468 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:38.660 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a60ac1c93680e494eb8c480f3e10398993cfb023 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:38.663 [Cloud] End of cloud request. 2026-05-01T15:18:38.663 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0e2e7c07 2026-05-01T15:18:38.722 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:38.722 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:38.722 [Cloud] Queued cloud request. 2026-05-01T15:18:38.722 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:38.722 [Cloud] Dequeued cloud request. 2026-05-01T15:18:38.723 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:38.918 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:39.042 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\10572034e7a43a04967c2024cb341e217fee782b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:39.043 [Cloud] End of cloud request. 2026-05-01T15:18:39.043 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xda14f9b8 2026-05-01T15:18:39.105 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:39.105 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:39.105 [Cloud] Queued cloud request. 2026-05-01T15:18:39.105 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:39.106 [Cloud] Dequeued cloud request. 2026-05-01T15:18:39.106 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:39.431 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d48d817a0322726c8ee544bc93cfc5b361fc682e Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:39.434 [Cloud] End of cloud request. 2026-05-01T15:18:39.434 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe758ba89 2026-05-01T15:18:39.499 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:39.499 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:39.499 [Cloud] Queued cloud request. 2026-05-01T15:18:39.499 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:39.499 [Cloud] Dequeued cloud request. 2026-05-01T15:18:39.499 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:39.554 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:39.704 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\623fddf1a6e45c1657d4013daeff2820c36e2a22 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:39.705 [Cloud] End of cloud request. 2026-05-01T15:18:39.705 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfe25d8c0 2026-05-01T15:18:39.774 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:39.774 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:39.774 [Cloud] Queued cloud request. 2026-05-01T15:18:39.774 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:39.774 [Cloud] Dequeued cloud request. 2026-05-01T15:18:39.775 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:39.978 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\67b12f856f3790544fd1553b98de4b8c6491ee80 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:39.978 [Cloud] End of cloud request. 2026-05-01T15:18:39.978 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2e200ff0 2026-05-01T15:18:40.053 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:40.053 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:40.053 [Cloud] Queued cloud request. 2026-05-01T15:18:40.053 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:40.054 [Cloud] Dequeued cloud request. 2026-05-01T15:18:40.054 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:40.221 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:40.258 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\42ef781589943a96c36643e6f0bad717c550814b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:40.259 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:40.259 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0b0d9728 2026-05-01T15:18:40.314 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:40.314 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:40.314 [Cloud] Queued cloud request. 2026-05-01T15:18:40.314 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:40.314 [Cloud] Dequeued cloud request. 2026-05-01T15:18:40.314 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\40991564c4980609dfff134c7fa2f8a7b8b9c14a Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:40.562 Dynamic signature received 2026-05-01T15:18:40.563 [Cloud] End of cloud request. 2026-05-01T15:18:40.563 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc139414f 2026-05-01T15:18:40.635 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:40.635 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:40.635 [Cloud] Queued cloud request. 2026-05-01T15:18:40.635 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:40.635 [Cloud] Dequeued cloud request. 2026-05-01T15:18:40.635 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:40.767 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:40.816 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e9fd7cb314a47c9354f38e23d6367c3a20c9c16 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:40.817 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:40.817 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb1421553 2026-05-01T15:18:40.880 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:40.880 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:40.880 [Cloud] Queued cloud request. 2026-05-01T15:18:40.880 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:40.880 [Cloud] Dequeued cloud request. 2026-05-01T15:18:40.880 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:41.125 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1080f5be4166797b60a9b3f441b7778fc7050ed5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:40 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:41.126 [Cloud] End of cloud request. 2026-05-01T15:18:41.126 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe1e74fb5 2026-05-01T15:18:41.200 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:41.200 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:41.200 [Cloud] Queued cloud request. 2026-05-01T15:18:41.200 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:41.200 [Cloud] Dequeued cloud request. 2026-05-01T15:18:41.200 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:41.340 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:41.472 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\91ce7360f8e948baa72327c7ef52d20edd7939c1 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:40 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:41.472 [Cloud] End of cloud request. 2026-05-01T15:18:41.472 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x808a975e 2026-05-01T15:18:41.606 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:41.606 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:41.606 [Cloud] Queued cloud request. 2026-05-01T15:18:41.606 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:41.606 [Cloud] Dequeued cloud request. 2026-05-01T15:18:41.606 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3be80d0c 2026-05-01T15:18:41.983 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:41.994 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2877a173e1a2bcfe48d9a1e55578d151eeb264a2 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:41 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:41.995 [Cloud] End of cloud request. 2026-05-01T15:18:41.995 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6f20fc74 2026-05-01T15:18:42.063 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:42.063 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:42.063 [Cloud] Queued cloud request. 2026-05-01T15:18:42.063 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:42.063 [Cloud] Dequeued cloud request. 2026-05-01T15:18:42.063 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:42.398 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b0b0940bf02bce066c8f2aae5ac34c56e6b35f98 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:41 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:42.399 [Cloud] End of cloud request. 2026-05-01T15:18:42.399 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:42.511 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc2b54150 2026-05-01T15:18:43.038 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:43.039 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:43.039 [Cloud] Queued cloud request. 2026-05-01T15:18:43.039 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:43.039 [Cloud] Dequeued cloud request. 2026-05-01T15:18:43.039 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:43.228 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\328d988b0a35d385adb0364f540ce762ee70989b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:42 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:43.229 [Cloud] End of cloud request. 2026-05-01T15:18:43.229 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb5394e6f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xee70883d 2026-05-01T15:18:43.335 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:43.335 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:43.335 [Cloud] Queued cloud request. 2026-05-01T15:18:43.335 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:43.335 [Cloud] Dequeued cloud request. 2026-05-01T15:18:43.335 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:43.517 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\278301b479b7f8af9e8b33dfc1847c9bbd08dc16 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:42 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:43.518 [Cloud] End of cloud request. 2026-05-01T15:18:43.518 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:43.752 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:43.814 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:43.814 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:43.814 [Cloud] Queued cloud request. 2026-05-01T15:18:43.814 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:43.814 [Cloud] Dequeued cloud request. 2026-05-01T15:18:43.814 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:44.166 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4fd8ae0a7639264673f037e77087205bb4b64dea Dynamic Signature Compilation Timestamp:05-01-2026 15:18:43 Persistence Type:Duration Time remaining:150196224 2026-05-01T15:18:44.168 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:44.169 [Cloud] End of cloud request. 2026-05-01T15:18:44.693 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x99c3634c 2026-05-01T15:18:45.048 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:45.048 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:45.048 [Cloud] Queued cloud request. 2026-05-01T15:18:45.048 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:45.048 [Cloud] Dequeued cloud request. 2026-05-01T15:18:45.048 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:45.310 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3185471581d590ab54b81875218951913fa9b793 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:44 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:45.311 [Cloud] End of cloud request. 2026-05-01T15:18:45.311 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x63b0d5e2 2026-05-01T15:18:45.566 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:45.567 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:45.567 [Cloud] Queued cloud request. 2026-05-01T15:18:45.567 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:45.567 [Cloud] Dequeued cloud request. 2026-05-01T15:18:45.567 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:45.749 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\20dcb3cef9e1da7fc9553f4b951cf42a3d158f7c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:44 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:45.750 [Cloud] End of cloud request. 2026-05-01T15:18:45.750 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc9225445 2026-05-01T15:18:45.828 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:45.829 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:45.829 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:45.829 [Cloud] Queued cloud request. 2026-05-01T15:18:45.829 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:45.829 [Cloud] Dequeued cloud request. 2026-05-01T15:18:45.830 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdd5dee32910baf7706a17de1a789a9851a78132 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:46.008 Dynamic signature received 2026-05-01T15:18:46.008 [Cloud] End of cloud request. 2026-05-01T15:18:46.008 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf84933c3 2026-05-01T15:18:46.254 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:46.254 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:46.254 [Cloud] Queued cloud request. 2026-05-01T15:18:46.254 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:46.254 [Cloud] Dequeued cloud request. 2026-05-01T15:18:46.254 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e47e396fc34943ff48b72ceaf56b28a577b0ee5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:46.456 Dynamic signature received 2026-05-01T15:18:46.457 [Cloud] End of cloud request. 2026-05-01T15:18:46.457 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb1849d19 2026-05-01T15:18:46.529 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:46.529 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:46.529 [Cloud] Queued cloud request. 2026-05-01T15:18:46.529 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:46.529 [Cloud] Dequeued cloud request. 2026-05-01T15:18:46.529 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:46.531 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ac96b8789ce01b499e962452cf245b68a8d5246 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:46.726 Dynamic signature received 2026-05-01T15:18:46.727 [Cloud] End of cloud request. 2026-05-01T15:18:46.727 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x933d95e8 2026-05-01T15:18:46.786 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:46.786 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:46.786 [Cloud] Queued cloud request. 2026-05-01T15:18:46.786 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:46.786 [Cloud] Dequeued cloud request. 2026-05-01T15:18:46.786 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:47.000 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cedbd927b0682953fe759c910459f136fe93c8c7 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:47.002 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:47.004 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf7e2e928 2026-05-01T15:18:47.113 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:47.113 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:47.113 [Cloud] Queued cloud request. 2026-05-01T15:18:47.113 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:47.113 [Cloud] Dequeued cloud request. 2026-05-01T15:18:47.113 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:47.249 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:47.341 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\abb410a5870e36b1a7b3f4bc13245cd04dd8e253 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:47.342 [Cloud] End of cloud request. 2026-05-01T15:18:47.342 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x773a99d1 2026-05-01T15:18:47.446 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:47.446 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:47.446 [Cloud] Queued cloud request. 2026-05-01T15:18:47.446 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:47.446 [Cloud] Dequeued cloud request. 2026-05-01T15:18:47.446 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:47.867 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:47.992 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b4b8db705bbffce93b0d96ed57244e0a58612995 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:47.995 [Cloud] End of cloud request. 2026-05-01T15:18:47.995 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x33b18282 2026-05-01T15:18:48.099 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:48.099 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:48.099 [Cloud] Queued cloud request. 2026-05-01T15:18:48.099 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:48.099 [Cloud] Dequeued cloud request. 2026-05-01T15:18:48.099 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:48.333 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a4b8dd1b4a818f8a7b29b7adccb91f6dc0671f74 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:48.334 [Cloud] End of cloud request. 2026-05-01T15:18:48.334 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x535712c2 2026-05-01T15:18:48.430 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:48.430 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:48.430 [Cloud] Queued cloud request. 2026-05-01T15:18:48.430 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:48.430 [Cloud] Dequeued cloud request. 2026-05-01T15:18:48.430 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:48.516 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:48.672 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\09bc755c2b4eb96136c423482b1ecb1dae6fc811 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:48.673 [Cloud] End of cloud request. 2026-05-01T15:18:48.673 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5351bd46 2026-05-01T15:18:48.754 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:48.754 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:48.754 [Cloud] Queued cloud request. 2026-05-01T15:18:48.754 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:48.754 [Cloud] Dequeued cloud request. 2026-05-01T15:18:48.754 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:49.186 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4800f287 2026-05-01T15:18:58.754 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume7\xampp\php\ext\php_sockets.dll. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-05-01T15:18:58.819 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x290aa726 2026-05-01T15:18:58.920 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:58.920 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:58.920 [Cloud] Queued cloud request. 2026-05-01T15:18:58.920 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:58.921 [Cloud] Dequeued cloud request. 2026-05-01T15:18:58.921 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:59.342 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:18:59.441 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\851646e93aafacd5ac3d7444d170d70880dfbaa1 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:58 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:59.443 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:18:59.443 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x133955c7 2026-05-01T15:18:59.522 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:59.522 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:59.522 [Cloud] Queued cloud request. 2026-05-01T15:18:59.522 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:59.522 [Cloud] Dequeued cloud request. 2026-05-01T15:18:59.523 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:59.740 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\067e1b9d1540852306b0b3571494e407ddd004d9 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:58 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:18:59.741 [Cloud] End of cloud request. 2026-05-01T15:18:59.741 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x173209d1 2026-05-01T15:18:59.852 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T15:18:59.852 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T15:18:59.852 [Cloud] Queued cloud request. 2026-05-01T15:18:59.852 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T15:18:59.853 [Cloud] Dequeued cloud request. 2026-05-01T15:18:59.853 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T15:18:59.983 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:19:00.042 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5708fd1a12610220658c23b5fc37f278f3e56b5f Dynamic Signature Compilation Timestamp:05-01-2026 15:18:59 Persistence Type:Duration Time remaining:50065408 2026-05-01T15:19:00.043 [Cloud] End of cloud request. 2026-05-01T15:19:00.043 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T15:19:00.562 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T15:23:30.304 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T15:29:50.395 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26659, FileId: 0xe0000000b949b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:38:35.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T15:47:32.690 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #26729, FileId: 0x130000000b9632, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:48:13.343 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T15:48:13.343 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 11229, Count: 275, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 5500, TotalTime: 5572, Count: 413, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume7\xampp\phpMyAdmin\js\functions.js, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 5980, TotalTime: 3693, Count: 74, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume7\xampp\php\php5ts.dll, EstimatedImpact: 12% 2026-05-01T15:48:13.344 ProcessImageName: helper.exe, Pid: 11636, TotalTime: 3648, Count: 90, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 82% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 10704, TotalTime: 3127, Count: 195, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\03_Album\Gallery\CH-Gallery-1.2.7\index.php, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T15:48:13.344 ProcessImageName: DesktopOK.exe, Pid: 3716, TotalTime: 2670, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 7544, TotalTime: 2217, Count: 76, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 71% 2026-05-01T15:48:13.344 ProcessImageName: xampp-control.exe, Pid: 9660, TotalTime: 1778, Count: 9, MaxTime: 1562, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T15:48:13.344 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T15:48:13.344 ProcessImageName: xampp-control.exe, Pid: 2180, TotalTime: 1217, Count: 3, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 4% 2026-05-01T15:48:13.344 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T15:48:13.344 ProcessImageName: mysqld.exe, Pid: 4948, TotalTime: 1066, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: iWatchDVR.exe, Pid: 8008, TotalTime: 764, Count: 8, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\{EC351E9C-0CD1-4459-9DA1-82BA5DC21729}\module\RapaRobot.dll.1.1.0.2322-77FE66DF5CE6F319C6464468A3D1CF1F->(UPX), EstimatedImpact: 5% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 11120, TotalTime: 623, Count: 3, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 42% 2026-05-01T15:48:13.344 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T15:48:13.344 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T15:48:13.344 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T15:48:13.344 ProcessImageName: updater.exe, Pid: 212, TotalTime: 439, Count: 35, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 425, Count: 30, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T15:48:13.344 ProcessImageName: httpd.exe, Pid: 6328, TotalTime: 338, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 285, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-01.log, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 278, Count: 9, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 2480, TotalTime: 232, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 197, Count: 11, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: updater.exe, Pid: 3656, TotalTime: 151, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T15:48:13.344 ProcessImageName: Notepad.exe, Pid: 3624, TotalTime: 137, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T15:48:13.344 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T15:48:13.344 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T15:48:13.344 ProcessImageName: mysqld.exe, Pid: 8096, TotalTime: 120, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: firefox.exe, Pid: 6628, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 105, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 92, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T15:48:13.344 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T15:48:13.344 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T15:48:13.344 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T15:48:13.344 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T15:48:13.344 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: Notepad.exe, Pid: 7488, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 11% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: mysqld.exe, Pid: 12428, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T15:48:13.344 ProcessImageName: SDXHelper.exe, Pid: 8352, TotalTime: 46, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 4% 2026-05-01T15:48:13.344 ProcessImageName: TeamViewer.exe, Pid: 8076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: dasHost.exe, Pid: 5404, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: xampp-control.exe, Pid: 7000, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\readme_de.txt, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 12588, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1620.log, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T15:48:13.344 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T15:48:13.344 ProcessImageName: xampp-control.exe, Pid: 13136, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: AdobeARM.exe, Pid: 4928, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\Other[1].htm, EstimatedImpact: 7% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: FileCoAuth.exe, Pid: 1416, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1547.1416.1.aodl, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 7708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1729.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 7308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1600.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 7592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1651.log, EstimatedImpact: 1% 2026-05-01T15:48:13.344 ProcessImageName: SDXHelper.exe, Pid: 876, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381, EstimatedImpact: 9% 2026-05-01T15:48:13.344 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 1724, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1611.log, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: pingsender.exe, Pid: 11444, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\631e25a7-6735-4569-8273-eeff025828a7, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: AdobeARM.exe, Pid: 8084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-05-01T15:48:13.344 ProcessImageName: SDXHelper.exe, Pid: 7424, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T15:48:13.344 ProcessImageName: helper.exe, Pid: 7248, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nsv79C4.tmp\System.dll, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: OfficeC2RClient.exe, Pid: 10388, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1655.log, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T15:48:13.344 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T15:51:48.386 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26763, FileId: 0x1f0000000b9664, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:53:40.304 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T15:54:40.028 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26819, FileId: 0x1e4000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.028 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26818, FileId: 0x240000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.030 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26824, FileId: 0x1e8000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.032 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26822, FileId: 0x270000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.033 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26825, FileId: 0x1e9000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.035 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26826, FileId: 0x290000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.043 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26828, FileId: 0x1eb000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.044 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26820, FileId: 0x260000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.046 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26830, FileId: 0x2b0000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.049 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26831, FileId: 0x1ec000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.050 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26829, FileId: 0x2a0000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.052 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26832, FileId: 0x2c0000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.064 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26835, FileId: 0x2e0000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.067 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26838, FileId: 0x2f0000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.070 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26839, FileId: 0x300000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.076 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #26836, FileId: 0x1ee000000003364, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:54:40.514 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\452752b5-a2e2-428d-b78d-51a47f943bc4. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #26877, FileId: 0x7a000000025011, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T15:59:47.678 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26888, FileId: 0x130000000b5a16, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:08:45.304 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x590d0996 Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x590d0996 2026-05-01T16:15:20.193 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #27861, FileId: 0x160000000b96b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:15:30.358 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #27875, FileId: 0xf0000000b972c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:19:43.080 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #27911, FileId: 0x100000000b972d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:23:50.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T16:27:55.363 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #27924, FileId: 0x100000000b98c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:38:52.852 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #27940, FileId: 0x150000000b98c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T16:38:55.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe48ec7f4 2026-05-01T16:54:00.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x93e3d568 2026-05-01T16:56:15.276 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:15.276 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:15.276 [Cloud] Queued cloud request. 2026-05-01T16:56:15.276 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:15.276 [Cloud] Dequeued cloud request. 2026-05-01T16:56:15.276 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:15.584 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c5c6fb2d1730f84bf96d2a1efa7c43f648d0a75c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:14 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:15.585 [Cloud] End of cloud request. 2026-05-01T16:56:15.585 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x78674378 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d00769c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x14197fae 2026-05-01T16:56:15.824 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:15.824 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:15.824 [Cloud] Queued cloud request. 2026-05-01T16:56:15.824 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:15.824 [Cloud] Dequeued cloud request. 2026-05-01T16:56:15.824 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:15.830 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:15.830 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:15.830 [Cloud] Queued cloud request. 2026-05-01T16:56:15.830 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:15.831 [Cloud] Dequeued cloud request. 2026-05-01T16:56:15.831 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:15.863 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:15.863 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:15.863 [Cloud] Queued cloud request. 2026-05-01T16:56:15.863 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:15.863 [Cloud] Dequeued cloud request. 2026-05-01T16:56:15.863 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:16.052 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5ea79242865383ab7546c68307722879f9fbae4b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:16.053 [Cloud] End of cloud request. 2026-05-01T16:56:16.053 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe6ba0229 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5af73969736c0694242f883c497bed6a45cc6ec9 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:16.107 [Cloud] End of cloud request. 2026-05-01T16:56:16.107 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:16.111 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:16.113 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:16.113 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:16.113 [Cloud] Queued cloud request. 2026-05-01T16:56:16.113 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:16.113 [Cloud] Dequeued cloud request. 2026-05-01T16:56:16.113 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:16.136 Dynamic signature received 2026-05-01T16:56:16.193 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0843e22d8ae59a1b6fb12c4991bc898d0c93276d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:16.194 [Cloud] End of cloud request. 2026-05-01T16:56:16.194 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x027b0320 2026-05-01T16:56:16.376 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cb3c701d7a5fd32506264b4b77f6bdaa00ad13b6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:16.377 [Cloud] End of cloud request. 2026-05-01T16:56:16.377 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:16.622 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe0c57da9 2026-05-01T16:56:17.373 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:17.373 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:17.373 [Cloud] Queued cloud request. 2026-05-01T16:56:17.373 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:17.373 [Cloud] Dequeued cloud request. 2026-05-01T16:56:17.374 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:17.553 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\05300957d37ba6ba01d556379cc5003ea6e7881a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:16 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:17.553 [Cloud] End of cloud request. 2026-05-01T16:56:17.553 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6bca9ba5 2026-05-01T16:56:17.623 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:17.623 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:17.623 [Cloud] Queued cloud request. 2026-05-01T16:56:17.623 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:17.623 [Cloud] Dequeued cloud request. 2026-05-01T16:56:17.623 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:17.822 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\da8d0872d91d52f4151e896cac044a2121a2d5ca Dynamic Signature Compilation Timestamp:05-01-2026 16:56:16 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:17.823 [Cloud] End of cloud request. 2026-05-01T16:56:17.823 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9de1bcd2 2026-05-01T16:56:17.878 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:17.878 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:17.878 [Cloud] Queued cloud request. 2026-05-01T16:56:17.878 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:17.878 [Cloud] Dequeued cloud request. 2026-05-01T16:56:17.878 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:18.069 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:18.201 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2bd5c584cd7177ba6f6ab17fa445145a73fa59a3 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:18.202 [Cloud] End of cloud request. 2026-05-01T16:56:18.202 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf5befb43 2026-05-01T16:56:18.274 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:18.274 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:18.274 [Cloud] Queued cloud request. 2026-05-01T16:56:18.274 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:18.274 [Cloud] Dequeued cloud request. 2026-05-01T16:56:18.275 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:18.476 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6d17bc9db58fa9ad3d492762817a54992f1057d5 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:18.477 [Cloud] End of cloud request. 2026-05-01T16:56:18.477 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe772b5d2 2026-05-01T16:56:18.541 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:18.541 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:18.541 [Cloud] Queued cloud request. 2026-05-01T16:56:18.541 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:18.541 [Cloud] Dequeued cloud request. 2026-05-01T16:56:18.541 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:18.723 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:18.747 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e77b3708bb2d2b48afb5f38ec82655205b356e27 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:18.748 [Cloud] End of cloud request. 2026-05-01T16:56:18.748 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x28e12625 2026-05-01T16:56:18.820 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:18.820 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:18.820 [Cloud] Queued cloud request. 2026-05-01T16:56:18.820 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:18.820 [Cloud] Dequeued cloud request. 2026-05-01T16:56:18.820 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:19.012 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f6e74aa1c22a25b6dfb3dbf90d1740051c68e085 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:19.013 [Cloud] End of cloud request. 2026-05-01T16:56:19.013 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbd59641e 2026-05-01T16:56:19.078 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:19.079 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:19.079 [Cloud] Queued cloud request. 2026-05-01T16:56:19.079 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:19.079 [Cloud] Dequeued cloud request. 2026-05-01T16:56:19.079 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:19.269 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:19.353 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7d05456d7f3c28fe53b535de4e15248b7c911f6c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:19.354 [Cloud] End of cloud request. 2026-05-01T16:56:19.354 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xefa01ec8 2026-05-01T16:56:19.414 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:19.414 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:19.414 [Cloud] Queued cloud request. 2026-05-01T16:56:19.414 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:19.414 [Cloud] Dequeued cloud request. 2026-05-01T16:56:19.414 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:19.649 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d1284d96ff183882f7d8b7514ddafdcc0db67b0d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:19.649 [Cloud] End of cloud request. 2026-05-01T16:56:19.649 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9852ef00 2026-05-01T16:56:19.718 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:19.718 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:19.718 [Cloud] Queued cloud request. 2026-05-01T16:56:19.718 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:19.718 [Cloud] Dequeued cloud request. 2026-05-01T16:56:19.718 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:19.879 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:19.905 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ec84c9ae477733046bbe2eb96adc17a61e1d23c4 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:19.906 [Cloud] End of cloud request. 2026-05-01T16:56:19.906 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x74cae9c7 2026-05-01T16:56:19.962 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:19.962 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:19.962 [Cloud] Queued cloud request. 2026-05-01T16:56:19.962 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:19.962 [Cloud] Dequeued cloud request. 2026-05-01T16:56:19.962 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:20.314 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f69451f681a9a63534f982dab57744801ed5fce Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:20.315 [Cloud] End of cloud request. 2026-05-01T16:56:20.315 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x88b98e66 2026-05-01T16:56:20.390 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:20.391 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:20.391 [Cloud] Queued cloud request. 2026-05-01T16:56:20.391 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:20.391 [Cloud] Dequeued cloud request. 2026-05-01T16:56:20.391 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:20.422 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:20.568 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\33184f2134a668f9b702c4b7c8d91961ccacf62a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:20.569 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:20.569 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbc3c9a04 2026-05-01T16:56:20.658 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:20.658 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:20.658 [Cloud] Queued cloud request. 2026-05-01T16:56:20.658 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:20.658 [Cloud] Dequeued cloud request. 2026-05-01T16:56:20.658 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\77c439db3a0b61bb6c667b0fee96e3a8e557ef83 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:20.952 [Cloud] End of cloud request. 2026-05-01T16:56:20.952 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa36b933 2026-05-01T16:56:21.020 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:21.020 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:21.020 [Cloud] Queued cloud request. 2026-05-01T16:56:21.020 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:21.020 [Cloud] Dequeued cloud request. 2026-05-01T16:56:21.020 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:21.094 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:21.142 Dynamic signature received 2026-05-01T16:56:21.203 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6930aeee137f7bd735fb62f8ef8766f732c6e99b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:21.204 [Cloud] End of cloud request. 2026-05-01T16:56:21.204 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8f69aa98 2026-05-01T16:56:21.306 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:21.306 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:21.306 [Cloud] Queued cloud request. 2026-05-01T16:56:21.306 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:21.306 [Cloud] Dequeued cloud request. 2026-05-01T16:56:21.307 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:21.543 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3e54a4bdfe8d32951a51ff0ad3c82d95716c57df Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:21.544 [Cloud] End of cloud request. 2026-05-01T16:56:21.544 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7b1a0fd1 2026-05-01T16:56:21.640 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:21.640 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:21.640 [Cloud] Queued cloud request. 2026-05-01T16:56:21.640 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:21.640 [Cloud] Dequeued cloud request. 2026-05-01T16:56:21.640 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:21.717 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:21.828 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f61bb28f7e1d7666bbe7e906f4d2655918d12aee Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:21.829 [Cloud] End of cloud request. 2026-05-01T16:56:21.829 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x537410d7 2026-05-01T16:56:21.894 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:21.894 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:21.894 [Cloud] Queued cloud request. 2026-05-01T16:56:21.894 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:21.894 [Cloud] Dequeued cloud request. 2026-05-01T16:56:21.894 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:22.102 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75d90c56c528a95a6523c7efbe685642055302c6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:22.103 [Cloud] End of cloud request. 2026-05-01T16:56:22.103 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4e95ed9 2026-05-01T16:56:22.172 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:22.172 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:22.172 [Cloud] Queued cloud request. 2026-05-01T16:56:22.172 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:22.172 [Cloud] Dequeued cloud request. 2026-05-01T16:56:22.173 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:22.340 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:22.454 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7fd2045f78a4b50cfbe9ddbbd598df0c7008b8f1 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:22.456 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:22.456 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x39da0735 2026-05-01T16:56:22.520 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:22.520 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:22.520 [Cloud] Queued cloud request. 2026-05-01T16:56:22.520 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:22.520 [Cloud] Dequeued cloud request. 2026-05-01T16:56:22.521 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:22.716 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5e2e1f1aa1104232ac58e8dacc97104081b208f8 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:22.717 [Cloud] End of cloud request. 2026-05-01T16:56:22.717 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x612bd000 2026-05-01T16:56:22.780 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:22.780 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:22.780 [Cloud] Queued cloud request. 2026-05-01T16:56:22.780 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:22.781 [Cloud] Dequeued cloud request. 2026-05-01T16:56:22.781 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:22.973 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2542a558a721f424fdf4b1258e2ff66fdd7ae2ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:22.973 [Cloud] End of cloud request. 2026-05-01T16:56:22.974 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:22.978 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd11e8782 2026-05-01T16:56:23.038 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:23.038 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:23.039 [Cloud] Queued cloud request. 2026-05-01T16:56:23.039 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:23.039 [Cloud] Dequeued cloud request. 2026-05-01T16:56:23.039 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:23.242 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\85184316dbaf249fa90b13912f97f0191cf6354b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:23.244 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:23.244 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9c83381f 2026-05-01T16:56:23.322 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:23.322 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:23.322 [Cloud] Queued cloud request. 2026-05-01T16:56:23.322 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:23.322 [Cloud] Dequeued cloud request. 2026-05-01T16:56:23.323 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:23.494 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cf83d18a3de5abcdd2d20529f1f44d88abf97b09 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:23.546 Dynamic signature received 2026-05-01T16:56:23.546 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:23.548 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfdcf1acc 2026-05-01T16:56:23.643 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:23.643 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:23.643 [Cloud] Queued cloud request. 2026-05-01T16:56:23.643 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:23.643 [Cloud] Dequeued cloud request. 2026-05-01T16:56:23.643 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:23.939 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd0fa8cc26e5cc1a5531a39f1af5c6aa99f6faa5 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:23.941 [Cloud] End of cloud request. 2026-05-01T16:56:23.941 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:24.067 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6fdef17b 2026-05-01T16:56:24.193 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:24.193 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:24.193 [Cloud] Queued cloud request. 2026-05-01T16:56:24.193 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:24.194 [Cloud] Dequeued cloud request. 2026-05-01T16:56:24.194 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ecd8d855f607ab21d12a76f70a26e2c289a75488 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:24.385 Dynamic signature received 2026-05-01T16:56:24.387 [Cloud] End of cloud request. 2026-05-01T16:56:24.387 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xff3fbf50 2026-05-01T16:56:24.458 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:24.459 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:24.459 [Cloud] Queued cloud request. 2026-05-01T16:56:24.459 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:24.459 [Cloud] Dequeued cloud request. 2026-05-01T16:56:24.459 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:24.758 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\624a8e51d4e4ce4b1302c8494b7008a1e671ed9f Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:24.760 [Cloud] End of cloud request. 2026-05-01T16:56:24.760 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x014d12ed 2026-05-01T16:56:24.824 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:24.824 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:24.824 [Cloud] Queued cloud request. 2026-05-01T16:56:24.824 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:24.824 [Cloud] Dequeued cloud request. 2026-05-01T16:56:24.824 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:24.912 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:25.118 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\144b2a1f16b4c727c2d7ee42609ead3ad072894a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:25.119 [Cloud] End of cloud request. 2026-05-01T16:56:25.119 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9897b9b4 2026-05-01T16:56:25.180 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:25.180 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:25.180 [Cloud] Queued cloud request. 2026-05-01T16:56:25.180 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:25.180 [Cloud] Dequeued cloud request. 2026-05-01T16:56:25.180 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:25.420 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1cbfe3d3f11f17f2a08ee11cc25a8a630dab115 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:25.421 [Cloud] End of cloud request. 2026-05-01T16:56:25.421 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x102961b5 2026-05-01T16:56:25.481 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:25.481 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:25.481 [Cloud] Queued cloud request. 2026-05-01T16:56:25.481 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:25.481 [Cloud] Dequeued cloud request. 2026-05-01T16:56:25.482 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:25.634 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:25.694 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\df24c6b3317a436207734c2a106400f0fa3f43d6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:25.695 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:25.695 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xddc1693b 2026-05-01T16:56:25.781 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:25.781 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:25.782 [Cloud] Queued cloud request. 2026-05-01T16:56:25.782 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:25.782 [Cloud] Dequeued cloud request. 2026-05-01T16:56:25.782 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e6a425020624e392f4bbd14b922d402376d89b3e Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:25.982 Dynamic signature received 2026-05-01T16:56:25.982 [Cloud] End of cloud request. 2026-05-01T16:56:25.983 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x162b573c 2026-05-01T16:56:26.053 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:26.053 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:26.053 [Cloud] Queued cloud request. 2026-05-01T16:56:26.053 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:26.053 [Cloud] Dequeued cloud request. 2026-05-01T16:56:26.053 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:26.214 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:26.419 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d2c0257256978d35c1d4d2faacabc66e2affb602 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:26.420 [Cloud] End of cloud request. 2026-05-01T16:56:26.420 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ffefed1 2026-05-01T16:56:26.487 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:26.487 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:26.487 [Cloud] Queued cloud request. 2026-05-01T16:56:26.487 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:26.487 [Cloud] Dequeued cloud request. 2026-05-01T16:56:26.487 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:26.714 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\70a17dce5911e857ba45df620b908b2dbe341800 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:26.715 [Cloud] End of cloud request. 2026-05-01T16:56:26.715 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x055e921d 2026-05-01T16:56:26.773 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:26.773 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:26.773 [Cloud] Queued cloud request. 2026-05-01T16:56:26.773 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:26.773 [Cloud] Dequeued cloud request. 2026-05-01T16:56:26.773 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:26.940 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:26.982 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9393c1eb9c274f450e6528f75a9a199c3e57b11d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:26.983 [Cloud] End of cloud request. 2026-05-01T16:56:26.983 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5b9ce51c 2026-05-01T16:56:27.077 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:27.077 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:27.077 [Cloud] Queued cloud request. 2026-05-01T16:56:27.077 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:27.077 [Cloud] Dequeued cloud request. 2026-05-01T16:56:27.078 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\faeee822267c626d1eab21ce8d60aab4d8271758 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:27.346 Dynamic signature received 2026-05-01T16:56:27.347 [Cloud] End of cloud request. 2026-05-01T16:56:27.347 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5d46892 2026-05-01T16:56:27.422 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:27.422 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:27.422 [Cloud] Queued cloud request. 2026-05-01T16:56:27.422 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:27.423 [Cloud] Dequeued cloud request. 2026-05-01T16:56:27.423 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:27.498 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a77c65dfe96d3bddc5868d05a9b75027071450bf Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:27.660 Dynamic signature received 2026-05-01T16:56:27.661 [Cloud] End of cloud request. 2026-05-01T16:56:27.662 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3f832d0f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9725238f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe3ffc57d 2026-05-01T16:56:28.138 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:28.138 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:28.138 [Cloud] Queued cloud request. 2026-05-01T16:56:28.138 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:28.138 [Cloud] Dequeued cloud request. 2026-05-01T16:56:28.138 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:28.170 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:28.500 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\78f67d01e4c856736d870f499aa3403812fc9a74 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:27 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:28.501 [Cloud] End of cloud request. 2026-05-01T16:56:28.502 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7f33e982 2026-05-01T16:56:29.026 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:29.395 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:29.395 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:29.395 [Cloud] Queued cloud request. 2026-05-01T16:56:29.395 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:29.395 [Cloud] Dequeued cloud request. 2026-05-01T16:56:29.395 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:29.612 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7cdc67c7eb6588c3f62b533eecb969c07a60e460 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:28 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:29.613 [Cloud] End of cloud request. 2026-05-01T16:56:29.613 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4b6c659b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9942ce4 2026-05-01T16:56:29.789 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:29.789 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:29.789 [Cloud] Queued cloud request. 2026-05-01T16:56:29.789 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:29.789 [Cloud] Dequeued cloud request. 2026-05-01T16:56:29.789 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:29.979 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c3c4f384515bb6245b92d875fac64360e6fd77a3 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:29 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:29.980 [Cloud] End of cloud request. 2026-05-01T16:56:29.980 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:30.154 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x909672fe 2026-05-01T16:56:30.340 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:30.340 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:30.340 [Cloud] Queued cloud request. 2026-05-01T16:56:30.340 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:30.341 [Cloud] Dequeued cloud request. 2026-05-01T16:56:30.341 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:30.561 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\937b1563c0503cd44c601fd0a75bdf759144a7ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:29 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:30.562 [Cloud] End of cloud request. 2026-05-01T16:56:30.562 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfba2715c 2026-05-01T16:56:30.691 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:30.691 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:30.691 [Cloud] Queued cloud request. 2026-05-01T16:56:30.691 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:30.691 [Cloud] Dequeued cloud request. 2026-05-01T16:56:30.692 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e220e26819db38a2006c6fe6ed0a73c2f0859930 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:31.002 Dynamic signature received 2026-05-01T16:56:31.002 [Cloud] End of cloud request. 2026-05-01T16:56:31.003 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0de07c78 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbaedf2a7 2026-05-01T16:56:31.092 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:31.118 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:31.118 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:31.118 [Cloud] Queued cloud request. 2026-05-01T16:56:31.118 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:31.119 [Cloud] Dequeued cloud request. 2026-05-01T16:56:31.119 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:31.341 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9836eb86eccff9ea015d97ff7720b1dad83fd20a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:30 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:31.342 [Cloud] End of cloud request. 2026-05-01T16:56:31.342 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x413cc667 2026-05-01T16:56:31.685 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:31.685 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:31.685 [Cloud] Queued cloud request. 2026-05-01T16:56:31.685 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:31.685 [Cloud] Dequeued cloud request. 2026-05-01T16:56:31.685 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:31.881 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:32.139 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4991d789daca1a1932ecfdc25e32e26f34f58f99 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:31 Persistence Type:Duration Time remaining:150196224 2026-05-01T16:56:32.140 [Cloud] End of cloud request. 2026-05-01T16:56:32.140 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf11c2271 2026-05-01T16:56:32.357 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:32.357 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:32.357 [Cloud] Queued cloud request. 2026-05-01T16:56:32.357 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:32.357 [Cloud] Dequeued cloud request. 2026-05-01T16:56:32.357 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:32.585 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ed2fead095710bbebb877aa5e6bbcfbd861a5297 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:31 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:32.586 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:32.586 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb5ad208c 2026-05-01T16:56:32.660 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:32.661 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:32.661 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:32.661 [Cloud] Queued cloud request. 2026-05-01T16:56:32.661 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:32.661 [Cloud] Dequeued cloud request. 2026-05-01T16:56:32.661 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:32.893 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\12000b12e54e13427dc525bd749898dae1d3b7bc Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:32.894 [Cloud] End of cloud request. 2026-05-01T16:56:32.894 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xda5660a5 2026-05-01T16:56:33.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:33.097 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:33.097 [Cloud] Queued cloud request. 2026-05-01T16:56:33.097 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:33.097 [Cloud] Dequeued cloud request. 2026-05-01T16:56:33.097 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b8013051e3ef55dcfb2374dfb288c192ec454ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:33.325 Dynamic signature received 2026-05-01T16:56:33.326 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:33.326 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7561b1d8 2026-05-01T16:56:33.393 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:33.393 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:33.393 [Cloud] Queued cloud request. 2026-05-01T16:56:33.393 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:33.394 [Cloud] Dequeued cloud request. 2026-05-01T16:56:33.394 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:33.412 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:33.768 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99fe86ebd901811f983df57371318b2d999f32d1 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:33.769 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:33.769 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0e62217b 2026-05-01T16:56:33.836 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:33.836 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:33.836 [Cloud] Queued cloud request. 2026-05-01T16:56:33.836 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:33.836 [Cloud] Dequeued cloud request. 2026-05-01T16:56:33.837 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\220f9e94e0232e0952d8510fb420210b415c5267 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:34.066 Dynamic signature received 2026-05-01T16:56:34.068 [Cloud] End of cloud request. 2026-05-01T16:56:34.068 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7309bef6 2026-05-01T16:56:34.143 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:34.143 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:34.143 [Cloud] Queued cloud request. 2026-05-01T16:56:34.143 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:34.143 [Cloud] Dequeued cloud request. 2026-05-01T16:56:34.143 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:34.288 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:34.394 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2e637667c7ae066652721bbe38a0d6c4780aeed7 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:34.395 [Cloud] End of cloud request. 2026-05-01T16:56:34.395 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4c7e81bf 2026-05-01T16:56:34.552 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:34.552 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:34.552 [Cloud] Queued cloud request. 2026-05-01T16:56:34.552 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:34.553 [Cloud] Dequeued cloud request. 2026-05-01T16:56:34.553 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:34.775 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9e298fd1d3e6f545821019ff382f870a6a90736c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:34.776 [Cloud] End of cloud request. 2026-05-01T16:56:34.776 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcf5c0135 2026-05-01T16:56:34.860 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:34.860 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:34.860 [Cloud] Queued cloud request. 2026-05-01T16:56:34.860 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:34.861 [Cloud] Dequeued cloud request. 2026-05-01T16:56:34.861 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:34.913 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T16:56:35.084 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4c12a83d286b4d8766026ac9d26d44f86df6a3ab Dynamic Signature Compilation Timestamp:05-01-2026 16:56:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:35.085 [Cloud] End of cloud request. 2026-05-01T16:56:35.085 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa44f966 2026-05-01T16:56:35.145 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T16:56:35.145 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T16:56:35.146 [Cloud] Queued cloud request. 2026-05-01T16:56:35.146 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T16:56:35.146 [Cloud] Dequeued cloud request. 2026-05-01T16:56:35.146 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T16:56:35.375 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6316050beafada0c0ee877e0e5cabfbe5f454472 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:34 Persistence Type:Duration Time remaining:50065408 2026-05-01T16:56:35.375 [Cloud] End of cloud request. 2026-05-01T16:56:35.375 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T16:56:35.602 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x89d692cd Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x89d692cd 2026-05-01T17:09:05.297 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T17:13:16.036 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj722AAC9DD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30698, FileId: 0x280000000bd742, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.049 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1CF70C992. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30699, FileId: 0x290000000bd742, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.058 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2E2697954. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30700, FileId: 0x2a0000000bd742, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.072 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6543B8915. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30701, FileId: 0x2b0000000bd742, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.089 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7C7479981. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30702, FileId: 0x110000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.320 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC3D0DE94E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30704, FileId: 0x160000000bd747, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.333 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1707849F0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30705, FileId: 0x130000000bd746, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.349 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj41EEE19AA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30706, FileId: 0x140000000bd746, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.361 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjADE421925. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30707, FileId: 0x140000000bd743, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.379 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7C6DE09E3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30708, FileId: 0x190000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.393 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7ACECA930. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30709, FileId: 0x1a0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.405 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8D22D92C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30710, FileId: 0x1b0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.418 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj00A2029CA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30711, FileId: 0x1c0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.430 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBA3738952. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30712, FileId: 0x1d0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.442 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF47CF19E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30713, FileId: 0x1e0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.455 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj358888974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30714, FileId: 0x1f0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.484 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7078799E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30715, FileId: 0x200000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.498 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj51220D968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30716, FileId: 0x210000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.506 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj81E7509B2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30717, FileId: 0x220000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.513 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCF11C99EF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30718, FileId: 0x230000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.529 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj10A817910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30719, FileId: 0x220000000bd743, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.535 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2D1E6E94A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30720, FileId: 0x230000000bd743, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.632 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC63B379FD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30721, FileId: 0x160000000bd746, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.644 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj10D3E9922. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30722, FileId: 0x250000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.658 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj88FA10906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30723, FileId: 0x260000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.672 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAF527192F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30724, FileId: 0x270000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.685 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA95F11984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30725, FileId: 0x280000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.705 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj004883914. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30726, FileId: 0x290000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.721 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBCE1AC90A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30727, FileId: 0x2a0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:16.741 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5001F4980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30728, FileId: 0x2b0000000bd745, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:30.962 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30731, FileId: 0x3800000001db42, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:31.099 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30733, FileId: 0x1c0000000bd740, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:44.793 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30741, FileId: 0x180000000bd73c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:13:44.796 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #30743, FileId: 0x180000000bd73e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:21:24.092 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume8\xampp\tmp\#sql2490_2_1.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #31622, FileId: 0x3000000000844, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:24:10.301 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1698b785 2026-05-01T17:39:15.299 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T17:40:15.741 [RTP] [Mini-filter] Copy hint telemetry notification (\Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. 2026-05-01T17:42:36.221 [RTP] [Mini-filter] Copy hint telemetry notification (\Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. 2026-05-01T17:44:26.446 [RTP] [Mini-filter] Copy hint telemetry notification (\Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xefaa5d78 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13dbd17f 2026-05-01T17:46:35.472 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:35.472 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:35.472 [Cloud] Queued cloud request. 2026-05-01T17:46:35.472 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:35.472 [Cloud] Dequeued cloud request. 2026-05-01T17:46:35.472 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:43.413 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\be984154fb4f22b176da3f59b73274acb449fcec Dynamic Signature Compilation Timestamp:05-01-2026 17:46:42 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:43.414 [Cloud] End of cloud request. 2026-05-01T17:46:43.414 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xde65ca27 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2be02083 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x02f929b1 2026-05-01T17:46:43.591 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:43.591 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:43.591 [Cloud] Queued cloud request. 2026-05-01T17:46:43.591 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:43.591 [Cloud] Dequeued cloud request. 2026-05-01T17:46:43.591 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:43.591 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:43.592 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:43.592 [Cloud] Queued cloud request. 2026-05-01T17:46:43.592 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:43.592 [Cloud] Dequeued cloud request. 2026-05-01T17:46:43.592 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:43.599 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:43.599 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:43.599 [Cloud] Queued cloud request. 2026-05-01T17:46:43.599 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:43.599 [Cloud] Dequeued cloud request. 2026-05-01T17:46:43.599 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:43.801 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4dea43befcd640198d6d2e2cef7c0aa50ed699f8 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:42 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:43.802 [Cloud] End of cloud request. 2026-05-01T17:46:43.802 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:43.926 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:43.987 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5472eaaf57da8da157d1f038c222b55b29db1720 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:43.988 [Cloud] End of cloud request. 2026-05-01T17:46:43.988 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:44.058 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b68054b66dd526d400031637c719e07390fecc21 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:44.059 [Cloud] End of cloud request. 2026-05-01T17:46:44.059 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ffdde34 2026-05-01T17:46:44.120 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:44.121 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:44.121 [Cloud] Queued cloud request. 2026-05-01T17:46:44.121 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:44.121 [Cloud] Dequeued cloud request. 2026-05-01T17:46:44.121 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:44.311 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\95eeaaa65ea12eda89faf066823698a8378b5f2b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:44.312 [Cloud] End of cloud request. 2026-05-01T17:46:44.312 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:44.505 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcc1c40b1 2026-05-01T17:46:45.203 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:45.203 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:45.203 [Cloud] Queued cloud request. 2026-05-01T17:46:45.203 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:45.204 [Cloud] Dequeued cloud request. 2026-05-01T17:46:45.204 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\38cf7431bdcf8de4bf5b013442129fdc24f08805 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:44 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:45.416 Dynamic signature received 2026-05-01T17:46:45.417 [Cloud] End of cloud request. 2026-05-01T17:46:45.417 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1bc3c001 2026-05-01T17:46:45.466 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:45.466 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:45.466 [Cloud] Queued cloud request. 2026-05-01T17:46:45.466 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:45.466 [Cloud] Dequeued cloud request. 2026-05-01T17:46:45.467 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:45.661 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e1f61e87c43432a4861c7970aa0fcdf675e2e359 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:44 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:45.662 [Cloud] End of cloud request. 2026-05-01T17:46:45.662 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3be3358d 2026-05-01T17:46:45.713 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:45.713 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:45.713 [Cloud] Queued cloud request. 2026-05-01T17:46:45.713 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:45.714 [Cloud] Dequeued cloud request. 2026-05-01T17:46:45.714 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:45.930 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:45.969 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\542e1bd888de7bf100c715e8922291fb95193c6d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:45.970 [Cloud] End of cloud request. 2026-05-01T17:46:45.970 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x562d4543 2026-05-01T17:46:46.019 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:46.019 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:46.020 [Cloud] Queued cloud request. 2026-05-01T17:46:46.020 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:46.020 [Cloud] Dequeued cloud request. 2026-05-01T17:46:46.020 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:46.242 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\631c4e4a8b504f4ab4a454450311419d2178298d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:46.243 [Cloud] End of cloud request. 2026-05-01T17:46:46.243 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x325a00a0 2026-05-01T17:46:46.294 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:46.294 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:46.294 [Cloud] Queued cloud request. 2026-05-01T17:46:46.294 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:46.294 [Cloud] Dequeued cloud request. 2026-05-01T17:46:46.295 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:46.491 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:46.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\772b3247d836beb22bf77b2cf472092b3bd696f4 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:46.524 [Cloud] End of cloud request. 2026-05-01T17:46:46.524 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcc56acdd 2026-05-01T17:46:46.578 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:46.578 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:46.578 [Cloud] Queued cloud request. 2026-05-01T17:46:46.578 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:46.578 [Cloud] Dequeued cloud request. 2026-05-01T17:46:46.578 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d8660b33b1796fbf6000097782cce2e0a5352630 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:46.822 Dynamic signature received 2026-05-01T17:46:46.823 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:46.824 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59eeeee6 2026-05-01T17:46:46.872 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:46.872 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:46.872 [Cloud] Queued cloud request. 2026-05-01T17:46:46.872 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:46.872 [Cloud] Dequeued cloud request. 2026-05-01T17:46:46.872 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:47.048 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:47.124 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7f1e7683a50152312e34fcd83953be63e3778ad Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:47.125 [Cloud] End of cloud request. 2026-05-01T17:46:47.125 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0b179430 2026-05-01T17:46:47.174 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:47.174 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:47.174 [Cloud] Queued cloud request. 2026-05-01T17:46:47.174 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:47.175 [Cloud] Dequeued cloud request. 2026-05-01T17:46:47.175 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:47.451 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\90372607743180a40db1ac976e950e17c0daa663 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:47.452 [Cloud] End of cloud request. 2026-05-01T17:46:47.452 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ce565f8 2026-05-01T17:46:47.503 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:47.503 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:47.503 [Cloud] Queued cloud request. 2026-05-01T17:46:47.503 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:47.503 [Cloud] Dequeued cloud request. 2026-05-01T17:46:47.504 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:47.637 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:47.735 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31ddbf1cf02bcfa3f2ca4ee8ad6bf1924238cbc2 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:47.737 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:47.737 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xaff6f2c1 2026-05-01T17:46:47.788 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:47.788 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:47.788 [Cloud] Queued cloud request. 2026-05-01T17:46:47.788 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:47.788 [Cloud] Dequeued cloud request. 2026-05-01T17:46:47.788 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:48.078 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bd376463e83523401069d3f61198a4520577ba76 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:48.079 [Cloud] End of cloud request. 2026-05-01T17:46:48.079 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6c0e049e 2026-05-01T17:46:48.131 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:48.131 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:48.131 [Cloud] Queued cloud request. 2026-05-01T17:46:48.131 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:48.131 [Cloud] Dequeued cloud request. 2026-05-01T17:46:48.132 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:48.254 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:48.362 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\966acd9ba0dcfd640628f16a37619052d0e0d41d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:48.364 [Cloud] End of cloud request. 2026-05-01T17:46:48.364 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x588b10fc 2026-05-01T17:46:48.412 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:48.412 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:48.412 [Cloud] Queued cloud request. 2026-05-01T17:46:48.412 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:48.413 [Cloud] Dequeued cloud request. 2026-05-01T17:46:48.413 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:48.678 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd13bd10fb59b0c4bc107f7c0de16ddfafa24832 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:48.680 [Cloud] End of cloud request. 2026-05-01T17:46:48.680 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd9113c45 2026-05-01T17:46:48.733 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:48.733 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:48.733 [Cloud] Queued cloud request. 2026-05-01T17:46:48.733 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:48.733 [Cloud] Dequeued cloud request. 2026-05-01T17:46:48.733 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:48.887 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:49.010 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9b7b26e1a850cdb186c9961df03811ded9be6a82 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:49.011 [Cloud] End of cloud request. 2026-05-01T17:46:49.011 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc9c9c33f 2026-05-01T17:46:49.062 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:49.062 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:49.062 [Cloud] Queued cloud request. 2026-05-01T17:46:49.062 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:49.062 [Cloud] Dequeued cloud request. 2026-05-01T17:46:49.063 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:49.292 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e863bab68d7216257e908186f564ccf3ac6be1b8 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:49.293 [Cloud] End of cloud request. 2026-05-01T17:46:49.293 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4dc88e49 2026-05-01T17:46:49.345 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:49.345 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:49.345 [Cloud] Queued cloud request. 2026-05-01T17:46:49.345 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:49.345 [Cloud] Dequeued cloud request. 2026-05-01T17:46:49.345 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:49.528 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:49.585 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52056ba1955403217f6528d54894389b88014acd Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:49.586 [Cloud] End of cloud request. 2026-05-01T17:46:49.586 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d47970 2026-05-01T17:46:49.642 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:49.642 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:49.642 [Cloud] Queued cloud request. 2026-05-01T17:46:49.642 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:49.642 [Cloud] Dequeued cloud request. 2026-05-01T17:46:49.642 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:49.921 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe4fa22162ee5a9961a8952a34dd04f6888b148f Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:49.922 [Cloud] End of cloud request. 2026-05-01T17:46:49.922 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8249377e 2026-05-01T17:46:49.971 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:49.972 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:49.972 [Cloud] Queued cloud request. 2026-05-01T17:46:49.972 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:49.972 [Cloud] Dequeued cloud request. 2026-05-01T17:46:49.972 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:50.106 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:50.284 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\763210ff3e031058dc3b448b304356448d7eb7ca Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:50.285 [Cloud] End of cloud request. 2026-05-01T17:46:50.285 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7f7a6e92 2026-05-01T17:46:50.335 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:50.335 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:50.335 [Cloud] Queued cloud request. 2026-05-01T17:46:50.335 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:50.335 [Cloud] Dequeued cloud request. 2026-05-01T17:46:50.335 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:50.592 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2f954fed4191a2e5743fc2c0e5eb0859905eec99 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:50.593 [Cloud] End of cloud request. 2026-05-01T17:46:50.593 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x11228ba4 2026-05-01T17:46:50.645 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:50.645 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:50.645 [Cloud] Queued cloud request. 2026-05-01T17:46:50.645 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:50.645 [Cloud] Dequeued cloud request. 2026-05-01T17:46:50.646 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:50.801 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:50.901 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a7041609adbe381bf73118a338981e7e2b06585b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:50.902 [Cloud] End of cloud request. 2026-05-01T17:46:50.902 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa117dc26 2026-05-01T17:46:50.953 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:50.953 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:50.953 [Cloud] Queued cloud request. 2026-05-01T17:46:50.953 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:50.953 [Cloud] Dequeued cloud request. 2026-05-01T17:46:50.954 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:51.244 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7673c8600249a723f6c38364a0f2eceaab686877 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:51.245 [Cloud] End of cloud request. 2026-05-01T17:46:51.246 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x49ab8d6d 2026-05-01T17:46:51.298 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:51.298 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:51.298 [Cloud] Queued cloud request. 2026-05-01T17:46:51.298 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:51.298 [Cloud] Dequeued cloud request. 2026-05-01T17:46:51.298 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:51.421 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:51.510 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b5cd9fbf91792259afeefbe7cdf90347ca7c03b5 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:51.511 [Cloud] End of cloud request. 2026-05-01T17:46:51.511 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5bcd9393 2026-05-01T17:46:51.561 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:51.561 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:51.561 [Cloud] Queued cloud request. 2026-05-01T17:46:51.561 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:51.561 [Cloud] Dequeued cloud request. 2026-05-01T17:46:51.561 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\135e490dd33131e097f2106e4297c4ddb76a2953 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:51.783 Dynamic signature received 2026-05-01T17:46:51.784 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:51.784 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b697b83 2026-05-01T17:46:51.836 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:51.836 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:51.836 [Cloud] Queued cloud request. 2026-05-01T17:46:51.836 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:51.836 [Cloud] Dequeued cloud request. 2026-05-01T17:46:51.836 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:52.025 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:52.081 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0382392a482016c0f1929ea45d1ce0bd342c3f83 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:52.082 [Cloud] End of cloud request. 2026-05-01T17:46:52.082 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1b8835a8 2026-05-01T17:46:52.135 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:52.135 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:52.135 [Cloud] Queued cloud request. 2026-05-01T17:46:52.135 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:52.135 [Cloud] Dequeued cloud request. 2026-05-01T17:46:52.135 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:52.408 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b45d87fa25db8fa36b1963ef47733f442fc42602 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:52.409 [Cloud] End of cloud request. 2026-05-01T17:46:52.409 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa74f9bb2 2026-05-01T17:46:52.468 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:52.468 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:52.468 [Cloud] Queued cloud request. 2026-05-01T17:46:52.468 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:52.468 [Cloud] Dequeued cloud request. 2026-05-01T17:46:52.469 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:52.600 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:52.722 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14871022fea6023466ca0d4a865118d6e4953fcd Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:52.723 [Cloud] End of cloud request. 2026-05-01T17:46:52.723 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4dbf0cc6 2026-05-01T17:46:52.778 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:52.778 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:52.778 [Cloud] Queued cloud request. 2026-05-01T17:46:52.778 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:52.778 [Cloud] Dequeued cloud request. 2026-05-01T17:46:52.778 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:53.011 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\af5ff3066ee1e9df1fadd9a4951b1b0196d66fcb Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:53.012 [Cloud] End of cloud request. 2026-05-01T17:46:53.012 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc1218489 2026-05-01T17:46:53.068 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:53.068 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:53.068 [Cloud] Queued cloud request. 2026-05-01T17:46:53.068 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:53.068 [Cloud] Dequeued cloud request. 2026-05-01T17:46:53.068 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:53.240 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:53.367 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b6e51c887202c27b6cf630b471a1a7382f2cd58c Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:53.368 [Cloud] End of cloud request. 2026-05-01T17:46:53.368 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7bc3e064 2026-05-01T17:46:53.432 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:53.433 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:53.433 [Cloud] Queued cloud request. 2026-05-01T17:46:53.433 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:53.433 [Cloud] Dequeued cloud request. 2026-05-01T17:46:53.433 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:53.699 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a1eabbaf7d0587d3b64a08a7d786bba1483cd9c0 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:53.700 [Cloud] End of cloud request. 2026-05-01T17:46:53.700 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x350cd24a 2026-05-01T17:46:53.761 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:53.761 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:53.761 [Cloud] Queued cloud request. 2026-05-01T17:46:53.761 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:53.761 [Cloud] Dequeued cloud request. 2026-05-01T17:46:53.761 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:53.884 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:54.034 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6409bb1d86b8d75d8646a13491896206b21c8b8d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:54.034 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:54.034 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3ff7a575 2026-05-01T17:46:54.099 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:54.099 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:54.099 [Cloud] Queued cloud request. 2026-05-01T17:46:54.099 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:54.099 [Cloud] Dequeued cloud request. 2026-05-01T17:46:54.099 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\96fadda3d39e9db6ffcaef2c262377a0e9bddee0 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:54.361 [Cloud] End of cloud request. 2026-05-01T17:46:54.361 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x338c1385 2026-05-01T17:46:54.420 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:54.420 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:54.420 [Cloud] Queued cloud request. 2026-05-01T17:46:54.420 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:54.420 [Cloud] Dequeued cloud request. 2026-05-01T17:46:54.420 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:54.562 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6fcb653c16036e26a8897305f185023b57ae842b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:54.616 [Cloud] End of cloud request. 2026-05-01T17:46:54.616 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:54.641 Dynamic signature received 2026-05-01T17:46:54.642 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7745d804 2026-05-01T17:46:54.680 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:54.680 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:54.680 [Cloud] Queued cloud request. 2026-05-01T17:46:54.680 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:54.681 [Cloud] Dequeued cloud request. 2026-05-01T17:46:54.681 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:54.925 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f408e05fd75fe75a83e7b84be45c93168e55370 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:54.927 [Cloud] End of cloud request. 2026-05-01T17:46:54.927 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa3740135 2026-05-01T17:46:55.007 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:55.007 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:55.007 [Cloud] Queued cloud request. 2026-05-01T17:46:55.007 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:55.007 [Cloud] Dequeued cloud request. 2026-05-01T17:46:55.007 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:55.128 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:55.219 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\717f81afc794fa1ea60726491cca8f17582581a9 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:55.220 [Cloud] End of cloud request. 2026-05-01T17:46:55.220 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbb5a75e6 2026-05-01T17:46:55.288 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:55.288 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:55.288 [Cloud] Queued cloud request. 2026-05-01T17:46:55.288 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:55.288 [Cloud] Dequeued cloud request. 2026-05-01T17:46:55.289 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:55.628 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\adadf795703beaac3ea8f3c1049c4e43110cd35c Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:55.629 [Cloud] End of cloud request. 2026-05-01T17:46:55.629 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ab81960 2026-05-01T17:46:55.691 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:55.692 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:55.692 [Cloud] Queued cloud request. 2026-05-01T17:46:55.692 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:55.692 [Cloud] Dequeued cloud request. 2026-05-01T17:46:55.692 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:55.735 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\657c49d658ccae926cd0fa75079847cc29ad3da2 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:55 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:55.913 Dynamic signature received 2026-05-01T17:46:55.914 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:55.915 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b7d3581 2026-05-01T17:46:56.437 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:56.536 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:56.536 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:56.536 [Cloud] Queued cloud request. 2026-05-01T17:46:56.536 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:56.536 [Cloud] Dequeued cloud request. 2026-05-01T17:46:56.536 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:56.734 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3869d549bfb724456f857f79688dba80ae5cebee Dynamic Signature Compilation Timestamp:05-01-2026 17:46:55 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:56.735 [Cloud] End of cloud request. 2026-05-01T17:46:56.735 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6b5411ee Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf8111669 2026-05-01T17:46:56.882 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:56.883 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:56.883 [Cloud] Queued cloud request. 2026-05-01T17:46:56.883 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:56.883 [Cloud] Dequeued cloud request. 2026-05-01T17:46:56.883 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:57.070 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4273defc9bdf43fd3375485e609212a51a8c9586 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:56 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:57.071 [Cloud] End of cloud request. 2026-05-01T17:46:57.071 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:57.253 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b51e504 2026-05-01T17:46:57.637 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:57.637 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:57.637 [Cloud] Queued cloud request. 2026-05-01T17:46:57.637 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:57.637 [Cloud] Dequeued cloud request. 2026-05-01T17:46:57.638 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:57.843 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e598b14f1ddca534d25f5d53d1f6b6c96826fef3 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:57.844 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:57.844 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7b9a754b 2026-05-01T17:46:57.948 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:57.948 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:57.948 [Cloud] Queued cloud request. 2026-05-01T17:46:57.948 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:57.948 [Cloud] Dequeued cloud request. 2026-05-01T17:46:57.948 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:58.205 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4b3f040f3e8aa0075a1232c13247f321e6af57ac Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:58.206 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:46:58.208 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d008459 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfadbb58b 2026-05-01T17:46:58.376 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:46:58.440 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:58.440 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:58.440 [Cloud] Queued cloud request. 2026-05-01T17:46:58.440 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:58.440 [Cloud] Dequeued cloud request. 2026-05-01T17:46:58.440 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\885533744e1e909a2fea44aed5cac6598353a050 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:46:58.735 Dynamic signature received 2026-05-01T17:46:58.736 [Cloud] End of cloud request. 2026-05-01T17:46:58.736 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8a547fa1 2026-05-01T17:46:58.799 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:46:58.799 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:46:58.799 [Cloud] Queued cloud request. 2026-05-01T17:46:58.799 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:46:58.799 [Cloud] Dequeued cloud request. 2026-05-01T17:46:58.799 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:46:59.259 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:47:08.802 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume10\xampp\php\ext\php_gettext.dll. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-05-01T17:47:08.819 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x01a849d6 2026-05-01T17:47:08.932 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:08.932 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:08.932 [Cloud] Queued cloud request. 2026-05-01T17:47:08.932 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:08.932 [Cloud] Dequeued cloud request. 2026-05-01T17:47:08.932 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:09.140 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\34c04b32e1fd424d5437f92d3fcdc8fd61f2c34b Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:09.141 [Cloud] End of cloud request. 2026-05-01T17:47:09.141 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf559b5cf 2026-05-01T17:47:09.198 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:09.198 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:09.198 [Cloud] Queued cloud request. 2026-05-01T17:47:09.198 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:09.198 [Cloud] Dequeued cloud request. 2026-05-01T17:47:09.198 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:09.338 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:47:09.520 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\61cd7987fc0e0741553b3cda54cf2db86d5adb20 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:09.521 [Cloud] End of cloud request. 2026-05-01T17:47:09.521 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x855c0bbc 2026-05-01T17:47:09.571 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:09.571 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:09.571 [Cloud] Queued cloud request. 2026-05-01T17:47:09.571 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:09.571 [Cloud] Dequeued cloud request. 2026-05-01T17:47:09.572 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:09.771 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d9dffb7063b0218735e752d5e7d2ba77708dfcbb Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:09.772 [Cloud] End of cloud request. 2026-05-01T17:47:09.772 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3e82d95a 2026-05-01T17:47:09.839 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:09.839 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:09.839 [Cloud] Queued cloud request. 2026-05-01T17:47:09.839 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:09.839 [Cloud] Dequeued cloud request. 2026-05-01T17:47:09.839 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:10.047 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:47:10.071 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\224aeed77b00379528457f2c30dcc56745e88f7e Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:10.072 [Cloud] End of cloud request. 2026-05-01T17:47:10.072 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x35a9d751 2026-05-01T17:47:10.142 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:10.142 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:10.142 [Cloud] Queued cloud request. 2026-05-01T17:47:10.142 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:10.143 [Cloud] Dequeued cloud request. 2026-05-01T17:47:10.143 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\173ca5267402020a41997d4c239bfb242c012971 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:10.344 Dynamic signature received 2026-05-01T17:47:10.345 [Cloud] End of cloud request. 2026-05-01T17:47:10.345 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x995634cd 2026-05-01T17:47:10.463 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:10.464 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:10.464 [Cloud] Queued cloud request. 2026-05-01T17:47:10.464 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:10.464 [Cloud] Dequeued cloud request. 2026-05-01T17:47:10.465 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:10.598 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:47:10.670 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6d7b8b26ec5bae7b061d679c5541797cdb232f3 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:10.671 [Cloud] End of cloud request. 2026-05-01T17:47:10.671 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0a55e18 2026-05-01T17:47:10.731 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T17:47:10.732 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T17:47:10.732 [Cloud] Queued cloud request. 2026-05-01T17:47:10.732 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T17:47:10.732 [Cloud] Dequeued cloud request. 2026-05-01T17:47:10.732 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T17:47:10.921 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b28e7a4d4c706750f9ab0a1189d75a8fe684f8da Dynamic Signature Compilation Timestamp:05-01-2026 17:47:10 Persistence Type:Duration Time remaining:50065408 2026-05-01T17:47:10.922 [Cloud] End of cloud request. 2026-05-01T17:47:10.922 RTSD:RTSD recieved, rescanning impacted resources 2026-05-01T17:47:11.184 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T17:48:13.351 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T17:48:13.351 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 13900, Count: 359, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 5728, TotalTime: 11668, Count: 623, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume8\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 2% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 5500, TotalTime: 9809, Count: 899, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume7\xampp\phpMyAdmin\js\functions.js, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T17:48:13.351 ProcessImageName: DesktopOK.exe, Pid: 3716, TotalTime: 5445, Count: 747, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 9148, TotalTime: 4223, Count: 78, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\php7ts.dll, EstimatedImpact: 21% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 8220, TotalTime: 3799, Count: 77, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 13% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 5980, TotalTime: 3693, Count: 74, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume7\xampp\php\php5ts.dll, EstimatedImpact: 12% 2026-05-01T17:48:13.351 ProcessImageName: helper.exe, Pid: 11636, TotalTime: 3648, Count: 90, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 82% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 10704, TotalTime: 3127, Count: 195, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\03_Album\Gallery\CH-Gallery-1.2.7\index.php, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 7544, TotalTime: 2217, Count: 76, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 71% 2026-05-01T17:48:13.351 ProcessImageName: xampp-control.exe, Pid: 9660, TotalTime: 1778, Count: 9, MaxTime: 1562, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T17:48:13.351 ProcessImageName: xampp-control.exe, Pid: 6892, TotalTime: 1575, Count: 6, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 3% 2026-05-01T17:48:13.351 ProcessImageName: xampp-control.exe, Pid: 14184, TotalTime: 1543, Count: 9, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T17:48:13.351 ProcessImageName: xampp-control.exe, Pid: 2180, TotalTime: 1325, Count: 6, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T17:48:13.351 ProcessImageName: mysqld.exe, Pid: 4948, TotalTime: 1066, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: httpd.exe, Pid: 14048, TotalTime: 984, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\logs\php_error_log, EstimatedImpact: 0% 2026-05-01T17:48:13.351 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T17:48:13.351 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: iWatchDVR.exe, Pid: 8008, TotalTime: 764, Count: 8, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\{EC351E9C-0CD1-4459-9DA1-82BA5DC21729}\module\RapaRobot.dll.1.1.0.2322-77FE66DF5CE6F319C6464468A3D1CF1F->(UPX), EstimatedImpact: 5% 2026-05-01T17:48:13.352 ProcessImageName: PDFXCview.exe, Pid: 7820, TotalTime: 750, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 55% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: notepad++.exe, Pid: 7580, TotalTime: 708, Count: 54, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 4% 2026-05-01T17:48:13.352 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T17:48:13.352 ProcessImageName: httpd.exe, Pid: 11120, TotalTime: 623, Count: 3, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 42% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 13616, TotalTime: 615, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\share\english\errmsg.sys, EstimatedImpact: 31% 2026-05-01T17:48:13.352 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T17:48:13.352 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T17:48:13.352 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 455, Count: 34, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: updater.exe, Pid: 212, TotalTime: 439, Count: 35, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T17:48:13.352 ProcessImageName: firefox.exe, Pid: 3184, TotalTime: 405, Count: 47, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09260, EstimatedImpact: 52% 2026-05-01T17:48:13.352 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 3984, TotalTime: 390, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 376, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7627F19F3, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: httpd.exe, Pid: 6328, TotalTime: 338, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 278, Count: 9, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: vlc.exe, Pid: 5608, TotalTime: 242, Count: 33, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\vlc\vlc-qt-interface.ini, EstimatedImpact: 5% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 242, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 2480, TotalTime: 232, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OpenWith.exe, Pid: 3812, TotalTime: 214, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Windows Media Player\wmplayer.exe, EstimatedImpact: 35% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: updater.exe, Pid: 3656, TotalTime: 151, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 4472, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 8096, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T17:48:13.352 ProcessImageName: Notepad.exe, Pid: 3624, TotalTime: 137, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T17:48:13.352 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T17:48:13.352 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T17:48:13.352 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: firefox.exe, Pid: 6628, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: Photos.exe, Pid: 11044, TotalTime: 106, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 5% 2026-05-01T17:48:13.352 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 92, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: Notepad.exe, Pid: 14284, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T17:48:13.352 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T17:48:13.352 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T17:48:13.352 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T17:48:13.352 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T17:48:13.352 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: httpd.exe, Pid: 4676, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: Notepad.exe, Pid: 7488, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 11% 2026-05-01T17:48:13.352 ProcessImageName: notepad++.exe, Pid: 1576, TotalTime: 61, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 12428, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: httpd.exe, Pid: 5924, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\htdocs\index.html, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T17:48:13.352 ProcessImageName: mysqld.exe, Pid: 5836, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: SDXHelper.exe, Pid: 8352, TotalTime: 46, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 4% 2026-05-01T17:48:13.352 ProcessImageName: TeamViewer.exe, Pid: 8076, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 13332, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7996_1608984001\BIT692.tmp, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: dasHost.exe, Pid: 5404, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: printfilterpipelinesvc.exe, Pid: 10580, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_620c281895426e89\MPDW-pipelineconfig.xml, EstimatedImpact: 26% 2026-05-01T17:48:13.352 ProcessImageName: xampp-control.exe, Pid: 7000, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\readme_de.txt, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 12588, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1620.log, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: xampp-control.exe, Pid: 13136, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T17:48:13.352 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T17:48:13.352 ProcessImageName: FileCoAuth.exe, Pid: 13200, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.13200.1.aodl, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: AdobeARM.exe, Pid: 4928, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\Other[1].htm, EstimatedImpact: 7% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: FileCoAuth.exe, Pid: 1416, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1547.1416.1.aodl, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: PhoneExperienceHost.exe, Pid: 6508, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 7592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1651.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: FileCoAuth.exe, Pid: 10580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.10580.1.aodl, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 7308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1600.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 7708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1729.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 12800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1838.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1827.log, EstimatedImpact: 1% 2026-05-01T17:48:13.352 ProcessImageName: SDXHelper.exe, Pid: 876, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381, EstimatedImpact: 9% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 4032, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1819.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 10268, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1751.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 11164, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1759.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 1724, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1611.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: AdobeARM.exe, Pid: 8084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: pingsender.exe, Pid: 11444, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\631e25a7-6735-4569-8273-eeff025828a7, EstimatedImpact: 3% 2026-05-01T17:48:13.352 ProcessImageName: SDXHelper.exe, Pid: 7424, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T17:48:13.352 ProcessImageName: helper.exe, Pid: 7248, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nsv79C4.tmp\System.dll, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: OfficeC2RClient.exe, Pid: 10388, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1655.log, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T17:48:13.352 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T17:49:05.055 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #78174, FileId: 0x350000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:49:05.057 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #78173, FileId: 0x330000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:49:05.059 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #78175, FileId: 0x7000000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:49:05.060 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #78176, FileId: 0x7200000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:49:05.510 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #78224, FileId: 0x410000000119d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T17:54:20.307 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T18:09:25.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T18:24:30.302 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T18:39:35.307 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T18:54:40.311 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5ca953c5 Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x5ca953c5 2026-05-01T19:09:45.310 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T19:24:50.129 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T19:39:54.982 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T19:48:12.966 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T19:48:12.966 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 14652, Count: 390, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 5728, TotalTime: 11668, Count: 623, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume8\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 2% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 5500, TotalTime: 9809, Count: 899, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume7\xampp\phpMyAdmin\js\functions.js, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 10180, TotalTime: 7287, Count: 415, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T19:48:12.966 ProcessImageName: DesktopOK.exe, Pid: 3716, TotalTime: 5445, Count: 747, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 9148, TotalTime: 4223, Count: 78, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\php7ts.dll, EstimatedImpact: 21% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 8220, TotalTime: 3799, Count: 77, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 13% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 5980, TotalTime: 3693, Count: 74, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume7\xampp\php\php5ts.dll, EstimatedImpact: 12% 2026-05-01T19:48:12.966 ProcessImageName: helper.exe, Pid: 11636, TotalTime: 3648, Count: 90, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 82% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 10704, TotalTime: 3127, Count: 195, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\03_Album\Gallery\CH-Gallery-1.2.7\index.php, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 7544, TotalTime: 2217, Count: 76, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 71% 2026-05-01T19:48:12.966 ProcessImageName: xampp-control.exe, Pid: 9660, TotalTime: 1778, Count: 9, MaxTime: 1562, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: xampp-control.exe, Pid: 6892, TotalTime: 1698, Count: 10, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T19:48:12.966 ProcessImageName: xampp-control.exe, Pid: 14184, TotalTime: 1543, Count: 9, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T19:48:12.966 ProcessImageName: xampp-control.exe, Pid: 2180, TotalTime: 1325, Count: 6, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T19:48:12.966 ProcessImageName: mysqld.exe, Pid: 4948, TotalTime: 1066, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 14048, TotalTime: 984, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\logs\php_error_log, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T19:48:12.966 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: iWatchDVR.exe, Pid: 8008, TotalTime: 764, Count: 8, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\{EC351E9C-0CD1-4459-9DA1-82BA5DC21729}\module\RapaRobot.dll.1.1.0.2322-77FE66DF5CE6F319C6464468A3D1CF1F->(UPX), EstimatedImpact: 5% 2026-05-01T19:48:12.966 ProcessImageName: PDFXCview.exe, Pid: 7820, TotalTime: 750, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 55% 2026-05-01T19:48:12.966 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: notepad++.exe, Pid: 7580, TotalTime: 708, Count: 54, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 4% 2026-05-01T19:48:12.966 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T19:48:12.966 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T19:48:12.966 ProcessImageName: mysqld.exe, Pid: 13616, TotalTime: 675, Count: 79, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\share\english\errmsg.sys, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: httpd.exe, Pid: 11120, TotalTime: 623, Count: 3, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 42% 2026-05-01T19:48:12.966 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T19:48:12.966 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 515, Count: 39, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.966 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T19:48:12.966 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T19:48:12.966 ProcessImageName: updater.exe, Pid: 212, TotalTime: 439, Count: 35, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-05-01T19:48:12.966 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T19:48:12.966 ProcessImageName: firefox.exe, Pid: 13916, TotalTime: 406, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\459ae8c1-2f1f-42f9-b28a-8e032eff6981, EstimatedImpact: 51% 2026-05-01T19:48:12.966 ProcessImageName: firefox.exe, Pid: 3184, TotalTime: 405, Count: 47, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09260, EstimatedImpact: 52% 2026-05-01T19:48:12.966 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 3984, TotalTime: 390, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 376, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7627F19F3, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: httpd.exe, Pid: 6328, TotalTime: 338, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 278, Count: 9, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 257, Count: 17, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: vlc.exe, Pid: 5608, TotalTime: 242, Count: 33, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\vlc\vlc-qt-interface.ini, EstimatedImpact: 5% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 2480, TotalTime: 232, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OpenWith.exe, Pid: 3812, TotalTime: 214, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Windows Media Player\wmplayer.exe, EstimatedImpact: 35% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: updater.exe, Pid: 3656, TotalTime: 151, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 4472, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 8096, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T19:48:12.967 ProcessImageName: Notepad.exe, Pid: 3624, TotalTime: 137, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T19:48:12.967 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T19:48:12.967 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 135, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T19:48:12.967 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: firefox.exe, Pid: 6628, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: Photos.exe, Pid: 11044, TotalTime: 106, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 5% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 14740, TotalTime: 105, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 92, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 14980, TotalTime: 90, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: Notepad.exe, Pid: 14284, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T19:48:12.967 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T19:48:12.967 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T19:48:12.967 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T19:48:12.967 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T19:48:12.967 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: httpd.exe, Pid: 4676, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: Notepad.exe, Pid: 7488, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 11% 2026-05-01T19:48:12.967 ProcessImageName: httpd.exe, Pid: 11788, TotalTime: 62, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\HTTP_FORBIDDEN.html.var, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 1576, TotalTime: 61, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 12428, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 1860, TotalTime: 60, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: httpd.exe, Pid: 5924, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\htdocs\index.html, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 11444, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 5640, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-2119.log, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 5836, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 5576, TotalTime: 46, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 8352, TotalTime: 46, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 4% 2026-05-01T19:48:12.967 ProcessImageName: TeamViewer.exe, Pid: 8076, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: svchost.exe, Pid: 13332, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7996_1608984001\BIT692.tmp, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: dasHost.exe, Pid: 5404, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: printfilterpipelinesvc.exe, Pid: 10580, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_620c281895426e89\MPDW-pipelineconfig.xml, EstimatedImpact: 26% 2026-05-01T19:48:12.967 ProcessImageName: xampp-control.exe, Pid: 7000, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\readme_de.txt, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 12588, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1620.log, EstimatedImpact: 2% 2026-05-01T19:48:12.967 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T19:48:12.967 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T19:48:12.967 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 5616, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 6% 2026-05-01T19:48:12.967 ProcessImageName: xampp-control.exe, Pid: 13136, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: FileCoAuth.exe, Pid: 13200, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.13200.1.aodl, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: AdobeARM.exe, Pid: 4928, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\Other[1].htm, EstimatedImpact: 7% 2026-05-01T19:48:12.967 ProcessImageName: httpd.exe, Pid: 4288, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\tmp\sess_13nud9ubncgpm9esi42dlncl8rorpjnk, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 13424, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 5% 2026-05-01T19:48:12.967 ProcessImageName: mysqld.exe, Pid: 12312, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: FileCoAuth.exe, Pid: 1416, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1547.1416.1.aodl, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: PhoneExperienceHost.exe, Pid: 6508, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 3% 2026-05-01T19:48:12.967 ProcessImageName: notepad++.exe, Pid: 4160, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\index.html, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 12800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1838.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 7592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1651.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 3192, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1952.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 7308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1600.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 7708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1729.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1827.log, EstimatedImpact: 1% 2026-05-01T19:48:12.967 ProcessImageName: FileCoAuth.exe, Pid: 10580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.10580.1.aodl, EstimatedImpact: 0% 2026-05-01T19:48:12.967 ProcessImageName: SDXHelper.exe, Pid: 876, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-01T19:48:12.968 ProcessImageName: pingsender.exe, Pid: 14484, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\347e5666-23cd-43d6-92c2-dd703d6dabd2, EstimatedImpact: 7% 2026-05-01T19:48:12.968 ProcessImageName: pingsender.exe, Pid: 3204, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\f3f3e8ad-3190-40f5-9419-7c2111e54e28, EstimatedImpact: 7% 2026-05-01T19:48:12.968 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381, EstimatedImpact: 9% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 4032, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1819.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 12856, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-2127.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: xampp-control.exe, Pid: 7824, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 10268, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1751.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 1724, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1611.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 11164, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1759.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: AdobeARM.exe, Pid: 8084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-05-01T19:48:12.968 ProcessImageName: SDXHelper.exe, Pid: 7424, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-05-01T19:48:12.968 ProcessImageName: pingsender.exe, Pid: 11444, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\631e25a7-6735-4569-8273-eeff025828a7, EstimatedImpact: 3% 2026-05-01T19:48:12.968 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T19:48:12.968 ProcessImageName: pingsender.exe, Pid: 10728, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\089bbaa0-3e64-4884-b6cb-694102a20f24, EstimatedImpact: 4% 2026-05-01T19:48:12.968 ProcessImageName: helper.exe, Pid: 7248, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nsv79C4.tmp\System.dll, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: OfficeC2RClient.exe, Pid: 10388, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1655.log, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T19:48:12.968 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T19:54:59.858 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T19:59:35.535 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #86755, FileId: 0x240000000bdf11, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T20:10:04.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T20:25:09.703 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T20:40:14.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T20:55:19.624 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{AE42A2EF-212F-30FB-34F0-B134BBE0C73C} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:7308 ProcessCreationTime:134221426359498598 SessionID:1 CreationTime:05-01-2026 21:02:47 ImagePath:E:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: E:\xampp\xampp-control.exe:14300:3,C:\Windows\System32\csrss.exe:696:2, Operations:None END BM telemetry 2026-05-01T21:02:48.829 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-01T21:02:48.829 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T21:02:48.829 [Cloud] Queued cloud request. 2026-05-01T21:02:48.829 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-01T21:02:48.831 [Cloud] Dequeued cloud request. 2026-05-01T21:02:48.831 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T21:02:48.842 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-05-01T21:02:48.842 [Cloud] Start of cloud request. Passive mode: 0 2026-05-01T21:02:48.842 [Cloud] Queued cloud request. 2026-05-01T21:02:48.842 [Cloud] Dequeued cloud request. 2026-05-01T21:02:48.848 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-01T21:02:49.106 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-01T21:02:49.107 [Cloud] End of cloud request. 2026-05-01T21:02:49.209 [Cloud] End of cloud request. 2026-05-01T21:02:49.629 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T21:10:24.600 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T21:25:29.576 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T21:40:34.566 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T21:48:12.620 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 16345, Count: 533, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 5728, TotalTime: 11668, Count: 623, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume8\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 2% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 5500, TotalTime: 9809, Count: 899, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume7\xampp\phpMyAdmin\js\functions.js, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 10180, TotalTime: 7287, Count: 415, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T21:48:12.620 ProcessImageName: DesktopOK.exe, Pid: 3716, TotalTime: 5445, Count: 747, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 4700, TotalTime: 4240, Count: 317, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\vendor\phpseclib\phpseclib\phpseclib\Crypt\Base.php, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 9148, TotalTime: 4223, Count: 78, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\php7ts.dll, EstimatedImpact: 21% 2026-05-01T21:48:12.620 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 3989, Count: 95, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 8220, TotalTime: 3799, Count: 77, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 13% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 5980, TotalTime: 3693, Count: 74, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume7\xampp\php\php5ts.dll, EstimatedImpact: 12% 2026-05-01T21:48:12.620 ProcessImageName: helper.exe, Pid: 11636, TotalTime: 3648, Count: 90, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 82% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 10704, TotalTime: 3127, Count: 195, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\03_Album\Gallery\CH-Gallery-1.2.7\index.php, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: SrTasks.exe, Pid: 6680, TotalTime: 2957, Count: 407, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\snapshot-2, EstimatedImpact: 12% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 12856, TotalTime: 2389, Count: 76, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\southgateinn\SouthGateInn\js\jquery.dataTables.min.js, EstimatedImpact: 15% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 7544, TotalTime: 2217, Count: 76, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\libcrypto-1_1-x64.dll, EstimatedImpact: 71% 2026-05-01T21:48:12.620 ProcessImageName: xampp-control.exe, Pid: 9660, TotalTime: 1778, Count: 9, MaxTime: 1562, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: xampp-control.exe, Pid: 6892, TotalTime: 1698, Count: 10, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: DeviceCensus.exe, Pid: 1276, TotalTime: 1684, Count: 6, MaxTime: 812, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 46% 2026-05-01T21:48:12.620 ProcessImageName: xampp-control.exe, Pid: 14184, TotalTime: 1543, Count: 9, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 13104, TotalTime: 1450, Count: 68, MaxTime: 859, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDrive.Sync.Service.dll, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: powershell.exe, Pid: 1324, TotalTime: 1399, Count: 28, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 13% 2026-05-01T21:48:12.620 ProcessImageName: xampp-control.exe, Pid: 2180, TotalTime: 1325, Count: 6, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: GUP.exe, Pid: 7012, TotalTime: 1093, Count: 31, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\npp.8.9.3.Installer.x64.exe, EstimatedImpact: 5% 2026-05-01T21:48:12.620 ProcessImageName: mysqld.exe, Pid: 4948, TotalTime: 1066, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 14048, TotalTime: 984, Count: 87, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\logs\php_error_log, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: npp.8.9.3.Installer.x64.exe, Pid: 2580, TotalTime: 889, Count: 114, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\nsm5526.tmp\System.dll, EstimatedImpact: 2% 2026-05-01T21:48:12.620 ProcessImageName: svchost.exe, Pid: 3920, TotalTime: 811, Count: 3, MaxTime: 656, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: iWatchDVR.exe, Pid: 8008, TotalTime: 764, Count: 8, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\{EC351E9C-0CD1-4459-9DA1-82BA5DC21729}\module\RapaRobot.dll.1.1.0.2322-77FE66DF5CE6F319C6464468A3D1CF1F->(UPX), EstimatedImpact: 5% 2026-05-01T21:48:12.620 ProcessImageName: PDFXCview.exe, Pid: 7820, TotalTime: 750, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 55% 2026-05-01T21:48:12.620 ProcessImageName: svchost.exe, Pid: 3768, TotalTime: 746, Count: 9, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO8BCB.tmp, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: notepad++.exe, Pid: 7580, TotalTime: 708, Count: 54, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 4% 2026-05-01T21:48:12.620 ProcessImageName: notepad++.exe, Pid: 7032, TotalTime: 705, Count: 60, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 3% 2026-05-01T21:48:12.620 ProcessImageName: WmiPrvSE.exe, Pid: 7028, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 80% 2026-05-01T21:48:12.620 ProcessImageName: mysqld.exe, Pid: 13616, TotalTime: 675, Count: 79, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\share\english\errmsg.sys, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: httpd.exe, Pid: 11120, TotalTime: 623, Count: 3, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 42% 2026-05-01T21:48:12.620 ProcessImageName: WmiPrvSE.exe, Pid: 1216, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-01T21:48:12.620 ProcessImageName: svchost.exe, Pid: 1500, TotalTime: 545, Count: 43, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.620 ProcessImageName: notepad++.exe, Pid: 4360, TotalTime: 507, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 7% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 4160, TotalTime: 497, Count: 69, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\oben.html@2026-05-01_221648, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 10212, TotalTime: 467, Count: 67, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07040, EstimatedImpact: 48% 2026-05-01T21:48:12.621 ProcessImageName: updater.exe, Pid: 212, TotalTime: 439, Count: 35, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0001), EstimatedImpact: 3% 2026-05-01T21:48:12.621 ProcessImageName: powershell.exe, Pid: 11732, TotalTime: 432, Count: 29, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 28% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 13916, TotalTime: 406, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\459ae8c1-2f1f-42f9-b28a-8e032eff6981, EstimatedImpact: 51% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 3184, TotalTime: 405, Count: 47, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09260, EstimatedImpact: 52% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 6748, TotalTime: 405, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 12% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 3984, TotalTime: 390, Count: 38, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: AdobeCollabSync.exe, Pid: 13148, TotalTime: 376, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7627F19F3, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 488, TotalTime: 353, Count: 43, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\southgateinn_\SouthGateInn\includes\database.php, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: httpd.exe, Pid: 6328, TotalTime: 338, Count: 15, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 1% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 4248, TotalTime: 272, Count: 19, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\sru\SRUDB.jfm, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: PhoneExperienceHost.exe, Pid: 5432, TotalTime: 255, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: vlc.exe, Pid: 5608, TotalTime: 242, Count: 33, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\vlc\vlc-qt-interface.ini, EstimatedImpact: 5% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 2480, TotalTime: 232, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: OpenWith.exe, Pid: 3812, TotalTime: 214, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Windows Media Player\wmplayer.exe, EstimatedImpact: 35% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 202, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 804, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: httpd.exe, Pid: 4288, TotalTime: 181, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\tmp\sess_esc7jj5po5b5n4jfcmjajpog9avd11ku, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: Notepad.exe, Pid: 1048, TotalTime: 167, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\conf\httpd.conf, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: updater.exe, Pid: 3656, TotalTime: 151, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.log, EstimatedImpact: 1% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 4472, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: ngentask.exe, Pid: 2840, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 8096, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\mysql\bin\my.ini, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: taskhostw.exe, Pid: 8020, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 58% 2026-05-01T21:48:12.621 ProcessImageName: Notepad.exe, Pid: 3624, TotalTime: 137, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialog.xbf, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 4100, TotalTime: 136, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: AggregatorHost.exe, Pid: 5376, TotalTime: 136, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: backgroundTaskHost.exe, Pid: 8920, TotalTime: 135, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-01T21:48:12.621 ProcessImageName: backgroundTaskHost.exe, Pid: 6604, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1777483015, EstimatedImpact: 13% 2026-05-01T21:48:12.621 ProcessImageName: dllhost.exe, Pid: 5904, TotalTime: 135, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: Acrobat.exe, Pid: 6532, TotalTime: 122, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll, EstimatedImpact: 9% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 11108, TotalTime: 120, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\southgateinn\SouthGateInn\includes\config.php, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: ngentask.exe, Pid: 8568, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 6628, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: Photos.exe, Pid: 11044, TotalTime: 106, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 5% 2026-05-01T21:48:12.621 ProcessImageName: SDXHelper.exe, Pid: 12744, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\385C259C-BE25-46C3-A5FE-3FBB6747B1DD, EstimatedImpact: 3% 2026-05-01T21:48:12.621 ProcessImageName: OfficeC2RClient.exe, Pid: 7556, TotalTime: 106, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 14740, TotalTime: 105, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: FileCoAuth.exe, Pid: 6448, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\.ses, EstimatedImpact: 1% 2026-05-01T21:48:12.621 ProcessImageName: brynhildr.exe, Pid: 11048, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751, EstimatedImpact: 3% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 13248, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT2CC3.tmp, EstimatedImpact: 1% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 4220, TotalTime: 92, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 14980, TotalTime: 90, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: Notepad.exe, Pid: 14284, TotalTime: 90, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: SecurityHealthHost.exe, Pid: 8240, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-01T21:48:12.621 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 11% 2026-05-01T21:48:12.621 ProcessImageName: ngentask.exe, Pid: 4472, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 11% 2026-05-01T21:48:12.621 ProcessImageName: ngentask.exe, Pid: 4964, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 11% 2026-05-01T21:48:12.621 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 13212, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{38B2962F-A6B4-4AA9-B37E-FBF5DD665086}\EDGEMITMP_0681F.tmp\setup.exe, EstimatedImpact: 50% 2026-05-01T21:48:12.621 ProcessImageName: taskhostw.exe, Pid: 10468, TotalTime: 76, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: httpd.exe, Pid: 4676, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: FileCoAuth.exe, Pid: 936, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1102.936.1.aodl, EstimatedImpact: 1% 2026-05-01T21:48:12.621 ProcessImageName: Notepad.exe, Pid: 7488, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\25d1380a-34d5-4fee-a93b-d4f1e937b9c1.0.bin, EstimatedImpact: 11% 2026-05-01T21:48:12.621 ProcessImageName: httpd.exe, Pid: 11788, TotalTime: 62, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\HTTP_FORBIDDEN.html.var, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 1576, TotalTime: 61, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: OfficeC2RClient.exe, Pid: 9304, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: FileCoAuth.exe, Pid: 8208, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 12428, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 1860, TotalTime: 60, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: AcroCEF.exe, Pid: 13244, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 16% 2026-05-01T21:48:12.621 ProcessImageName: OfficeC2RClient.exe, Pid: 4612, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1152a.log, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 11444, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: httpd.exe, Pid: 5924, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\htdocs\index.html, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 5836, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: OfficeC2RClient.exe, Pid: 5640, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-2119.log, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: updater.exe, Pid: 1804, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 10% 2026-05-01T21:48:12.621 ProcessImageName: notepad++.exe, Pid: 5576, TotalTime: 46, Count: 30, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: SDXHelper.exe, Pid: 8352, TotalTime: 46, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 4% 2026-05-01T21:48:12.621 ProcessImageName: mysqld.exe, Pid: 14444, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: TeamViewer.exe, Pid: 8076, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: svchost.exe, Pid: 13332, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_7996_1608984001\BIT692.tmp, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: SDXHelper.exe, Pid: 1912, TotalTime: 45, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: Notepad.exe, Pid: 13248, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\72670eef-a237-4c0c-a45d-634df946f808.0.bin, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: dasHost.exe, Pid: 5404, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: printfilterpipelinesvc.exe, Pid: 10580, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_620c281895426e89\MPDW-pipelineconfig.xml, EstimatedImpact: 26% 2026-05-01T21:48:12.621 ProcessImageName: xampp-control.exe, Pid: 7000, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\xampp\readme_de.txt, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: OneDriveLauncher.exe, Pid: 7844, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-01T21:48:12.621 ProcessImageName: OfficeC2RClient.exe, Pid: 12588, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1620.log, EstimatedImpact: 2% 2026-05-01T21:48:12.621 ProcessImageName: xampp-control.exe, Pid: 13136, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-05-01T21:48:12.621 ProcessImageName: firefox.exe, Pid: 10992, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\omni.ja, EstimatedImpact: 14% 2026-05-01T21:48:12.621 ProcessImageName: Acrobat.exe, Pid: 8464, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 4% 2026-05-01T21:48:12.622 ProcessImageName: SDXHelper.exe, Pid: 5616, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 6% 2026-05-01T21:48:12.622 ProcessImageName: FileCoAuth.exe, Pid: 13200, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.13200.1.aodl, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: Notepad.exe, Pid: 7920, TotalTime: 31, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\c8223d31-e83f-4b7b-8ee2-5aafe510806d.bin, EstimatedImpact: 5% 2026-05-01T21:48:12.622 ProcessImageName: httpd.exe, Pid: 13124, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\conf\httpd.conf, EstimatedImpact: 10% 2026-05-01T21:48:12.622 ProcessImageName: notepad++.exe, Pid: 9032, TotalTime: 30, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: Notepad.exe, Pid: 2036, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\72670eef-a237-4c0c-a45d-634df946f808.0.bin, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: AdobeARM.exe, Pid: 4928, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\2YH7E8Q9\Other[1].htm, EstimatedImpact: 7% 2026-05-01T21:48:12.622 ProcessImageName: Notepad.exe, Pid: 864, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\c8223d31-e83f-4b7b-8ee2-5aafe510806d.bin, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: SDXHelper.exe, Pid: 13424, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 5% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 8640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: mysqld.exe, Pid: 12312, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 9644, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1304.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: FileCoAuth.exe, Pid: 1416, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1547.1416.1.aodl, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 13952, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 18% 2026-05-01T21:48:12.622 ProcessImageName: mysqld.exe, Pid: 6044, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: PhoneExperienceHost.exe, Pid: 6508, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 3% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 3192, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1952.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 7708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1729.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 7592, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1651.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 11044, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1207.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 7308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1600.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 12800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1838.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1827.log, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: FileCoAuth.exe, Pid: 10580, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-01.1615.10580.1.aodl, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 14484, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\347e5666-23cd-43d6-92c2-dd703d6dabd2, EstimatedImpact: 7% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 3204, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\f3f3e8ad-3190-40f5-9419-7c2111e54e28, EstimatedImpact: 7% 2026-05-01T21:48:12.622 ProcessImageName: SDXHelper.exe, Pid: 876, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 14608, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\a30b7ee3-ce20-4d1e-a735-cb57b985f5b5, EstimatedImpact: 7% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 8340, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\7978cd7e-338e-449c-9bb9-fe214d0ba315, EstimatedImpact: 8% 2026-05-01T21:48:12.622 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\F0BD97B4EC6CD8B71C35631738259CF9F2E54381, EstimatedImpact: 9% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 7964, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: powershell.exe, Pid: 3508, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 10268, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1751.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: xampp-control.exe, Pid: 7824, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 12856, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-2127.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: sihost.exe, Pid: 8116, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 4032, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1819.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 1724, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1611.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: rundll32.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Cursors\person_eoa.cur, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 11164, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1759.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: SDXHelper.exe, Pid: 7424, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 2% 2026-05-01T21:48:12.622 ProcessImageName: svchost.exe, Pid: 13188, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: SDXHelper.exe, Pid: 13908, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 1% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 10728, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\089bbaa0-3e64-4884-b6cb-694102a20f24, EstimatedImpact: 4% 2026-05-01T21:48:12.622 ProcessImageName: pingsender.exe, Pid: 11444, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\631e25a7-6735-4569-8273-eeff025828a7, EstimatedImpact: 3% 2026-05-01T21:48:12.622 ProcessImageName: AdobeARM.exe, Pid: 8084, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 3% 2026-05-01T21:48:12.622 ProcessImageName: DismHost.exe, Pid: 236, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 2% 2026-05-01T21:48:12.622 ProcessImageName: helper.exe, Pid: 7248, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nsv79C4.tmp\System.dll, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: OfficeC2RClient.exe, Pid: 10388, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260501-1655.log, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: brynhildr.exe, Pid: 4172, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-01T21:48:12.622 ProcessImageName: ApplicationFrameHost.exe, Pid: 1188, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\rescache\_merged\387692435\593211170.pri, EstimatedImpact: 0% 2026-05-01T21:55:39.547 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T22:01:08.974 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume10\xampp\tmp\#sql253c_20_7.MAI. Process: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #93287, FileId: 0x110000000010de, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:01:57.449 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume10\xampp\tmp\#sql253c_34_7.MAI. Process: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #93508, FileId: 0x90000000010fa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:02:21.899 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume10\xampp\tmp\#sql253c_42_7.MAI. Process: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #93611, FileId: 0x180000000010fa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:02:34.064 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume10\xampp\tmp\#sql253c_52_5.MAI. Process: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #93671, FileId: 0x290000000010fa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:10:44.546 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T22:25:49.542 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T22:40:31.124 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\3625F2E2-5C02-4297-BE40-58B7E81A70A92b9c.1dcd9bb82ad60b1 2026-05-01T22:40:31.338 Verifying engine and signature files (source: 0) ... 2026-05-01T22:40:31.338 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpengine.dll] due to PPL. 2026-05-01T22:40:31.338 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasbase.vdm] (file in cache) 2026-05-01T22:40:31.338 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-01T22:40:31.356 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasdlta.vdm] 2026-05-01T22:40:31.356 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpavbase.vdm] (file in cache) 2026-05-01T22:40:31.356 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-01T22:40:31.376 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpavdlta.vdm] 2026-05-01T22:40:31.537 [Engine] IsHybridMode: 0 2026-05-01T22:40:31.538 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-01T22:40:31.546 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-30869B6040E53BC2206458066F3B3C6707A55D17.bin): 0x00000002 2026-05-01T22:40:31.549 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-30869B6040E53BC2206458066F3B3C6707A55D17.bin) 2026-05-01T22:40:31.549 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-01T22:40:31.549 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-01T22:40:31.549 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-01T22:40:31.549 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-01T22:40:44.639 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-01T22:40:44.639 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-01T22:40:44.649 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF82C678020, lRefCount: 5, hr=0 2026-05-01T22:40:44.649 [Engine] New active engine 00007FFFBA5E8020 replacing engine 00007FF82C678020. Number of active engines: 2 2026-05-01T22:40:44.656 EngineInit:Global ASOC is enabled 2026-05-01T22:40:44.656 EngineInit:ASOO is enabled for developer volumes 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T22:40:44.726 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.727 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-01T22:40:44.729 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3f2d673135833fd6321ff161a19c2393b8bdd9a2 Dynamic Signature Compilation Timestamp:04-01-2026 19:26:53 Persistence Type:Duration Time remaining:150196224 2026-05-01T22:40:44.729 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62de9132c59fc85c3b88a9cc43112738199ea596 Dynamic Signature Compilation Timestamp:04-01-2026 19:27:04 Persistence Type:Duration Time remaining:150196224 2026-05-01T22:40:44.729 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5866ed75622314e002b815339a72992aa2c8cfc4 Dynamic Signature Compilation Timestamp:04-01-2026 19:27:15 Persistence Type:Duration Time remaining:150196224 2026-05-01T22:40:44.732 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4baa2a975ac254332543642c124c275ba6e2567f Dynamic Signature Compilation Timestamp:05-01-2026 14:34:54 Persistence Type:Duration Time remaining:288000000 2026-05-01T22:40:44.748 MpWriteUupSignatureVersion 1.449.391.0, hr = 0 2026-05-01T22:40:44.749 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-01T22:40:44.767 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-01T22:40:44.769 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-01T22:40:44.769 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-01T22:40:44.769 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-01T22:40:44.769 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-01T22:40:44.795 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-01T22:40:44.795 [Plugin] Initializing RTP plugin state... 2026-05-01T22:40:44.795 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-01T22:40:44.795 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎01‎-‎2026 11:48:14 Last Perf:‎05‎-‎01‎-‎2026 11:48:13 First RTP Scan:‎05‎-‎01‎-‎2026 11:48:14 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:5337 Misses:35066 BM Queue:0,403,0 Proc:0,298,0 File:0,396,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:97735 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:475154016 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:15 TotalStreamCon:65321 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:198192 TotalHits:815305 InstanceCacheInserts:6895 InstanceCacheUpdates:0 InstanceCacheDeletes:1586 InstanceCacheHits:848 InstanceCacheMisses:98063 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (7197/2324) Success: 2324, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-01T22:40:44.796 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50} 2026-05-01T22:40:44.796 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878}\mpasbase.vdm in use, hr=0x80070020 2026-05-01T22:40:44.798 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{63F9D5A7-DC8B-4C23-B74D-F2530EA59191} removed 2026-05-01T22:40:44.798 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-01T22:40:44.799 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.799 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.799 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.799 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.800 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-01-2026 22:40:44 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-01-2026 22:40:44 2026-05-01T22:40:44.804 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-01T22:40:44.804 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-01T22:40:44.806 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T22:40:44.806 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-01T22:40:44.808 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-01T22:40:44.808 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.808 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.809 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.809 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-01T22:40:44.810 MdCoreSvc is supported in this platform and OS Signature updated on 05-01-2026 22:40:44 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.391.0 AV Signature Version: 1.449.391.0 ************************************************************ 2026-05-01T22:40:44.812 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-01T22:40:44.812 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\3625F2E2-5C02-4297-BE40-58B7E81A70A92b9c.1dcd9bb82ad60b1 2026-05-01T22:40:44.826 Process scan (postsignatureupdatescan) started. 2026-05-01T22:40:44.908 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-01T22:40:44.910 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-01T22:40:45.273 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-01T22:40:45.273 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-01T22:40:45.273 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-01T22:40:45.303 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-01T22:40:45.303 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-01T22:40:45.303 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-01T22:40:45.303 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-01T22:40:45.303 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-01T22:40:45.311 [Engine] Engine 00007FF82C678020 no longer in use. Number of active engines: 1 2026-05-01T22:40:45.311 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-01T22:40:45.311 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-01T22:40:45.628 ProcessImageName: explorer.exe, Pid: 3644, TotalTime: 17100, Count: 604, MaxTime: 1265, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-01T22:40:45.628 ProcessImageName: CCC.exe, Pid: 12788, TotalTime: 15096, Count: 392, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Systemtray.dll, EstimatedImpact: 33% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 5728, TotalTime: 11668, Count: 623, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume8\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 2% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 5500, TotalTime: 9809, Count: 899, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume7\xampp\phpMyAdmin\js\functions.js, EstimatedImpact: 0% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 14828, TotalTime: 8181, Count: 478, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\libraries\classes\Display\Results.php, EstimatedImpact: 1% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 10180, TotalTime: 7287, Count: 415, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 0% 2026-05-01T22:40:45.628 ProcessImageName: setup.exe, Pid: 11668, TotalTime: 6861, Count: 396, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\147.0.3912.98\mspdf.dll, EstimatedImpact: 19% 2026-05-01T22:40:45.628 ProcessImageName: DesktopOK.exe, Pid: 3716, TotalTime: 5445, Count: 747, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 0% 2026-05-01T22:40:45.628 ProcessImageName: AcroCEF.exe, Pid: 9996, TotalTime: 4364, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 34% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 4700, TotalTime: 4240, Count: 317, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\phpMyAdmin\vendor\phpseclib\phpseclib\phpseclib\Crypt\Base.php, EstimatedImpact: 0% 2026-05-01T22:40:45.628 ProcessImageName: httpd.exe, Pid: 9148, TotalTime: 4223, Count: 78, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\php7ts.dll, EstimatedImpact: 21% 2026-05-01T22:40:45.629 ProcessImageName: dllhost.exe, Pid: 10320, TotalTime: 3989, Count: 95, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\625N68XGIH_38, EstimatedImpact: 0% 2026-05-01T22:40:45.629 ProcessImageName: httpd.exe, Pid: 8220, TotalTime: 3799, Count: 77, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 13% 2026-05-01T22:40:45.629 ProcessImageName: httpd.exe, Pid: 5980, TotalTime: 3693, Count: 74, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume7\xampp\php\php5ts.dll, EstimatedImpact: 12% 2026-05-01T22:40:45.629 ProcessImageName: helper.exe, Pid: 11636, TotalTime: 3648, Count: 90, MaxTime: 2062, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 82% 2026-05-01T22:40:45.629 ProcessImageName: httpd.exe, Pid: 10704, TotalTime: 3127, Count: 195, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\0_\03_Album\Gallery\CH-Gallery-1.2.7\index.php, EstimatedImpact: 0% 2026-05-01T22:40:45.710 [Engine] RSIG_UNLOADENGINE, 00007FF82C678020, err=0x0 2026-05-01T22:40:45.731 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{282BD216-4E34-4307-A766-EF23F71D0878} removed 2026-05-01T22:40:46.834 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T22:40:46.843 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-01T22:40:46.844 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-01T22:40:54.527 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-01T22:41:07.412 Process scan (postsignatureupdatescan) completed. 2026-05-01T22:45:44.693 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-01T22:54:40.238 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98081, FileId: 0x2700000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.245 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98080, FileId: 0x8100000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.245 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98079, FileId: 0x2600000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.268 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98083, FileId: 0x8400000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.269 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98087, FileId: 0x2b00000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.286 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98088, FileId: 0x8700000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.288 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98086, FileId: 0x2a00000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.673 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98132, FileId: 0x3100000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.674 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98134, FileId: 0x8c00000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.676 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98137, FileId: 0x8d00000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.691 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98143, FileId: 0x8f00000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.691 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98144, FileId: 0x3600000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98138, FileId: 0x3300000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.827 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98163, FileId: 0x3800000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.828 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98164, FileId: 0x9300000001024c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.845 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98161, FileId: 0x3700000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-01T22:54:40.872 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #98171, FileId: 0x3b00000006e5ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-02-2026 08:20:01 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/02/2026 08:20:01.949885000 UTC (15671 ms since boot) 2026-05-02T08:20:02.140 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-02T08:20:02.140 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-02T08:20:02.140 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-02T08:20:02.215 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260502-082002-00000003-fffffffeffffffff.bin ... 2026-05-02T08:20:02.365 [WPP] Trace session started - MpWppTracing-20260502-082002-00000003-fffffffeffffffff.bin 2026-05-02T08:20:02.370 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-02T08:20:02.370 [RbM] Rollback manager succesfully initialized. 2026-05-02T08:20:02.370 [RbM] Rollback manager EnableRollbackManager called. 2026-05-02T08:20:02.385 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-02T08:20:02.385 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-02T08:20:02.385 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-02T08:20:02.385 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-02T08:20:02.385 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-02T08:20:02.396 MdCoreSvc is supported in this platform and OS 2026-05-02T08:20:02.396 MdCoreSvc is supported in this platform and OS 2026-05-02T08:20:02.396 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-02T08:20:02.400 [PlatUpd] Starting MdCoreSvc service 2026-05-02T08:20:02.443 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-02T08:20:07.678 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-02T08:20:07.678 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-02T08:20:07.678 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-02T08:20:07.678 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-02T08:20:07.678 [PlatUpd] CSP platform update started 2026-05-02T08:20:07.678 [PlatUpd] Defender MDM CSP platform update not required 2026-05-02T08:20:07.678 [PlatUpd] WMI/PS provider platform update started 2026-05-02T08:20:07.678 [PlatUpd] WMI/PS provider platform update not required 2026-05-02T08:20:07.678 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-02T08:20:07.678 MdCoreSvc is supported in this platform and OS 2026-05-02T08:20:07.678 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-02T08:20:07.678 [PlatUpd] Starting MdCoreSvc service 2026-05-02T08:20:07.678 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-02T08:20:07.678 [TS] Troublshooting mode is not available! 2026-05-02T08:20:07.678 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-02T08:20:07.678 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-02T08:20:07.710 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-02T08:20:07.710 [Service] Enabling AutoLoggers ... 2026-05-02T08:20:07.725 [Service] Enabling AMSI registration ... 2026-05-02T08:20:07.725 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-02T08:20:07.741 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 45619 Number of invalid entries is 0 Number of inserts issued is 1578497 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6475 Number of lookups is 107703218 Number of lookup misses is 5172065 Number of fast lookup misses is 54875784 Number of false fast lookups is 5172060 Number of invalidations is 731651 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-02T08:20:07.741 Verifying license file... 2026-05-02T08:20:07.741 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-05-02T08:20:07.757 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-02T08:20:07.757 Loaded module#0 MpComServer. 2026-05-02T08:20:07.757 Loaded module#1 StartupPolicies. 2026-05-02T08:20:07.757 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-02T08:20:07.757 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-02T08:20:07.772 COM server initialized successfully. 2026-05-02T08:20:07.772 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-02T08:20:07.788 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-02T08:20:07.788 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-02T08:20:07.803 [RTP] [RTP] FilterCommunicator object 0x0000019E8C096660 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-02T08:20:07.819 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-02T08:20:07.819 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:20:07.819 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:20:07.819 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-02T08:20:07.819 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-02T08:20:07.819 [RTP] [RTP] FilterCommunicator object 0x0000019E8C08C520 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-02T08:20:07.819 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-02T08:20:07.819 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-02T08:20:07.819 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-02T08:20:07.819 [RTP] [RTP] StartCommunication 0x0000019E8C096660 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-02T08:20:07.819 [init][RTP] RTPPlugin initialization completed 2026-05-02T08:20:07.819 OS boot count = 2 2026-05-02T08:20:07.819 OS Install = 0 2026-05-02T08:20:07.882 [init] MpAddMpUxRegistrationForToast succeeded 2026-05-02T08:20:07.882 [KSL] Entering CKSLEngine::Initialize. 2026-05-02T08:20:07.882 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-02T08:20:07.882 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-02T08:20:07.882 [KSL] MpInstallKslD: hr=0x1 2026-05-02T08:20:07.882 [KSL] MpRegisterKslD: hr=0 2026-05-02T08:20:07.897 [KSL] MpStartKslD: hr=0 2026-05-02T08:20:07.897 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-02T08:20:07.897 Loading engine... 2026-05-02T08:20:07.913 Verifying engine and signature files (source: 1) ... 2026-05-02T08:20:07.913 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpengine.dll] due to PPL. 2026-05-02T08:20:07.913 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasbase.vdm] (file in cache) 2026-05-02T08:20:07.913 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasdlta.vdm] (file in cache) 2026-05-02T08:20:07.913 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpavbase.vdm] (file in cache) 2026-05-02T08:20:07.913 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpavdlta.vdm] (file in cache) 2026-05-02T08:20:07.991 [Engine] IsHybridMode: 0 2026-05-02T08:20:07.991 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-02T08:20:08.022 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-30869B6040E53BC2206458066F3B3C6707A55D17.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-02T08:20:27.018 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-02T08:20:27.018 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-02T08:20:27.018 [Engine] New active engine 00007FF960998020 (no old engine). Number of active engines: 1 2026-05-02T08:20:27.034 EngineInit:Global ASOC is enabled 2026-05-02T08:20:27.034 EngineInit:ASOO is enabled for developer volumes 2026-05-02T08:20:27.175 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-02T08:20:27.175 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.176 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.177 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.178 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.178 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:20:27.178 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\baaf2d6bb078686b6ecdff45978a1c543b09af7c Dynamic Signature Compilation Timestamp:04-01-2026 23:15:24 Persistence Type:Duration Time remaining:150196224 2026-05-02T08:20:27.184 Dynamic signature dropped 2026-05-02T08:20:27.345 MpWriteUupSignatureVersion 1.449.391.0, hr = 0 2026-05-02T08:20:27.347 [SigStatUpd] CSignatureStatus: back to good 2026-05-02T08:20:27.347 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-02T08:20:27.382 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-02T08:20:27.382 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-02T08:20:27.382 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-02T08:20:27.382 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-02T08:20:27.383 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-02T08:20:27.404 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-02T08:20:27.404 [Plugin] Initializing RTP plugin state... 2026-05-02T08:20:27.404 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,1,0 Proc:0,1,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2298 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3575 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:20971 TotalHits:0 InstanceCacheInserts:73 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3961 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-02T08:20:27.405 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-02T08:20:27.408 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50} 2026-05-02T08:20:27.412 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:20:27.412 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:20:27.412 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:20:27.413 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-02T08:20:27.413 MdCoreSvc is supported in this platform and OS 2026-05-02T08:20:27.414 Engine loaded! 2026-05-02T08:20:27.415 [DLP] Create FeatureControlState instance 2026-05-02T08:20:27.423 RegisterSModeChangeListener: hr = 0x1 2026-05-02T08:20:27.424 RegisterHybridModeChangeListener: hr = 0 2026-05-02T08:20:27.431 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-02T08:20:27.439 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-02T08:20:27.468 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-02T08:20:27.469 [SigReleaseHb] Initialized with Stage 0 2026-05-02T08:20:27.469 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-02T08:20:27.470 [SCC][CID=41187_5444] Initializing ... 2026-05-02T08:20:27.470 [SCC][CID=41187_5444] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-02T08:20:27.475 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-02T08:20:27.475 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-02T08:20:27.479 [NRI] Stopping NIS service ... 2026-05-02T08:20:27.479 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-02T08:20:27.479 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.391.0 AV Signature Version: 1.449.391.0 ************************************************************ 2026-05-02T08:20:27.480 Resource usage Monitoring is enabled 2026-05-02T08:20:27.485 Job Notification: New process added to job (4324) 2026-05-02T08:20:27.485 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-02T08:20:27.488 Job Notification: New process added to job (12160) 2026-05-02T08:20:27.495 Job Notification: New process added to job (12180) 2026-05-02T08:20:27.501 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-02T08:20:27.509 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:12160] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:12180]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-02T08:20:27.656 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-02T08:20:27.659 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-02T08:20:27.662 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-02T08:20:27.663 Job Notification: Process exited from job (12160) 2026-05-02T08:20:27.668 Job Notification: Process exited from job (12180) 2026-05-02T08:20:27.670 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-02T08:20:27.670 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-02T08:20:27.670 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-02T08:20:27.670 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:20:27.670 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:20:27.670 [RTP] Generating the base plugin configuration ... 2026-05-02T08:20:27.670 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-02T08:20:27.671 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:20:27.671 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-02T08:20:27.673 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-02T08:20:27.679 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:20:27.679 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-02T08:20:27.683 [RTP] [RTP] StartCommunication 0x0000019E8C08C520 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-02T08:20:27.727 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-02T08:20:27.826 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\ff53159c1e9130e12b04c211d4f658fa67488def.tbres 2026-05-02T08:20:27.893 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-02T08:20:27.893 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-02T08:20:27.893 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-02T08:20:28.120 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:20:30.664 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:20:30.664 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:20:30.664 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-02T08:20:30.665 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-02T08:20:30.665 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-02T08:20:44.367 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #1080, FileId: 0x260000000bcc81, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:21:07.803 Process scan (poststartupscan) started. 2026-05-02T08:21:07.805 Process scan (poststartupscan) completed. 2026-05-02T08:21:08.317 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-02T08:21:08.328 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-02T08:21:10.878 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:21:10.878 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:21:10.878 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-02T08:21:10.878 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-02T08:21:10.879 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-02T08:22:05.101 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:22:05.101 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:22:05.101 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:25:00.834 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4053, FileId: 0xb0000000002e88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:00.834 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4055, FileId: 0xb0000000c3d82, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:00.834 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4054, FileId: 0x25200000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:01.116 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0a2f125d-e843-4c57-9a09-8cc2313b6bab. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #4078, FileId: 0x15f0000000014bb, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:01.116 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4076, FileId: 0x230000000b9392, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:05.072 Bm signature throttled:0x00002db31bed458f 2026-05-02T08:25:07.900 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4091, FileId: 0x40000000c3d7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:25:27.073 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-02T08:25:27.480 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T08:29:06.637 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-05-02T08:29:06.637 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:29:06.637 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:29:06.637 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-02T08:29:06.637 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-02T08:29:06.637 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-02T08:29:06.700 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-02T08:29:06.700 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-02T08:29:06.746 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-02T08:30:27.474 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-02T08:30:27.474 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-02T08:30:27.490 Job Notification: New process added to job (11372) 2026-05-02T08:30:27.505 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-02T08:30:27.505 Job Notification: New process added to job (11520) 2026-05-02T08:30:27.521 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11372] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11520]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-02T08:30:27.568 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 61447826(ms) from now at 03:34 (01:34 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-02T08:30:27.599 Job Notification: New process added to job (5976) 2026-05-02T08:30:27.615 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-02T08:30:27.615 Job Notification: New process added to job (14100) 2026-05-02T08:30:27.615 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:5976] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:14100]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-02T08:30:37.523 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\D3C02283-B174-4C32-8F6E-7A158D05E523960.1dcda0df2b88e10 2026-05-02T08:30:37.617 Verifying engine and signature files (source: 0) ... 2026-05-02T08:30:37.617 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpengine.dll] due to PPL. 2026-05-02T08:30:37.617 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasbase.vdm] (file in cache) 2026-05-02T08:30:37.617 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-02T08:30:37.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasdlta.vdm] 2026-05-02T08:30:37.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavbase.vdm] (file in cache) 2026-05-02T08:30:37.648 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-02T08:30:37.663 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavdlta.vdm] 2026-05-02T08:30:37.820 [Engine] IsHybridMode: 0 2026-05-02T08:30:37.820 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-02T08:30:37.820 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-6666196AACEA04299295A2FC3A7FA6F768C186B2.bin): 0x00000002 2026-05-02T08:30:37.835 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-6666196AACEA04299295A2FC3A7FA6F768C186B2.bin) 2026-05-02T08:30:37.835 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-02T08:30:37.835 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-02T08:30:37.835 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-02T08:30:37.835 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-02T08:30:49.652 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-02T08:30:49.652 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-02T08:30:49.652 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF960998020, lRefCount: 5, hr=0 2026-05-02T08:30:49.652 [Engine] New active engine 00007FF932DF8020 replacing engine 00007FF960998020. Number of active engines: 2 2026-05-02T08:30:49.668 EngineInit:Global ASOC is enabled 2026-05-02T08:30:49.668 EngineInit:ASOO is enabled for developer volumes 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.730 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-02T08:30:49.746 MpWriteUupSignatureVersion 1.449.398.0, hr = 0 2026-05-02T08:30:49.746 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-02T08:30:49.762 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-02T08:30:49.762 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-02T08:30:49.762 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-02T08:30:49.762 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-02T08:30:49.762 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-02T08:30:49.777 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-02T08:30:49.777 [Plugin] Initializing RTP plugin state... 2026-05-02T08:30:49.777 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎02‎-‎2026 10:20:27 Last Perf:‎05‎-‎02‎-‎2026 10:20:27 First RTP Scan:‎05‎-‎02‎-‎2026 10:20:27 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1903 Misses:2564 BM Queue:0,373,0 Proc:0,130,0 File:0,267,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:4714 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:15015072 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:7713 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:32605 TotalHits:16413 InstanceCacheInserts:536 InstanceCacheUpdates:0 InstanceCacheDeletes:395 InstanceCacheHits:0 InstanceCacheMisses:10079 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:5ms (1112/193) Success: 193, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-02T08:30:49.777 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-02T08:30:49.777 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11} 2026-05-02T08:30:49.793 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-02T08:30:49.793 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{890BBD6C-2C3C-456F-8210-35D0BCEE9FC4} removed 2026-05-02T08:30:49.793 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50}\mpasbase.vdm in use, hr=0x80070020 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-02-2026 08:30:49 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-02-2026 08:30:49 2026-05-02T08:30:49.793 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-02T08:30:49.793 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-02T08:30:49.793 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:30:49.793 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-02T08:30:49.793 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.793 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-02T08:30:49.808 MdCoreSvc is supported in this platform and OS Signature updated on 05-02-2026 08:30:49 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.398.0 AV Signature Version: 1.449.398.0 ************************************************************ 2026-05-02T08:30:49.808 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-02T08:30:49.808 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\D3C02283-B174-4C32-8F6E-7A158D05E523960.1dcda0df2b88e10 2026-05-02T08:30:49.875 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-02T08:30:49.875 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 05-02-2026 08:30:49 ************************************************************ 2026-05-02T08:30:49.907 Job Notification: Process exited from job (5976) 2026-05-02T08:30:49.907 Job Notification: Process exited from job (14100) 2026-05-02T08:30:49.969 Job Notification: Process exited from job (11372) 2026-05-02T08:30:49.969 Job Notification: Process exited from job (11520) 2026-05-02T08:30:50.172 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-02T08:30:50.172 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-02T08:30:50.172 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-02T08:30:50.172 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:30:50.172 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:30:50.172 [Engine] Engine 00007FF960998020 no longer in use. Number of active engines: 1 2026-05-02T08:30:50.172 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:30:50.172 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-02T08:30:50.250 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-02T08:30:50.250 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-02T08:30:50.250 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-02T08:30:50.282 ProcessImageName: explorer.exe, Pid: 7364, TotalTime: 5303, Count: 130, MaxTime: 1437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-05-02T08:30:50.282 ProcessImageName: AsPowerBar.exe, Pid: 12396, TotalTime: 2741, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 11% 2026-05-02T08:30:50.282 ProcessImageName: DipAwayMode.exe, Pid: 6996, TotalTime: 2644, Count: 29, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 48% 2026-05-02T08:30:50.282 ProcessImageName: MOM.exe, Pid: 11140, TotalTime: 1852, Count: 29, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 62% 2026-05-02T08:30:50.282 ProcessImageName: AISuite3.exe, Pid: 7068, TotalTime: 1598, Count: 26, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 11% 2026-05-02T08:30:50.282 ProcessImageName: websockify.exe, Pid: 9224, TotalTime: 880, Count: 18, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-02T08:30:50.282 ProcessImageName: WmiPrvSE.exe, Pid: 3744, TotalTime: 405, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf->(UTF-16LE), EstimatedImpact: 21% 2026-05-02T08:30:50.282 ProcessImageName: firefox.exe, Pid: 5048, TotalTime: 210, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa04240, EstimatedImpact: 11% 2026-05-02T08:30:50.282 ProcessImageName: WhatsApp.Root.exe, Pid: 3300, TotalTime: 195, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-05-02T08:30:50.282 ProcessImageName: TabTip.exe, Pid: 12096, TotalTime: 185, Count: 5, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 93% 2026-05-02T08:30:50.282 ProcessImageName: FileCoAuth.exe, Pid: 3092, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-02T08:30:50.282 ProcessImageName: backgroundTaskHost.exe, Pid: 11748, TotalTime: 135, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1777483015->(UTF-16LE), EstimatedImpact: 16% 2026-05-02T08:30:50.282 ProcessImageName: PhoneExperienceHost.exe, Pid: 12124, TotalTime: 105, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-02T08:30:50.282 ProcessImageName: OfficeC2RClient.exe, Pid: 2860, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-02T08:30:50.282 ProcessImageName: svchost.exe, Pid: 1408, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 0% 2026-05-02T08:30:50.313 [Engine] RSIG_UNLOADENGINE, 00007FF960998020, err=0x0 2026-05-02T08:30:50.328 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C104C23E-177A-4A2D-9CCE-7C646A727F50} removed 2026-05-02T08:30:51.813 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:30:51.813 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:30:51.813 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:31:07.814 Process scan (postsignatureupdatescan) started. 2026-05-02T08:31:25.554 Process scan (postsignatureupdatescan) completed. 2026-05-02T08:32:07.503 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj194D5A9FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5257, FileId: 0x70000000c2c84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.526 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj47D3AA9CA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5258, FileId: 0x80000000c2c84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.529 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD134829E4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5259, FileId: 0xe0000000c2c83, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.613 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6066AC99F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5267, FileId: 0x50000000c2c88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.671 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj264CEE936. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5273, FileId: 0xa0000000c2c84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.750 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj600916965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5279, FileId: 0x290000000297fb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.796 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB8118F9B5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5293, FileId: 0xc0000000c2c84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.828 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB100749B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5295, FileId: 0x60000000c2c87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.859 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj039FDD9AC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5296, FileId: 0x90000000c2c88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:07.875 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj726A789BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5298, FileId: 0xa0000000c2c88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:08.580 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26DB43975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5307, FileId: 0x80000000c2c87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:22.092 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5454, FileId: 0x70000000c2c5b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:22.155 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5456, FileId: 0x80000000c2c7d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:32:22.249 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5461, FileId: 0x9f0000000130d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:33:22.433 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5559, FileId: 0xa60000000130d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:35:09.816 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #5654, FileId: 0x6440000000006ff, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:35:49.675 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-02T08:36:22.761 [AutoPurge] Verification Routine tasks have started. 2026-05-02T08:36:22.762 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-02T08:36:22.768 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-02T08:36:22.769 Scheduled scan with Id F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-02T08:36:22.772 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-02T08:36:22.772 [SFC] System file cache build is not needed (already completed) 2026-05-02T08:36:22.809 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-02T08:36:22.810 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-02T08:36:22.810 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-02T08:36:22.810 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-02T08:36:22.810 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-02T08:36:22.815 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.836 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.856 Engine:EMS scan for process: svchost pid: 912, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.861 Engine:EMS scan for process: svchost pid: 1048, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.866 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.875 Engine:EMS scan for process: svchost pid: 1244, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.883 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.889 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.892 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.898 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.900 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.902 Engine:EMS scan for process: svchost pid: 1516, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.906 Engine:EMS scan for process: svchost pid: 1564, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.911 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.917 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.921 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.925 Engine:EMS scan for process: svchost pid: 1968, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.930 Engine:EMS scan for process: svchost pid: 1976, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.933 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.938 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.940 Engine:EMS scan for process: svchost pid: 2124, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.944 Engine:EMS scan for process: svchost pid: 2244, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.948 Engine:EMS scan for process: svchost pid: 2260, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.951 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.956 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.959 Engine:EMS scan for process: svchost pid: 2476, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.961 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.963 Engine:EMS scan for process: svchost pid: 2608, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.966 Engine:EMS scan for process: svchost pid: 2712, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.970 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.973 Engine:EMS scan for process: svchost pid: 2960, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.978 Engine:EMS scan for process: svchost pid: 3052, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.987 Engine:EMS scan for process: svchost pid: 2544, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.994 Engine:EMS scan for process: svchost pid: 3316, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.997 Engine:EMS scan for process: svchost pid: 3324, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:22.999 Engine:EMS scan for process: svchost pid: 3396, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.019 Engine:EMS scan for process: svchost pid: 3408, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.025 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.033 Engine:EMS scan for process: svchost pid: 3728, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.037 Engine:EMS scan for process: svchost pid: 3884, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.041 Engine:EMS scan for process: svchost pid: 4004, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.048 Engine:EMS scan for process: svchost pid: 4040, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.051 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-02T08:36:23.055 Engine:EMS scan for process: svchost pid: 4048, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.056 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-02T08:36:23.068 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.073 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.086 Engine:EMS scan for process: svchost pid: 4260, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.118 Engine:EMS scan for process: svchost pid: 4348, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.123 Engine:EMS scan for process: svchost pid: 4476, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.127 Engine:EMS scan for process: svchost pid: 4932, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.130 Engine:EMS scan for process: svchost pid: 5064, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.137 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-02T08:36:23.163 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-02T08:36:23.165 [AutoPurge] Verification Routine tasks have ended. 2026-05-02T08:36:23.173 Engine:EMS scan for process: svchost pid: 5164, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.183 Engine:EMS scan for process: svchost pid: 5376, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.187 Engine:EMS scan for process: dllhost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.190 Engine:EMS scan for process: svchost pid: 6124, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.194 Engine:EMS scan for process: svchost pid: 6236, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.199 Engine:EMS scan for process: svchost pid: 6812, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.208 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.221 Engine:EMS scan for process: svchost pid: 7032, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.225 Bm signature throttled:0x00002db31bed458f 2026-05-02T08:36:23.230 Engine:EMS scan for process: svchost pid: 7120, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.240 Engine:EMS scan for process: svchost pid: 7116, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.244 Engine:EMS scan for process: svchost pid: 4620, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.248 Engine:EMS scan for process: svchost pid: 6636, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.252 Engine:EMS scan for process: svchost pid: 6660, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.254 Engine:EMS scan for process: explorer pid: 7364, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.318 Engine:EMS scan for process: svchost pid: 7456, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.323 Engine:EMS scan for process: svchost pid: 7616, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.328 Engine:EMS scan for process: svchost pid: 8024, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.332 Engine:EMS scan for process: svchost pid: 8300, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.338 Engine:EMS scan for process: svchost pid: 9508, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.339 Bm signature throttled:0x00002db31bed458f 2026-05-02T08:36:23.340 Engine:EMS scan for process: dllhost pid: 10800, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.343 Bm signature throttled:0x00002db31bed458f 2026-05-02T08:36:23.344 Engine:EMS scan for process: svchost pid: 10824, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.348 Engine:EMS scan for process: svchost pid: 8560, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.355 Engine:EMS scan for process: svchost pid: 14116, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.363 Engine:EMS scan for process: svchost pid: 5176, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.368 Engine:EMS scan for process: svchost pid: 9040, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.373 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.375 Engine:EMS scan for process: svchost pid: 9368, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.383 Engine:EMS scan for process: svchost pid: 11284, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.386 Engine:EMS scan for process: svchost pid: 1036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.392 [AutoPurge] Cleanup Routine tasks have started. 2026-05-02T08:36:23.392 Engine:EMS scan for process: svchost pid: 9068, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.396 Engine:EMS scan for process: dllhost pid: 5456, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.399 Engine:EMS scan for process: svchost pid: 15200, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-02T08:36:23.414 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-02T08:36:23.419 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-02T08:36:23.419 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-02-2026 08:36:23 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-02-2026 08:36:23 2026-05-02T08:36:23.433 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-02T08:36:23.433 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-02T08:36:23.433 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-02T08:36:23.434 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-02T08:36:23.439 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-02T08:36:24.808 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:36:24.834 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:36:24.840 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:36:27.022 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6908, FileId: 0x8f000000003c48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:37:04.106 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Windows\Prefetch\SETHC.EXE-1E0D0DA0.pf. Process: \Device\HarddiskVolume3\Windows\System32\sethc.exe, Status: 0xc000004b, State: 0, ScanRequest #8854, FileId: 0x10a0000000020ea, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:37:04.643 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-02T08:37:04.722 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:04.726 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:04.731 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-02T08:37:04.744 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-02T08:37:04.745 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-02T08:37:04.745 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:37:04.745 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:37:04.745 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-02T08:37:04.745 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-02T08:37:04.746 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-02T08:37:04.784 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:04.792 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:05.045 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 66707089(ms) from now at 05:08 (03:08 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-02T08:37:07.502 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:37:07.502 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:37:07.502 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-05-02T08:37:07.502 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:37:07.502 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-02T08:37:07.503 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-05-02T08:37:08.458 RPC Rundown called on ScanID: F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525 2026-05-02T08:37:08.458 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525. bRemoveFromList(ClientKilled):1 2026-05-02T08:37:08.481 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525 2026-05-02T08:37:08.482 QuickScan:ScanID:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525: Scan was stopped 2026-05-02T08:37:08.482 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525 2026-05-02T08:37:08.482 QuickScan:ScanID:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525: Quick scan aborted by callback after end stage 2026-05-02T08:37:08.482 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525 2026-05-02T08:37:08.482 OnDemandScanWorker: Scan Cancelled! scanId:F6BEBFB5-1E28-4E7D-B9DA-2FF8A00B8525, hr = 0x80508018 2026-05-02T08:37:08.484 QuickScan:ScanID:C7B2BF51-DADF-E3EB-DBEA-20A0FC4463AA: Scan was stopped 2026-05-02T08:37:08.484 QuickScan:ScanID:C7B2BF51-DADF-E3EB-DBEA-20A0FC4463AA: Quick scan aborted by callback after end stage 2026-05-02T08:37:08.486 [AutoPurge] Routine task for Cache Maintenance has ended. BEGIN BM telemetry GUID:{8DC3822C-2FB0-61AC-5996-89EB825CABD2} SignatureID:23858905925058 SigSha:bb9deb67e0a930a74a0830b0cf819e8421704cec ThreatLevel:0 ProcessID:584 ProcessCreationTime:134221835957074713 SessionID:0 CreationTime:05-02-2026 08:37:09 ImagePath:C:\Windows\System32\csrss.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-05-02T08:37:09.924 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-02T08:37:09.924 [Cloud] Start of cloud request. Passive mode: 0 2026-05-02T08:37:09.924 [Cloud] Queued cloud request. 2026-05-02T08:37:09.924 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-02T08:37:09.924 [Cloud] Dequeued cloud request. 2026-05-02T08:37:09.925 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-02T08:37:10.258 [Cloud] End of cloud request. 2026-05-02T08:37:10.499 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:37:10.508 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:37:10.510 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:37:10.768 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:37:28.895 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:44D08508-5488-46F2-ADA8-CF2B925757CD, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-02T08:37:28.895 Scheduled scan with Id 44D08508-5488-46F2-ADA8-CF2B925757CD configured CPU priority: normal (LowCpuPriority: 0) 2026-05-02T08:37:28.897 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-02T08:37:28.897 [SFC] System file cache build is not needed (already completed) 2026-05-02T08:37:28.935 [AutoPurge] Cleanup Routine tasks have started. 2026-05-02T08:37:28.945 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-02T08:37:28.951 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-02T08:37:28.952 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-02-2026 08:37:28 2026-05-02T08:37:28.953 [AutoPurge] Verification Routine tasks have started. 2026-05-02T08:37:28.954 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-02-2026 08:37:28 2026-05-02T08:37:28.970 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-02T08:37:28.970 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-02T08:37:28.970 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-02T08:37:28.970 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-02T08:37:28.972 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-02T08:37:29.017 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-02T08:37:29.018 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-02T08:37:29.018 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-02T08:37:29.018 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-02T08:37:29.018 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-02T08:37:29.018 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-02T08:37:29.217 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-02T08:37:29.222 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-02T08:37:29.258 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-02T08:37:29.271 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-02T08:37:29.273 [AutoPurge] Verification Routine tasks have ended. 2026-05-02T08:37:30.911 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:37:30.917 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:37:30.919 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:37:31.419 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9607, FileId: 0x139000000005383, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:37:50.506 Engine:Triggered AR EMS scan 2026-05-02T08:37:50.510 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.527 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.544 Engine:EMS scan for process: svchost pid: 912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.547 Engine:EMS scan for process: svchost pid: 1048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.551 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.558 Engine:EMS scan for process: svchost pid: 1244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.563 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.568 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.570 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.575 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.577 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.578 Engine:EMS scan for process: svchost pid: 1516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.586 Engine:EMS scan for process: svchost pid: 1564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.590 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.592 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.594 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.597 Engine:EMS scan for process: svchost pid: 1968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.603 Engine:EMS scan for process: svchost pid: 1976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.605 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.608 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.611 Engine:EMS scan for process: svchost pid: 2124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.613 Engine:EMS scan for process: svchost pid: 2244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.616 Engine:EMS scan for process: svchost pid: 2260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.619 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.620 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.623 Engine:EMS scan for process: svchost pid: 2476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.624 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.626 Engine:EMS scan for process: svchost pid: 2608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.628 Engine:EMS scan for process: svchost pid: 2712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.631 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.634 Engine:EMS scan for process: svchost pid: 2960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.639 Engine:EMS scan for process: svchost pid: 3052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.642 Engine:EMS scan for process: svchost pid: 2544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.648 Engine:EMS scan for process: svchost pid: 3316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.651 Engine:EMS scan for process: svchost pid: 3324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.653 Engine:EMS scan for process: svchost pid: 3396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.670 Engine:EMS scan for process: svchost pid: 3408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.674 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.679 Engine:EMS scan for process: svchost pid: 3728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.683 Engine:EMS scan for process: svchost pid: 3884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.686 Engine:EMS scan for process: svchost pid: 4004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.690 Engine:EMS scan for process: svchost pid: 4040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.696 Engine:EMS scan for process: svchost pid: 4048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.703 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.707 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.711 Engine:EMS scan for process: svchost pid: 4260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.713 Engine:EMS scan for process: svchost pid: 4348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.717 Engine:EMS scan for process: svchost pid: 4476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.720 Engine:EMS scan for process: svchost pid: 4932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.726 Engine:EMS scan for process: svchost pid: 5064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.732 Engine:EMS scan for process: svchost pid: 5164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.738 Engine:EMS scan for process: svchost pid: 5376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.741 Engine:EMS scan for process: dllhost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.744 Engine:EMS scan for process: svchost pid: 6124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.746 Engine:EMS scan for process: svchost pid: 6236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.748 Engine:EMS scan for process: svchost pid: 6812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.753 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.761 Engine:EMS scan for process: svchost pid: 7032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.765 Engine:EMS scan for process: svchost pid: 7120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.772 Engine:EMS scan for process: svchost pid: 7116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.775 Engine:EMS scan for process: svchost pid: 4620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.778 Engine:EMS scan for process: svchost pid: 6636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.781 Engine:EMS scan for process: svchost pid: 6660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.782 Engine:EMS scan for process: explorer pid: 7364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.824 Engine:EMS scan for process: svchost pid: 7456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.828 Engine:EMS scan for process: svchost pid: 7616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.835 Engine:EMS scan for process: svchost pid: 8024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.839 Engine:EMS scan for process: svchost pid: 8300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.843 Engine:EMS scan for process: svchost pid: 9508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.848 Engine:EMS scan for process: dllhost pid: 10800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.852 Engine:EMS scan for process: svchost pid: 10824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.855 Engine:EMS scan for process: svchost pid: 8560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.859 Engine:EMS scan for process: svchost pid: 14116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.864 Engine:EMS scan for process: svchost pid: 5176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.868 Engine:EMS scan for process: svchost pid: 9040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.871 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.873 Engine:EMS scan for process: svchost pid: 9368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.879 Engine:EMS scan for process: svchost pid: 11284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.881 Engine:EMS scan for process: svchost pid: 1036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.883 Engine:EMS scan for process: svchost pid: 9068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.886 Engine:EMS scan for process: svchost pid: 15200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.888 Engine:EMS scan for process: svchost pid: 7984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.891 Engine:EMS scan for process: svchost pid: 12404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.893 Engine:EMS scan for process: svchost pid: 5548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:37:50.897 Engine:EMS scan for process: dllhost pid: 888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:38:08.219 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-02T08:38:08.257 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-02T08:38:08.258 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-02T08:38:08.258 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-02T08:38:08.259 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-02T08:38:08.259 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-02T08:38:08.260 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-02T08:38:08.260 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-02T08:38:08.260 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-02T08:38:08.260 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-02T08:38:08.260 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:38:08.260 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:38:08.260 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-02T08:38:08.260 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-02T08:38:08.260 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-02T08:38:08.296 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:38:08.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:38:08.303 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:38:08.306 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:38:08.317 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:38:08.401 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 57378604(ms) from now at 02:34 (00:34 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-02T08:38:10.734 RPC Rundown called on ScanID: 44D08508-5488-46F2-ADA8-CF2B925757CD 2026-05-02T08:38:10.734 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:44D08508-5488-46F2-ADA8-CF2B925757CD. bRemoveFromList(ClientKilled):1 2026-05-02T08:38:10.734 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:44D08508-5488-46F2-ADA8-CF2B925757CD 2026-05-02T08:38:10.734 QuickScan:ScanID:44D08508-5488-46F2-ADA8-CF2B925757CD: Scan was stopped 2026-05-02T08:38:10.736 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:44D08508-5488-46F2-ADA8-CF2B925757CD 2026-05-02T08:38:10.736 QuickScan:ScanID:44D08508-5488-46F2-ADA8-CF2B925757CD: Quick scan aborted by callback after end stage 2026-05-02T08:38:10.736 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:44D08508-5488-46F2-ADA8-CF2B925757CD 2026-05-02T08:38:10.737 OnDemandScanWorker: Scan Cancelled! scanId:44D08508-5488-46F2-ADA8-CF2B925757CD, hr = 0x80508018 2026-05-02T08:38:10.807 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:38:10.807 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:38:10.807 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-05-02T08:38:10.808 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:38:10.808 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-02T08:38:10.809 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-05-02T08:38:12.792 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:38:12.802 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:38:12.804 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:40:27.384 [AutoPurge] Verification Routine tasks have started. 2026-05-02T08:40:27.384 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-02T08:40:27.411 [AutoPurge] Cleanup Routine tasks have started. 2026-05-02T08:40:27.419 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-02T08:40:27.419 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-02T08:40:27.419 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-02T08:40:27.419 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-02T08:40:27.419 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-02T08:40:27.419 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-02T08:40:27.425 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-02T08:40:27.428 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-02T08:40:27.429 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-02-2026 08:40:27 2026-05-02T08:40:27.430 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:91637866-E232-4699-8939-82A30C8B7BDA, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-02T08:40:27.430 Scheduled scan with Id 91637866-E232-4699-8939-82A30C8B7BDA configured CPU priority: normal (LowCpuPriority: 0) 2026-05-02T08:40:27.432 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-02T08:40:27.432 [SFC] System file cache build is not needed (already completed) Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-02-2026 08:40:27 2026-05-02T08:40:27.442 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-02T08:40:27.442 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-02T08:40:27.442 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-02T08:40:27.442 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-02T08:40:27.443 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-02T08:40:27.655 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-02T08:40:27.660 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-02T08:40:27.688 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-02T08:40:27.703 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-02T08:40:27.705 [AutoPurge] Verification Routine tasks have ended. 2026-05-02T08:40:29.130 [RTP] [Mini-filter] OpenWithoutRead notification (840, 10002, \Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. 2026-05-02T08:40:29.453 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:40:29.459 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:40:29.461 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:40:30.261 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10512, FileId: 0x980000000060d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:40:31.278 Engine:Triggered AR EMS scan 2026-05-02T08:40:31.282 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.299 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.314 Engine:EMS scan for process: svchost pid: 912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.317 Engine:EMS scan for process: svchost pid: 1048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.321 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.329 Engine:EMS scan for process: svchost pid: 1244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.330 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.334 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.337 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.342 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.344 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.345 Engine:EMS scan for process: svchost pid: 1516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.348 Engine:EMS scan for process: svchost pid: 1564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.354 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.357 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.359 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.362 Engine:EMS scan for process: svchost pid: 1968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.364 Engine:EMS scan for process: svchost pid: 1976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.366 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.369 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.372 Engine:EMS scan for process: svchost pid: 2124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.374 Engine:EMS scan for process: svchost pid: 2244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.376 Engine:EMS scan for process: svchost pid: 2260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.378 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.380 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.382 Engine:EMS scan for process: svchost pid: 2476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.384 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.386 Engine:EMS scan for process: svchost pid: 2608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.388 Engine:EMS scan for process: svchost pid: 2712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.391 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.393 Engine:EMS scan for process: svchost pid: 2960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.396 Engine:EMS scan for process: svchost pid: 3052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.400 Engine:EMS scan for process: svchost pid: 2544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.406 Engine:EMS scan for process: svchost pid: 3316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.409 Engine:EMS scan for process: svchost pid: 3324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.410 Engine:EMS scan for process: svchost pid: 3396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.426 Engine:EMS scan for process: svchost pid: 3408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.431 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.437 Engine:EMS scan for process: svchost pid: 3728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.440 Engine:EMS scan for process: svchost pid: 3884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.444 Engine:EMS scan for process: svchost pid: 4004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.448 Engine:EMS scan for process: svchost pid: 4040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.454 Engine:EMS scan for process: svchost pid: 4048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.460 Engine:EMS scan for process: svchost pid: 4196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.464 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.467 Engine:EMS scan for process: svchost pid: 4260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.468 Engine:EMS scan for process: svchost pid: 4348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.473 Engine:EMS scan for process: svchost pid: 4476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.475 Engine:EMS scan for process: svchost pid: 4932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.478 Engine:EMS scan for process: svchost pid: 5064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.481 Engine:EMS scan for process: svchost pid: 5164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.483 Engine:EMS scan for process: svchost pid: 5376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.485 Engine:EMS scan for process: dllhost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.488 Engine:EMS scan for process: svchost pid: 6124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.490 Engine:EMS scan for process: svchost pid: 6236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.492 Engine:EMS scan for process: svchost pid: 6812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.497 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.504 Engine:EMS scan for process: svchost pid: 7032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.508 Engine:EMS scan for process: svchost pid: 7120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.510 Engine:EMS scan for process: svchost pid: 7116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.513 Engine:EMS scan for process: svchost pid: 4620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.516 Engine:EMS scan for process: svchost pid: 6636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.518 Engine:EMS scan for process: svchost pid: 6660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.520 Engine:EMS scan for process: explorer pid: 7364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.564 Engine:EMS scan for process: svchost pid: 7456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.567 Engine:EMS scan for process: svchost pid: 7616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.569 Engine:EMS scan for process: svchost pid: 8024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.573 Engine:EMS scan for process: svchost pid: 8300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.578 Engine:EMS scan for process: svchost pid: 9508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.579 Engine:EMS scan for process: dllhost pid: 10800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.582 Engine:EMS scan for process: svchost pid: 10824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.584 Engine:EMS scan for process: svchost pid: 8560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.589 Engine:EMS scan for process: svchost pid: 14116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.594 Engine:EMS scan for process: svchost pid: 5176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.602 Engine:EMS scan for process: svchost pid: 9040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.608 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.610 Engine:EMS scan for process: svchost pid: 9368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.615 Engine:EMS scan for process: svchost pid: 11284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.617 Engine:EMS scan for process: svchost pid: 1036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.620 Engine:EMS scan for process: svchost pid: 9068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.622 Engine:EMS scan for process: svchost pid: 7984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:31.624 Engine:EMS scan for process: dllhost pid: 15344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-02T08:40:32.472 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T08:40:50.396 ExpensiveFile:Scan time for `\\?\C:\Program Files\Microsoft Office\root\Office16\livecapture.bundle` is 8421 units 2026-05-02T08:42:22.313 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10653, FileId: 0xe50000000029f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:42:22.345 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10655, FileId: 0xe0000000007f3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:43:58.217 QuickScan:ScanID:91637866-E232-4699-8939-82A30C8B7BDA: Quick scan finished with error 0 2026-05-02T08:43:58.733 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-02T08:43:58.748 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-02T08:43:58.748 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:43:58.748 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:43:58.748 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:43:58.748 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-02T08:43:58.748 [RTP] No config change detected. Not updating plugin configuration. 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-02T08:43:58.748 [RTP] No config changes found. No configuration switch. 2026-05-02T08:43:58.748 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-02T08:43:58.748 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:43:58.748 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:43:58.748 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-02T08:43:58.748 [RTP] No config change detected. Not updating plugin configuration. 2026-05-02T08:43:58.748 [RTP] No config changes found. No configuration switch. 2026-05-02T08:43:58.748 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-02T08:43:58.748 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-02T08:43:58.748 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:43:58.748 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-02T08:43:58.748 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-02T08:43:58.748 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-02T08:43:58.748 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-02T08:43:58.748 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-02T08:43:58.748 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-02T08:43:58.748 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:43:58.764 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:43:58.764 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-02T08:43:58.811 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 56132590(ms) from now at 02:19 (00:19 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-02T08:44:00.222 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:44:00.222 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-02T08:44:00.222 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-02T08:44:01.316 [RTP] Duplicating the current plugin configuration object... 2026-05-02T08:44:01.316 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T08:44:01.316 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-02T08:44:01.316 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-02T08:44:01.316 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-02T08:45:02.858 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #10883, FileId: 0xe2000000007f3d, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T08:55:37.470 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T09:10:42.483 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T09:20:27.481 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-05-02T09:24:23.225 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:24:23.498 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:24:23.664 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:24:24.258 Engine:Process 688 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-02T09:24:39.833 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14811, FileId: 0x5000000001177a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T09:25:47.479 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T09:36:05.894 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:36:05.909 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:36:06.113 Bm signature throttled:0x00002db31bed458f 2026-05-02T09:36:21.329 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15338, FileId: 0x149000000005383, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T09:40:52.475 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T09:52:44.858 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16375, FileId: 0x9c00000001196c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T09:55:57.476 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T09:59:32.810 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16989, FileId: 0x5600000001197d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T10:00:47.467 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17126, FileId: 0x5700000001197d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-02T10:11:02.482 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T10:21:38.572 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-02T10:21:38.572 [RTP] 8 newly mounted volumes accumulated, forcing a config update ... 2026-05-02T10:21:38.572 [RTP] Duplicating the current plugin configuration object... 2026-05-02T10:21:38.572 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-02T10:21:38.572 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-02T10:21:38.572 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-02T10:21:38.572 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-02T10:25:59.373 Bm signature throttled:0x00002db31bed458f 2026-05-02T10:26:07.472 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-02T10:30:49.665 ProcessImageName: explorer.exe, Pid: 7364, TotalTime: 8278, Count: 229, MaxTime: 1421, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: AcroCEF.exe, Pid: 7148, TotalTime: 3742, Count: 174, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-02T10:30:49.665 ProcessImageName: setup.exe, Pid: 6048, TotalTime: 2541, Count: 354, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\new_msedge.exe, EstimatedImpact: 29% 2026-05-02T10:30:49.665 ProcessImageName: svchost.exe, Pid: 15200, TotalTime: 2249, Count: 3, MaxTime: 765, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-05-02T10:30:49.665 ProcessImageName: WmiPrvSE.exe, Pid: 15264, TotalTime: 785, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\refs.sys, EstimatedImpact: 90% 2026-05-02T10:30:49.665 ProcessImageName: WmiPrvSE.exe, Pid: 11544, TotalTime: 602, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 91% 2026-05-02T10:30:49.665 ProcessImageName: atieclxx.exe, Pid: 2364, TotalTime: 214, Count: 7, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: backgroundTaskHost.exe, Pid: 6208, TotalTime: 210, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-05-02T10:30:49.665 ProcessImageName: AdobeCollabSync.exe, Pid: 6920, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-02.log, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: TabTip.exe, Pid: 10680, TotalTime: 202, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 63% 2026-05-02T10:30:49.665 ProcessImageName: svchost.exe, Pid: 976, TotalTime: 200, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26093.307.4625.9664_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: TabTip.exe, Pid: 3164, TotalTime: 186, Count: 5, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-02T10:30:49.665 ProcessImageName: TabTip.exe, Pid: 6828, TotalTime: 186, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-02T10:30:49.665 ProcessImageName: ngentask.exe, Pid: 12060, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 4% 2026-05-02T10:30:49.665 ProcessImageName: PhoneExperienceHost.exe, Pid: 12124, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: ngentask.exe, Pid: 12028, TotalTime: 135, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-02T10:30:49.665 ProcessImageName: Acrobat.exe, Pid: 3152, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 19% 2026-05-02T10:30:49.665 ProcessImageName: svchost.exe, Pid: 2460, TotalTime: 108, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 78% 2026-05-02T10:30:49.665 ProcessImageName: svchost.exe, Pid: 912, TotalTime: 108, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: MicrosoftEdge_X64_147.0.3912.98_147.0.3912.86.exe, Pid: 11312, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{F302BE78-5A82-4EA6-BC69-5A84579700E0}\EDGEMITMP_709F9.tmp\setup.exe, EstimatedImpact: 66% 2026-05-02T10:30:49.665 ProcessImageName: SDXHelper.exe, Pid: 4396, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 3% 2026-05-02T10:30:49.665 ProcessImageName: SDXHelper.exe, Pid: 1340, TotalTime: 90, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: svchost.exe, Pid: 1408, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: ngentask.exe, Pid: 6560, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 12% 2026-05-02T10:30:49.665 ProcessImageName: ngentask.exe, Pid: 13340, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 15% 2026-05-02T10:30:49.665 ProcessImageName: SDXHelper.exe, Pid: 6896, TotalTime: 76, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\20EF30F2-C5CC-41AB-9CB9-D052F7403BAD, EstimatedImpact: 9% 2026-05-02T10:30:49.665 ProcessImageName: OfficeC2RClient.exe, Pid: 12996, TotalTime: 76, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 3% 2026-05-02T10:30:49.665 ProcessImageName: OfficeC2RClient.exe, Pid: 2080, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 1% 2026-05-02T10:30:49.665 ProcessImageName: OfficeC2RClient.exe, Pid: 10756, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8A64019-FB70-4431-BBB8-1BDA15DBB5B0, EstimatedImpact: 2% 2026-05-02T10:30:49.665 ProcessImageName: taskhostw.exe, Pid: 7856, TotalTime: 61, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 1% 2026-05-02T10:30:49.665 ProcessImageName: OfficeC2RClient.exe, Pid: 14824, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 1% 2026-05-02T10:30:49.665 ProcessImageName: AcroCEF.exe, Pid: 8044, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: dllhost.exe, Pid: 5888, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: OfficeC2RClient.exe, Pid: 6600, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260502-1037.log, EstimatedImpact: 2% 2026-05-02T10:30:49.665 ProcessImageName: AdobeARM.exe, Pid: 6248, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000155.db, EstimatedImpact: 10% 2026-05-02T10:30:49.665 ProcessImageName: TeamViewer.exe, Pid: 7748, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: dasHost.exe, Pid: 5276, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-02T10:30:49.665 ProcessImageName: SDXHelper.exe, Pid: 12000, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 8% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-03-2026 08:19:02 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/03/2026 08:19:02.928363000 UTC (20640 ms since boot) 2026-05-03T08:19:02.930 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-03T08:19:02.930 WARNING: the previous service shutdown was not expected. 2026-05-03T08:19:02.945 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-03T08:19:02.945 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-03T08:19:03.023 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260503-081903-00000003-fffffffeffffffff.bin ... 2026-05-03T08:19:03.211 [WPP] Trace session started - MpWppTracing-20260503-081903-00000003-fffffffeffffffff.bin 2026-05-03T08:19:03.211 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-03T08:19:03.211 [RbM] Rollback manager succesfully initialized. 2026-05-03T08:19:03.211 [RbM] Rollback manager EnableRollbackManager called. 2026-05-03T08:19:03.211 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-03T08:19:03.211 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-03T08:19:03.211 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-03T08:19:03.211 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-03T08:19:03.211 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-03T08:19:03.227 MdCoreSvc is supported in this platform and OS 2026-05-03T08:19:03.227 MdCoreSvc is supported in this platform and OS 2026-05-03T08:19:03.227 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-03T08:19:03.227 [PlatUpd] Starting MdCoreSvc service 2026-05-03T08:19:03.273 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-03T08:19:07.008 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-03T08:19:07.008 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-03T08:19:07.008 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-03T08:19:07.008 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-03T08:19:07.008 [PlatUpd] CSP platform update started 2026-05-03T08:19:07.008 [PlatUpd] Defender MDM CSP platform update not required 2026-05-03T08:19:07.008 [PlatUpd] WMI/PS provider platform update started 2026-05-03T08:19:07.008 [PlatUpd] WMI/PS provider platform update not required 2026-05-03T08:19:07.008 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-03T08:19:07.008 MdCoreSvc is supported in this platform and OS 2026-05-03T08:19:07.008 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-03T08:19:07.008 [PlatUpd] Starting MdCoreSvc service 2026-05-03T08:19:07.008 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-03T08:19:07.008 [TS] Troublshooting mode is not available! 2026-05-03T08:19:07.008 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-03T08:19:07.008 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-03T08:19:07.023 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-03T08:19:07.023 [Service] Enabling AutoLoggers ... 2026-05-03T08:19:07.023 [Service] Enabling AMSI registration ... 2026-05-03T08:19:07.023 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-03T08:19:07.055 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 45619 Number of invalid entries is 0 Number of inserts issued is 1578497 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6475 Number of lookups is 107703218 Number of lookup misses is 5172065 Number of fast lookup misses is 54875784 Number of false fast lookups is 5172060 Number of invalidations is 731651 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-03T08:19:07.055 Verifying license file... 2026-05-03T08:19:07.055 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll]. File not in cache (0x1) 2026-05-03T08:19:07.086 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] 2026-05-03T08:19:07.102 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-03T08:19:07.102 Loaded module#0 MpComServer. 2026-05-03T08:19:07.102 Loaded module#1 StartupPolicies. 2026-05-03T08:19:07.102 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-03T08:19:07.102 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-03T08:19:07.102 COM server initialized successfully. 2026-05-03T08:19:07.117 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-03T08:19:07.133 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-03T08:19:07.133 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-03T08:19:07.148 [RTP] [RTP] FilterCommunicator object 0x0000017C2BF0ADE0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-03T08:19:07.148 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-03T08:19:07.148 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-03T08:19:07.148 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-03T08:19:07.148 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-03T08:19:07.148 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-03T08:19:07.148 [RTP] [RTP] FilterCommunicator object 0x0000017C2BF0AFF0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-03T08:19:07.148 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-03T08:19:07.148 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-03T08:19:07.148 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-03T08:19:07.148 [RTP] [RTP] StartCommunication 0x0000017C2BF0ADE0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-03T08:19:07.148 [init][RTP] RTPPlugin initialization completed 2026-05-03T08:19:07.148 OS boot count = 2 2026-05-03T08:19:07.148 OS Install = 0 2026-05-03T08:19:07.180 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-03T08:19:07.180 [KSL] Entering CKSLEngine::Initialize. 2026-05-03T08:19:07.180 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-03T08:19:07.180 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-03T08:19:07.180 [KSL] MpInstallKslD: hr=0x1 2026-05-03T08:19:07.180 [KSL] MpRegisterKslD: hr=0 2026-05-03T08:19:07.195 [KSL] MpStartKslD: hr=0 2026-05-03T08:19:07.195 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-03T08:19:07.195 Loading engine... 2026-05-03T08:19:07.211 Verifying engine and signature files (source: 1) ... 2026-05-03T08:19:07.211 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpengine.dll] due to PPL. 2026-05-03T08:19:07.211 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasbase.vdm]. File not in cache (0x1) 2026-05-03T08:19:08.195 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasbase.vdm] 2026-05-03T08:19:08.195 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-03T08:19:08.211 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasdlta.vdm] 2026-05-03T08:19:08.211 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavbase.vdm]. File not in cache (0x1) 2026-05-03T08:19:08.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavbase.vdm] 2026-05-03T08:19:08.648 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-03T08:19:08.680 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpavdlta.vdm] 2026-05-03T08:19:08.711 [Engine] IsHybridMode: 0 2026-05-03T08:19:08.711 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-03T08:19:08.742 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-6666196AACEA04299295A2FC3A7FA6F768C186B2.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-03T08:19:15.539 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-03T08:19:15.539 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-03T08:19:15.539 [Engine] New active engine 00007FFFBD858020 (no old engine). Number of active engines: 1 2026-05-03T08:19:15.555 EngineInit:Global ASOC is enabled 2026-05-03T08:19:15.555 EngineInit:ASOO is enabled for developer volumes 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:15.633 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6276089dd379902c7668bb54fbdc1240b279139f Dynamic Signature Compilation Timestamp:04-02-2026 18:32:11 Persistence Type:Duration Time remaining:150196224 2026-05-03T08:19:15.648 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\50e0acde53ab1e62a0cbee42e99238b0cb983409 Dynamic Signature Compilation Timestamp:04-02-2026 18:32:13 Persistence Type:Duration Time remaining:150196224 2026-05-03T08:19:15.648 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b62230090a2d3d14d9c853a8230482a7c6e9d45b Dynamic Signature Compilation Timestamp:04-02-2026 18:41:26 Persistence Type:Duration Time remaining:150196224 2026-05-03T08:19:15.648 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ba77fe0f94089f8996bc52aa546c478ab061e88 Dynamic Signature Compilation Timestamp:04-02-2026 18:41:31 Persistence Type:Duration Time remaining:150196224 2026-05-03T08:19:15.648 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\837928c47aefabd6c7e8cd57d62504ed7c99616e Dynamic Signature Compilation Timestamp:04-30-2026 09:20:17 Persistence Type:Duration Time remaining:1728000000 2026-05-03T08:19:15.695 MpWriteUupSignatureVersion 1.449.398.0, hr = 0 2026-05-03T08:19:15.695 [SigStatUpd] CSignatureStatus: back to good 2026-05-03T08:19:15.695 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-03T08:19:15.727 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-03T08:19:15.727 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-03T08:19:15.727 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-03T08:19:15.727 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-03T08:19:15.727 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-03T08:19:15.742 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-03T08:19:15.742 [Plugin] Initializing RTP plugin state... 2026-05-03T08:19:15.742 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2448 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14119 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2721 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-03T08:19:15.742 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-03T08:19:15.742 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11} 2026-05-03T08:19:15.742 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:15.742 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:15.742 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:15.742 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:15.742 MdCoreSvc is supported in this platform and OS 2026-05-03T08:19:15.742 Engine loaded! 2026-05-03T08:19:15.742 [DLP] Create FeatureControlState instance 2026-05-03T08:19:15.742 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-03T08:19:15.742 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-03T08:19:15.758 RegisterSModeChangeListener: hr = 0x1 2026-05-03T08:19:15.758 RegisterHybridModeChangeListener: hr = 0 2026-05-03T08:19:15.758 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-03T08:19:15.758 [SigReleaseHb] Initialized with Stage 0 2026-05-03T08:19:15.758 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-03T08:19:15.773 [SCC][CID=33500_5636] Initializing ... 2026-05-03T08:19:15.773 [SCC][CID=33500_5636] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-03T08:19:15.773 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-03T08:19:15.773 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-03T08:19:15.773 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-03T08:19:15.773 [NRI] Stopping NIS service ... 2026-05-03T08:19:15.773 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-03T08:19:15.773 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.398.0 AV Signature Version: 1.449.398.0 ************************************************************ 2026-05-03T08:19:15.773 Resource usage Monitoring is enabled 2026-05-03T08:19:15.773 Job Notification: New process added to job (4680) 2026-05-03T08:19:15.773 Job Notification: New process added to job (7556) 2026-05-03T08:19:15.773 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-03T08:19:15.789 Job Notification: New process added to job (7572) 2026-05-03T08:19:15.789 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7556] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7572]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-03T08:19:15.852 Job Notification: Process exited from job (7556) 2026-05-03T08:19:15.867 Job Notification: Process exited from job (7572) 2026-05-03T08:19:15.867 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-03T08:19:15.867 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-03T08:19:15.867 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-03T08:19:15.883 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-03T08:19:15.883 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-03T08:19:15.883 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-03T08:19:15.883 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-03T08:19:15.883 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-03T08:19:15.883 [RTP] Generating the base plugin configuration ... 2026-05-03T08:19:15.883 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-03T08:19:15.883 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:19:15.883 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-03T08:19:15.883 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-03T08:19:15.883 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:19:15.883 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-03T08:19:15.883 [RTP] [RTP] StartCommunication 0x0000017C2BF0AFF0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-03T08:19:15.883 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-03T08:19:15.883 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-03T08:19:16.211 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-03T08:19:16.211 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-03T08:19:16.211 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-03T08:19:16.398 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:19:18.977 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:19:18.977 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:19:18.977 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-03T08:19:18.977 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-03T08:19:18.977 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-03T08:19:28.789 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\4F23A6EF-D757-4546-84F8-4B1F4A5680DA1fa8.1dcdad58e86ba39 2026-05-03T08:19:28.898 Verifying engine and signature files (source: 0) ... 2026-05-03T08:19:28.898 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpengine.dll] due to PPL. 2026-05-03T08:19:28.898 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpasbase.vdm] (file in cache) 2026-05-03T08:19:28.898 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-03T08:19:28.914 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpasdlta.vdm] 2026-05-03T08:19:28.914 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpavbase.vdm] (file in cache) 2026-05-03T08:19:28.914 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-03T08:19:28.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpavdlta.vdm] 2026-05-03T08:19:29.086 [Engine] IsHybridMode: 0 2026-05-03T08:19:29.086 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-03T08:19:29.086 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EEF90A1957CFB10938C2D2F5C6EAF2775E945F8A.bin): 0x00000002 2026-05-03T08:19:29.102 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EEF90A1957CFB10938C2D2F5C6EAF2775E945F8A.bin) 2026-05-03T08:19:29.102 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-03T08:19:29.102 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-03T08:19:29.102 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-03T08:19:29.102 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-03T08:19:40.977 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-03T08:19:40.977 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-03T08:19:40.977 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFFBD858020, lRefCount: 5, hr=0 2026-05-03T08:19:40.977 [Engine] New active engine 00007FFFB97C8020 replacing engine 00007FFFBD858020. Number of active engines: 2 2026-05-03T08:19:40.992 EngineInit:Global ASOC is enabled 2026-05-03T08:19:40.992 EngineInit:ASOO is enabled for developer volumes 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.055 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T08:19:41.070 MpWriteUupSignatureVersion 1.449.422.0, hr = 0 2026-05-03T08:19:41.070 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-03T08:19:41.086 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-03T08:19:41.102 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-03T08:19:41.102 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-03T08:19:41.102 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-03T08:19:41.102 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-03T08:19:41.102 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-03T08:19:41.102 [Plugin] Initializing RTP plugin state... 2026-05-03T08:19:41.102 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-03T08:19:41.102 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎03‎-‎2026 10:19:15 Last Perf:‎05‎-‎03‎-‎2026 10:19:15 First RTP Scan:‎05‎-‎03‎-‎2026 10:19:15 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:298 Misses:529 BM Queue:0,9,0 Proc:0,9,0 File:0,4,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:849 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:661914 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2647 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:15108 TotalHits:833 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2948 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (15/6) Success: 6, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-03T08:19:41.117 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9} 2026-05-03T08:19:41.117 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11}\mpasbase.vdm in use, hr=0x80070020 2026-05-03T08:19:41.117 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-03T08:19:41.117 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{887E6C3C-C224-4EA5-BA3A-A48D68DF9B88} removed 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-03-2026 08:19:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-03-2026 08:19:41 2026-05-03T08:19:41.117 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-03T08:19:41.117 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-03T08:19:41.117 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-03T08:19:41.117 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:19:41.117 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-03T08:19:41.117 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-03T08:19:41.117 MdCoreSvc is supported in this platform and OS Signature updated on 05-03-2026 08:19:41 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.422.0 AV Signature Version: 1.449.422.0 ************************************************************ 2026-05-03T08:19:41.133 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-03T08:19:41.133 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\4F23A6EF-D757-4546-84F8-4B1F4A5680DA1fa8.1dcdad58e86ba39 2026-05-03T08:19:41.211 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-03T08:19:41.211 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-03T08:19:41.477 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-03T08:19:41.477 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-03T08:19:41.477 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-03T08:19:41.477 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-03T08:19:41.477 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-03T08:19:41.477 [Engine] Engine 00007FFFBD858020 no longer in use. Number of active engines: 1 2026-05-03T08:19:41.477 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:19:41.477 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-03T08:19:41.555 ProcessImageName: svchost.exe, Pid: 3780, TotalTime: 951, Count: 5, MaxTime: 593, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 11% 2026-05-03T08:19:41.555 ProcessImageName: WmiPrvSE.exe, Pid: 3924, TotalTime: 465, Count: 59, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 22% 2026-05-03T08:19:41.555 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T08:19:41.570 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-03T08:19:41.570 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-03T08:19:41.570 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-03T08:19:41.586 [Engine] RSIG_UNLOADENGINE, 00007FFFBD858020, err=0x0 2026-05-03T08:19:41.602 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317C9179-618C-4AB2-AAA9-7067C2F27D11} removed 2026-05-03T08:20:07.086 Process scan (postsignatureupdatescan) started. 2026-05-03T08:20:07.602 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-03T08:20:07.602 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-03T08:20:10.180 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:20:10.180 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:20:10.180 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-03T08:20:10.180 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-03T08:20:10.180 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-03T08:20:22.727 Process scan (postsignatureupdatescan) completed. 2026-05-03T08:21:06.195 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:21:06.195 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-03T08:21:06.195 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:24:15.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T08:24:41.023 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-03T08:29:01.555 [AutoPurge] Verification Routine tasks have started. 2026-05-03T08:29:01.555 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-05-03T08:29:01.555 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-03T08:29:01.555 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-03T08:29:01.555 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-03T08:29:01.555 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-03T08:29:01.555 [AutoPurge] MpSignalMaintenanceMode ...ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-03T08:29:01.665 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-05-03T08:29:01.915 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-05-03T08:29:02.118 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-03T08:29:02.134 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-03T08:29:02.180 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-05-03T08:29:02.259 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-03T08:29:02.305 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-03T08:29:02.305 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:02.993 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:DC1CD4C2-B65B-40DC-A105-1F1D15B21902, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-03T08:29:02.993 Scheduled scan with Id DC1CD4C2-B65B-40DC-A105-1F1D15B21902 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-03T08:29:02.993 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-03T08:29:02.993 [SFC] System file cache build is not needed (already completed) 2026-05-03T08:29:03.040 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-03T08:29:03.102 [AutoPurge] Cleanup Routine tasks have started. 2026-05-03T08:29:03.128 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-03T08:29:03.134 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-03T08:29:03.134 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-03-2026 08:29:03 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-03-2026 08:29:03 2026-05-03T08:29:03.134 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-03T08:29:03.134 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-03T08:29:03.134 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-03T08:29:03.134 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-03T08:29:03.149 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-03T08:29:03.212 Job Notification: New process added to job (8) 2026-05-03T08:29:03.212 Task(GetDeviceTicket -AccessKey F2DC0326-313E-6ECE-CC10-C16ABBA3BED6 ) launched as network service 2026-05-03T08:29:03.244 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #2473, FileId: 0x5100000000f701, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T08:29:03.588 Job Notification: Process exited from job (8) 2026-05-03T08:29:03.603 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-03T08:29:03.634 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-05-03T08:29:03.650 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-03T08:29:03.650 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:29:03.650 [Cloud] Queued cloud request. 2026-05-03T08:29:03.650 [Cloud] Dequeued cloud request. 2026-05-03T08:29:03.650 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:29:03.744 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-03T08:29:03.759 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-03T08:29:03.931 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-03T08:29:03.931 [AutoPurge] Verification Routine tasks have ended. 2026-05-03T08:29:04.166 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-03T08:29:04.166 [Cloud] End of cloud request. 2026-05-03T08:29:04.181 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-03T08:29:04.213 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-03T08:29:04.213 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-03T08:29:04.213 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-03T08:29:04.213 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:29:04.213 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-03T08:29:04.213 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-03T08:29:04.213 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-03T08:29:04.213 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-03T08:29:04.213 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:29:04.213 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:29:04.228 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:29:04.228 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-03T08:29:04.306 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-03T08:29:04.447 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-03T08:29:04.463 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-03T08:29:04.650 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-03T08:29:04.681 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-03T08:29:04.744 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-03T08:29:04.931 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:04.994 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:29:05.009 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-03T08:29:05.009 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:29:05.119 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-03T08:29:05.275 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-03T08:29:05.447 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-03T08:29:05.447 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:05.478 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-03T08:29:05.572 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-03T08:29:05.634 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-03T08:29:05.994 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-03T08:29:06.228 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-03T08:29:06.275 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:06.588 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-03T08:29:06.728 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-03T08:29:06.791 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:29:06.791 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:29:06.791 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-05-03T08:29:06.791 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:29:06.791 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-03T08:29:06.791 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-05-03T08:29:07.197 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:07.213 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-03T08:29:07.275 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:07.478 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-03T08:29:07.572 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-03T08:29:07.713 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-03T08:29:07.900 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-03T08:29:07.963 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-03T08:29:07.978 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-03T08:29:08.009 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-03T08:29:08.181 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-03T08:29:08.259 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-03T08:29:08.384 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-03T08:29:08.478 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-03T08:29:08.931 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-03T08:29:08.947 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-03T08:29:09.181 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-03T08:29:09.228 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-03T08:29:09.744 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-03T08:29:09.775 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-03T08:29:09.791 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:09.791 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-03T08:29:09.853 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-03T08:29:09.900 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-03T08:29:09.994 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-03T08:29:10.259 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\winsxs\amd64_networking-mpssvc-ui_31bf3856ad364e35_10.0.22000.653_none_73afee5687447108\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-03T08:29:10.369 Engine:Setting original file name "AcroSpeedLaunch.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrobat_sl.exe", hr=0x800710da 2026-05-03T08:29:10.431 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-03T08:29:10.447 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:10.463 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-03T08:29:10.509 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-03T08:29:10.603 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-03T08:29:10.650 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-03T08:29:10.666 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-03T08:29:10.681 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-03T08:29:10.884 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-05-03T08:29:11.041 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-03T08:29:11.041 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-03T08:29:11.244 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-03T08:29:11.291 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-03T08:29:11.603 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-03T08:29:11.728 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:11.775 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-03T08:29:11.978 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-03T08:29:11.994 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-03T08:29:12.306 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-03T08:29:12.369 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-03T08:29:12.384 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-03T08:29:12.494 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-03T08:29:12.494 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-03T08:29:12.525 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-03T08:29:12.931 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-03T08:29:13.275 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-03T08:29:13.369 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-03T08:29:13.400 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-03T08:29:13.541 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-03T08:29:13.650 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-03T08:29:13.713 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-03T08:29:13.744 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-03T08:29:13.869 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-03T08:29:14.119 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:14.400 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-03T08:29:14.447 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-03T08:29:14.447 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:14.509 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:15.181 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:15.259 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:15.556 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-03T08:29:15.603 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-03T08:29:15.759 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-03T08:29:15.759 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-03T08:29:15.775 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-03T08:29:15.775 Job Notification: New process added to job (2920) 2026-05-03T08:29:15.822 Job Notification: New process added to job (7368) 2026-05-03T08:29:15.838 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:2920] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7368]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-03T08:29:15.838 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-03T08:29:15.853 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 59783484(ms) from now at 03:05 (01:05 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-03T08:29:15.869 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-03T08:29:15.884 Aggressive catchup quick scan threshold: 857284194723 / 25920000000000 2026-05-03T08:29:15.916 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:15.916 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-03T08:29:15.947 Job Notification: New process added to job (3256) 2026-05-03T08:29:15.947 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-03T08:29:15.947 Job Notification: New process added to job (7388) 2026-05-03T08:29:15.963 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:3256] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7388]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-03T08:29:16.291 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-03T08:29:16.353 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-03T08:29:16.353 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:29:16.353 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:29:16.353 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-03T08:29:16.353 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:29:16.353 [RTP] No config change detected. Not updating plugin configuration. 2026-05-03T08:29:16.353 [RTP] No config changes found. No configuration switch. 2026-05-03T08:29:16.353 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-03T08:29:16.369 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-03T08:29:16.447 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-03T08:29:16.525 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-03T08:29:16.556 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-03T08:29:16.634 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-03T08:29:16.759 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-03T08:29:16.853 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-03T08:29:16.931 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-03T08:29:16.947 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-03T08:29:16.963 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-03T08:29:17.181 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-03T08:29:17.181 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-03T08:29:17.338 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-03T08:29:17.791 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-03T08:29:18.056 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-03T08:29:18.119 Engine:Setting original file name "stobject.dll" for "c:\windows\winsxs\amd64_microsoft-windows-stobject_31bf3856ad364e35_10.0.22000.708_none_45a5d433da92062e\stobject.dll.mun", hr=0x800710da 2026-05-03T08:29:18.509 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-03T08:29:18.572 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-03T08:29:18.634 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-03T08:29:18.713 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-03T08:29:18.822 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-03T08:29:18.822 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-03T08:29:18.978 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-03T08:29:19.181 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-05-03T08:29:19.181 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-03T08:29:19.416 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-03T08:29:19.525 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-03T08:29:19.822 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-03T08:29:19.916 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-03T08:29:20.041 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-03T08:29:20.369 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-03T08:29:20.431 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-03T08:29:20.463 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-03T08:29:20.556 Job Notification: Process exited from job (3256) 2026-05-03T08:29:20.556 Job Notification: Process exited from job (7388) 2026-05-03T08:29:20.634 Job Notification: Process exited from job (2920) 2026-05-03T08:29:20.634 Job Notification: Process exited from job (7368) 2026-05-03T08:29:20.713 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-03T08:29:20.713 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-03T08:29:20.822 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-03T08:29:20.884 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-03T08:29:21.041 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-03T08:29:21.134 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-03T08:29:21.134 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:21.384 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-03T08:29:21.634 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-03T08:29:21.666 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-03T08:29:21.713 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-03T08:29:21.806 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-03T08:29:22.119 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-03T08:29:22.213 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:22.228 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-03T08:29:22.353 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:22.869 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-03T08:29:22.978 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-03T08:29:23.072 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-03T08:29:23.447 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-03T08:29:23.463 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-03T08:29:23.478 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-03T08:29:23.759 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-03T08:29:23.978 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-03T08:29:24.009 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-03T08:29:24.150 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-03T08:29:24.275 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-03T08:29:24.275 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-03T08:29:24.478 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-03T08:29:24.634 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-03T08:29:24.650 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-03T08:29:24.744 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-03T08:29:25.103 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-03T08:29:25.150 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-03T08:29:25.166 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-03T08:29:25.228 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-03T08:29:25.713 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-03T08:29:25.853 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-03T08:29:25.947 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-03T08:29:25.963 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-03T08:29:26.134 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-03T08:29:26.213 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-03T08:29:26.259 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-03T08:29:26.369 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:26.494 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-03T08:29:26.650 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-03T08:29:26.759 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-03T08:29:26.838 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-03T08:29:27.072 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-03T08:29:27.103 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-03T08:29:27.181 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-03T08:29:27.869 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-03T08:29:28.369 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-03T08:29:28.400 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-03T08:29:28.478 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-03T08:29:28.509 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-03T08:29:29.088 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-03T08:29:29.541 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-03T08:29:29.603 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-03T08:29:29.791 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-03T08:29:30.041 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-03T08:29:30.088 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-03T08:29:30.400 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-03T08:29:30.478 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-03T08:29:30.541 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-03T08:29:30.572 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-03T08:29:30.681 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-03T08:29:31.088 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-05-03T08:29:31.166 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-03T08:29:31.447 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-03T08:29:31.494 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-03T08:29:31.509 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-03T08:29:32.119 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-03T08:29:32.400 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-03T08:29:32.541 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-03T08:29:32.744 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:32.853 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:32.884 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-03T08:29:32.884 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:32.931 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-03T08:29:33.041 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-03T08:29:33.103 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-03T08:29:33.181 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-03T08:29:33.275 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-03T08:29:33.306 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-03T08:29:33.306 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-03T08:29:33.353 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-03T08:29:33.369 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-03T08:29:33.619 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-03T08:29:33.619 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-03T08:29:33.666 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-03T08:29:33.759 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-03T08:29:33.884 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-03T08:29:34.244 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-03T08:29:34.509 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-03T08:29:34.775 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-03T08:29:34.916 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-03T08:29:34.994 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:35.181 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-03T08:29:35.478 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-03T08:29:35.556 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-03T08:29:35.728 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-03T08:29:35.838 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-03T08:29:36.166 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-03T08:29:36.213 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-03T08:29:36.275 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-03T08:29:36.291 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-03T08:29:36.291 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-03T08:29:36.369 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:36.634 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-03T08:29:36.650 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-03T08:29:36.838 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-05-03T08:29:37.134 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-03T08:29:37.213 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-03T08:29:37.775 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-03T08:29:38.088 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-03T08:29:38.150 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-03T08:29:38.213 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-03T08:29:38.650 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-03T08:29:39.009 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-03T08:29:39.369 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-03T08:29:39.416 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-03T08:29:39.666 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-03T08:29:39.947 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-03T08:29:40.025 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-03T08:29:40.056 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-05-03T08:29:40.166 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-03T08:29:40.244 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:40.275 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-03T08:29:40.400 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-05-03T08:29:40.494 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-03T08:29:40.728 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-03T08:29:40.759 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-03T08:29:41.525 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-03T08:29:41.791 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-03T08:29:41.838 Engine:Triggered AR EMS scan 2026-05-03T08:29:41.838 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.869 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.869 Engine:EMS scan for process: svchost pid: 676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.869 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.884 Engine:EMS scan for process: svchost pid: 1192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.884 Engine:EMS scan for process: svchost pid: 1200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.884 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.900 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:41.900 Engine:EMS scan for process: svchost pid: 1360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.900 Engine:EMS scan for process: svchost pid: 1368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.900 Engine:EMS scan for process: svchost pid: 1376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.900 Engine:EMS scan for process: svchost pid: 1416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.900 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.916 Engine:EMS scan for process: svchost pid: 1536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.916 Engine:EMS scan for process: svchost pid: 1576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.916 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.916 Engine:EMS scan for process: svchost pid: 1668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.931 Engine:EMS scan for process: svchost pid: 1756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.931 Engine:EMS scan for process: svchost pid: 1848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.931 Engine:EMS scan for process: svchost pid: 1112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.931 Engine:EMS scan for process: svchost pid: 1588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.931 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.947 Engine:EMS scan for process: svchost pid: 2464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.963 Engine:EMS scan for process: svchost pid: 2596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.963 Engine:EMS scan for process: svchost pid: 2624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.963 Engine:EMS scan for process: svchost pid: 2708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.963 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.963 Engine:EMS scan for process: svchost pid: 2996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.978 Engine:EMS scan for process: svchost pid: 2144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.978 Engine:EMS scan for process: svchost pid: 2344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.978 Engine:EMS scan for process: svchost pid: 3184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.978 Engine:EMS scan for process: svchost pid: 3628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.994 Engine:EMS scan for process: svchost pid: 3668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.994 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.994 Engine:EMS scan for process: svchost pid: 3724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:41.994 Engine:EMS scan for process: svchost pid: 3780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.025 Engine:EMS scan for process: svchost pid: 3932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.025 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-03T08:29:42.025 Engine:EMS scan for process: svchost pid: 3976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.025 Engine:EMS scan for process: svchost pid: 3080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.025 Engine:EMS scan for process: svchost pid: 3368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.041 Engine:EMS scan for process: svchost pid: 4228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.041 Engine:EMS scan for process: svchost pid: 4256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.041 Engine:EMS scan for process: svchost pid: 4316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.056 Engine:EMS scan for process: svchost pid: 4356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.056 Engine:EMS scan for process: svchost pid: 4592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.056 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.072 Engine:EMS scan for process: svchost pid: 4708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.072 Engine:EMS scan for process: svchost pid: 4828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.072 Engine:EMS scan for process: svchost pid: 4836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.072 Engine:EMS scan for process: svchost pid: 5296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.088 Engine:EMS scan for process: svchost pid: 5352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.088 Engine:EMS scan for process: dllhost pid: 6076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.088 Engine:EMS scan for process: svchost pid: 6084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.088 Engine:EMS scan for process: svchost pid: 6276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.088 Engine:EMS scan for process: svchost pid: 6964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.103 Engine:EMS scan for process: svchost pid: 8160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.103 Engine:EMS scan for process: svchost pid: 7844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.103 Engine:EMS scan for process: svchost pid: 7004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.103 Engine:EMS scan for process: svchost pid: 3396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.103 Engine:EMS scan for process: svchost pid: 7372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.119 Engine:EMS scan for process: svchost pid: 1832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.119 Engine:EMS scan for process: svchost pid: 3360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.119 Engine:EMS scan for process: svchost pid: 6272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.134 Engine:EMS scan for process: svchost pid: 2060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.134 Engine:EMS scan for process: svchost pid: 536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.134 Engine:EMS scan for process: svchost pid: 5648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.134 Engine:EMS scan for process: svchost pid: 6916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.134 Engine:EMS scan for process: svchost pid: 7268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.150 Engine:EMS scan for process: svchost pid: 3504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-03T08:29:42.431 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-03T08:29:42.525 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-03T08:29:42.588 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-03T08:29:42.619 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-03T08:29:42.697 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-03T08:29:42.713 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:42.838 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-03T08:29:42.900 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-03T08:29:43.009 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-03T08:29:43.072 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-03T08:29:43.166 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:43.275 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-03T08:29:43.588 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-03T08:29:43.650 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-03T08:29:43.838 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-03T08:29:44.056 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-03T08:29:44.166 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-03T08:29:44.541 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-03T08:29:44.634 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:44.931 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-03T08:29:45.494 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-03T08:29:45.884 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-03T08:29:46.228 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-05-03T08:29:46.353 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-03T08:29:46.463 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-03T08:29:47.056 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-03T08:29:47.259 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-03T08:29:47.275 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-03T08:29:47.353 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:47.494 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-03T08:29:47.509 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-03T08:29:48.291 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-03T08:29:48.338 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-03T08:29:48.416 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-03T08:29:48.666 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-03T08:29:48.697 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-05-03T08:29:48.931 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-03T08:29:49.009 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-03T08:29:49.056 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-03T08:29:49.072 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-03T08:29:49.213 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-03T08:29:49.916 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-03T08:29:50.166 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-03T08:29:50.166 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-03T08:29:50.213 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-03T08:29:50.431 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:50.541 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-03T08:29:50.853 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-03T08:29:50.853 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:50.869 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-03T08:29:51.119 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-03T08:29:51.291 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-03T08:29:51.869 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-03T08:29:51.994 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-03T08:29:52.322 Engine:Setting original file name "Acrobat.dll" for "c:\program files\adobe\acrobat dc\acrobat\acrobatres.dll", hr=0x800710da 2026-05-03T08:29:52.416 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-03T08:29:52.463 Engine:Setting original file name "TWINUI.dll" for "c:\windows\winsxs\amd64_microsoft-windows-twinui_31bf3856ad364e35_10.0.22000.2538_none_ecbf26dcf11a684d\twinui.dll.mun", hr=0x800710da 2026-05-03T08:29:52.509 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-03T08:29:53.369 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-03T08:29:53.416 Engine:Setting original file name "_Project Import.exe" for "c:\program files\microsoft office\root\office16\projimpt.exe", hr=0x800710da 2026-05-03T08:29:53.509 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-03T08:29:53.556 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-03T08:29:53.744 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-shell32_31bf3856ad364e35_10.0.22000.2482_none_e551341849a7f566\shell32.dll.mun", hr=0x800710da 2026-05-03T08:29:53.791 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-03T08:29:53.869 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-03T08:29:53.931 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-03T08:29:54.072 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-03T08:29:54.088 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-05-03T08:29:54.119 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-03T08:29:54.259 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-03T08:29:54.306 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-03T08:29:54.369 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-03T08:29:54.400 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-03T08:29:54.400 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-03T08:29:54.666 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-03T08:29:54.775 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-03T08:29:54.822 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-03T08:29:54.838 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-03T08:29:55.119 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-03T08:29:55.213 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-03T08:29:55.228 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-03T08:29:55.244 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-03T08:29:55.494 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-03T08:29:55.822 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-03T08:29:55.900 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:55.994 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-05-03T08:29:56.103 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-03T08:29:56.166 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-05-03T08:29:56.291 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-05-03T08:29:56.369 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-05-03T08:29:56.463 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-05-03T08:29:56.572 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-05-03T08:29:56.619 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-05-03T08:29:56.634 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-05-03T08:29:56.838 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-05-03T08:29:56.900 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-05-03T08:29:56.916 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-05-03T08:29:56.931 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-03T08:29:57.634 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-05-03T08:29:57.650 OriginalFileName Maintenance::10077 files in Moac, 244 skipped (cached), 1 filename set 2026-05-03T08:29:57.650 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-03T08:30:13.213 ExpensiveFile:Scan time for `\\?\C:\Program Files\Microsoft Office\root\Office16\livecapture.bundle` is 8109 units Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0xf5c96b12 2026-05-03T08:30:40.869 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:40.869 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:40.869 [Cloud] Queued cloud request. 2026-05-03T08:30:40.869 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:40.869 [Cloud] Dequeued cloud request. 2026-05-03T08:30:40.869 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:41.525 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x9df1ce23 2026-05-03T08:30:41.947 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:41.947 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:41.947 [Cloud] Queued cloud request. 2026-05-03T08:30:41.947 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:41.947 [Cloud] Dequeued cloud request. 2026-05-03T08:30:41.947 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:42.041 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:30:42.494 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x83c1aa73 2026-05-03T08:30:42.509 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:42.509 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:42.509 [Cloud] Queued cloud request. 2026-05-03T08:30:42.509 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:42.509 [Cloud] Dequeued cloud request. 2026-05-03T08:30:42.509 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:42.900 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 2026-05-03T08:30:42.916 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:42.916 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:42.916 [Cloud] Queued cloud request. 2026-05-03T08:30:42.916 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:42.916 [Cloud] Dequeued cloud request. 2026-05-03T08:30:42.916 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:42.994 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:30:43.259 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x26b3ba41 2026-05-03T08:30:43.369 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:43.369 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:43.369 [Cloud] Queued cloud request. 2026-05-03T08:30:43.369 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:43.369 [Cloud] Dequeued cloud request. 2026-05-03T08:30:43.369 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:43.744 [Cloud] End of cloud request. 2026-05-03T08:30:43.759 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-03T08:30:43.775 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T08:30:43.775 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:30:43.775 [Cloud] Queued cloud request. 2026-05-03T08:30:43.775 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T08:30:43.775 [Cloud] Dequeued cloud request. 2026-05-03T08:30:43.775 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:30:44.119 [Cloud] End of cloud request. 2026-05-03T08:30:44.634 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:33:24.338 QuickScan:ScanID:DC1CD4C2-B65B-40DC-A105-1F1D15B21902: Quick scan finished with error 0 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xdac0cf3e7ffffffe 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x2e66e40f7ffffffe 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd1edc1e97ffffffe 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xe7b52c807ffffffe 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9dda20b57ffffffe 2026-05-03T08:33:24.353 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x5a295f8e7ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xdac0cf3e7ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x2e66e40f7ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd1edc1e97ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xe7b52c807ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9dda20b57ffffffe 2026-05-03T08:33:24.369 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x5a295f8e7ffffffe 2026-05-03T08:33:24.384 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 5 resources, RtpIoavOnly: FALSE Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0xf5c96b12 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x9df1ce23 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x83c1aa73 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-03T08:33:24.447 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-03T08:33:24.447 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-03T08:33:24.447 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x6fcfab137ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xee4a221a7ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xf5aa59297ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x6fcfab137ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xee4a221a7ffffffe 2026-05-03T08:33:24.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xf5aa59297ffffffe 2026-05-03T08:33:24.509 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-05-03T08:33:24.509 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T08:33:24.509 [Cloud] Queued cloud request. 2026-05-03T08:33:24.509 [Cloud] Dequeued cloud request. 2026-05-03T08:33:24.525 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T08:33:24.713 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-03T08:33:24.713 [Cloud] End of cloud request. 2026-05-03T08:33:24.869 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-03T08:33:24.869 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:33:24.869 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:33:24.869 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-03T08:33:24.869 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T08:33:24.869 [RTP] No config change detected. Not updating plugin configuration. 2026-05-03T08:33:24.869 [RTP] No config changes found. No configuration switch. 2026-05-03T08:33:24.869 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-03T08:33:24.869 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T08:33:26.369 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:33:26.369 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-03T08:33:26.369 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-03T08:34:28.322 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #3175, FileId: 0xad00000000ad0d, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T08:39:20.759 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T08:54:25.759 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T08:59:29.643 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #4287, FileId: 0x210000000bccae, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T08:59:35.596 [RTP] 9 newly mounted volumes accumulated, forcing a config update ... 2026-05-03T08:59:35.596 [RTP] Duplicating the current plugin configuration object... 2026-05-03T08:59:35.596 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-03T08:59:35.596 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-03T08:59:35.596 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-03T08:59:35.612 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-03T08:59:35.706 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-03T08:59:36.221 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-03T08:59:41.800 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-03T08:59:41.800 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-03T09:00:01.842 Engine:Triggered SMS scan for filename: explorer.exe, pid: 5092, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 2026-05-03T09:00:02.063 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #7003, FileId: 0xf0000000c353d, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-05-03T09:04:12.428 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8900, FileId: 0x21000000033faa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:04:32.725 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9021, FileId: 0x8300000000174a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:09:30.772 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T09:11:59.491 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA4E3CF9BA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9489, FileId: 0x14000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.506 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj537BA2902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9490, FileId: 0x15000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.506 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0B70F8921. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9493, FileId: 0x34000000029542, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.522 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0E946F9EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9494, FileId: 0x36000000029542, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.569 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj641F75983. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9495, FileId: 0x17000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.623 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj050A74920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9499, FileId: 0x18000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.629 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj301EBA938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9500, FileId: 0x27000000033faa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.653 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3E289D96A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9502, FileId: 0x1a000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.664 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj017E30946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9503, FileId: 0x28000000033faa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.707 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj293E7E9F3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9506, FileId: 0x3d000000029542, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.776 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1E4E169F8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9511, FileId: 0x1c000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.791 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8F7626906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9512, FileId: 0x1d000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.807 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0AFE74952. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9513, FileId: 0x1e000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.822 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj58F541995. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9514, FileId: 0x33000000033fe7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.822 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF1F6D69A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9516, FileId: 0x1f000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.885 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj60EF679CF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9517, FileId: 0x1c00000003401f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.901 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C7D939B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9518, FileId: 0x21000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.916 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF5005597F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9519, FileId: 0x22000000033fed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.932 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6FD95B9F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9520, FileId: 0x13f000000004be0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:11:59.957 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1ECA539B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9521, FileId: 0x140000000004be0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.007 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE0789C910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9525, FileId: 0x67000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.007 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj641619949. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9528, FileId: 0x68000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.023 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCEA03F935. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9529, FileId: 0x69000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.037 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD8EFE59F8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9531, FileId: 0x6a000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.070 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj367589958. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9532, FileId: 0x6b000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.087 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj165A19934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9533, FileId: 0x6c000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.167 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFC32409ED. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9534, FileId: 0x6d000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.180 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1E8B08951. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9535, FileId: 0x6e000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.251 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB7677594A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9537, FileId: 0x70000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.288 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC25E8A9B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9538, FileId: 0x1d00000003401f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.297 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4D9FA1910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9539, FileId: 0x72000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.415 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj96687B9E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9540, FileId: 0x1e00000003401f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.429 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA59062972. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9541, FileId: 0x74000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.441 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6499509E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9542, FileId: 0x75000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.455 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj77A286915. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9543, FileId: 0x76000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.472 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF28B7C96C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9544, FileId: 0x77000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.540 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFD7EB1914. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9545, FileId: 0xb60000000297f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.571 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11806D9CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9546, FileId: 0x79000000009497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.881 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj967465929. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9557, FileId: 0x1d000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:00.902 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj069B499C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9558, FileId: 0x1e000000033907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:14.055 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9709, FileId: 0x950000000186e2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:14.212 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9713, FileId: 0x4e000000013157, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:12:14.399 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9717, FileId: 0x530000000282d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:13:14.821 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9734, FileId: 0x8700000000174a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:13:30.087 [RTP] [Mini-filter] OpenWithoutRead notification (1226, 10001, \Device\HarddiskVolume3\Windows\System32\msiexec.exe) sent successfully. 2026-05-03T09:13:43.149 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\Eureka\AcroCoreSync\Adobe\CoreSync\EntitySync\80307f885d209ff3421f3adf000d6b1e.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10699, FileId: 0x12000000062015, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:13:43.165 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8CBC0D922. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10702, FileId: 0x2b000000033faa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:13:43.165 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10703, FileId: 0x6700000001ac88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:13:43.180 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10705, FileId: 0x136000000018741, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:14:33.305 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #14446, FileId: 0x6450000000006ff, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:19:15.759 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-05-03T09:24:35.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T09:33:00.879 Engine:Process 3752 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-03T09:34:08.146 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22194, FileId: 0x1f000000033872, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:39:40.771 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T09:42:36.380 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22555, FileId: 0xfe000000004a58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:45:12.960 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22793, FileId: 0x220000000366f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.444 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23126, FileId: 0x31000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.460 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23128, FileId: 0x32000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.460 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23130, FileId: 0x26800000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.460 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23127, FileId: 0x26600000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.476 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23133, FileId: 0x26900000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.491 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23135, FileId: 0x37000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.507 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23137, FileId: 0x27000000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.507 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23131, FileId: 0x34000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.507 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23125, FileId: 0x26500000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.929 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23183, FileId: 0x27600000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.929 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23185, FileId: 0x27700000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.944 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23181, FileId: 0x27500000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.944 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23186, FileId: 0x27800000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.944 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23187, FileId: 0x41000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.944 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23188, FileId: 0x42000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.960 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23182, FileId: 0x3f000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.960 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23191, FileId: 0x43000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.976 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23192, FileId: 0x27a00000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:40.991 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23199, FileId: 0x27d00000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.007 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23198, FileId: 0x46000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.023 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23203, FileId: 0x27e00000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.038 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23208, FileId: 0x4a000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.038 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23210, FileId: 0x28100000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.054 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23207, FileId: 0x27f00000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.054 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23209, FileId: 0x28000000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.163 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23235, FileId: 0x4e000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.163 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23234, FileId: 0x4d000000036777, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.163 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23233, FileId: 0x28400000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:41.663 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23289, FileId: 0x28700000000f7cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:42.694 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\997ea8e0-77bc-4eb4-8b18-2821308d0eb0. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #23377, FileId: 0xbb000000024684, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T09:54:45.773 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T10:02:04.095 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23632, FileId: 0x1620000000097ec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:03:10.428 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23838, FileId: 0x44000000011864, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:07:43.959 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24150, FileId: 0x154000000006242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:09:21.329 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24301, FileId: 0xa9000000003f19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:09:43.107 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24571, FileId: 0x380000000367ab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:09:50.768 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T10:10:44.818 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24768, FileId: 0x4a0000000367b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:13:11.024 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25079, FileId: 0xb2000000003f19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:14:27.546 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25290, FileId: 0x140000000369ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:16:59.470 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25727, FileId: 0x37000000036767, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:19:40.987 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T10:19:40.987 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 6214, Count: 124, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T10:19:40.987 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T10:19:40.987 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T10:19:40.987 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T10:19:40.987 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T10:19:40.987 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T10:19:40.987 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T10:19:40.987 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T10:19:40.987 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T10:19:40.987 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T10:19:40.987 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T10:19:40.987 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 486, Count: 35, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 275, Count: 17, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T10:19:40.987 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 185, Count: 9, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T10:19:40.987 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T10:19:40.987 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T10:19:40.987 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T10:19:40.987 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T10:19:40.987 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T10:19:40.987 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T10:19:40.987 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T10:19:40.987 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T10:19:40.987 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T10:19:40.987 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T10:19:40.987 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T10:19:40.987 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T10:19:40.987 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T10:19:40.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T10:19:40.987 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T10:22:26.397 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26069, FileId: 0x600000000282d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:23:04.711 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26329, FileId: 0x1d0000000369b2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:24:55.768 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T10:32:01.786 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26784, FileId: 0x32000000036771, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T10:40:00.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T10:55:05.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T11:10:10.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T11:25:15.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T11:40:20.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T11:49:04.895 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27306, FileId: 0x29000000036707, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T11:49:04.926 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27318, FileId: 0x33000000036707, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T11:55:25.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T12:10:30.769 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T12:19:40.986 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T12:19:40.986 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 6229, Count: 125, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T12:19:40.986 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T12:19:40.986 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T12:19:40.986 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T12:19:40.986 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T12:19:40.986 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T12:19:40.986 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T12:19:40.986 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T12:19:40.986 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T12:19:40.986 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T12:19:40.986 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 516, Count: 37, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T12:19:40.986 ProcessImageName: firefox.exe, Pid: 2732, TotalTime: 375, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11552, EstimatedImpact: 49% 2026-05-03T12:19:40.986 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 305, Count: 19, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T12:19:40.986 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 200, Count: 10, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T12:19:40.986 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T12:19:40.986 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T12:19:40.986 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T12:19:40.986 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T12:19:40.986 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T12:19:40.986 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T12:19:40.986 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T12:19:40.986 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1222.log, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T12:19:40.986 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1231.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T12:19:40.986 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T12:19:40.986 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3404, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1409.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 12988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1413.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 7996, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 7196, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 1% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 3984, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1223.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T12:19:40.986 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T12:19:40.986 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T12:19:40.986 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T12:25:35.768 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T12:38:17.978 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #29873, FileId: 0x220000000369f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T12:40:40.771 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T12:55:45.765 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T13:10:50.768 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T13:25:55.770 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T13:29:06.875 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #35862, FileId: 0x10000000036a57, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T13:41:00.757 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T13:56:05.757 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T14:11:10.757 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T14:19:40.991 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T14:19:40.991 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 7007, Count: 169, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T14:19:40.991 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T14:19:40.991 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T14:19:40.991 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T14:19:40.991 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T14:19:40.991 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T14:19:40.991 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T14:19:40.991 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T14:19:40.991 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T14:19:40.991 ProcessImageName: PDFXCview.exe, Pid: 5968, TotalTime: 720, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml->(UTF-8), EstimatedImpact: 54% 2026-05-03T14:19:40.991 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 681, Count: 49, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T14:19:40.991 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T14:19:40.991 ProcessImageName: firefox.exe, Pid: 2732, TotalTime: 375, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11552, EstimatedImpact: 49% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 320, Count: 25, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 230, Count: 13, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T14:19:40.991 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T14:19:40.991 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T14:19:40.991 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 596, TotalTime: 123, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITDB8.tmp, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T14:19:40.991 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T14:19:40.991 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T14:19:40.991 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T14:19:40.991 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T14:19:40.991 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T14:19:40.991 ProcessImageName: AdobeARM.exe, Pid: 8016, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1222.log, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9344, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1523.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 9160, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[8].htm, EstimatedImpact: 16% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 12880, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 2496, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 31, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1231.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: AdobeARM.exe, Pid: 9484, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T14:19:40.991 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T14:19:40.991 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1434.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1503.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 5964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1440.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T14:19:40.991 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3688, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1520.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1531.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3404, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1409.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 12988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1413.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 12548, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 2136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1533.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 6288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1454.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 12092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 7996, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 7196, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3984, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1223.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 6760, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1449.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 3176, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1542.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8784, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1438.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9920, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1436.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 8456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 10684, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1529.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 3688, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 13128, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: OfficeC2RClient.exe, Pid: 6692, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528a.log, EstimatedImpact: 0% 2026-05-03T14:19:40.991 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T14:26:15.757 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T14:41:20.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T14:56:25.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T15:11:30.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T15:26:35.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T15:41:40.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T15:56:45.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T16:11:50.762 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T16:19:40.998 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T16:19:40.998 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 7038, Count: 171, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T16:19:40.998 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T16:19:40.998 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T16:19:40.999 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T16:19:40.999 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T16:19:40.999 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T16:19:40.999 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T16:19:40.999 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T16:19:40.999 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T16:19:40.999 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T16:19:40.999 ProcessImageName: PDFXCview.exe, Pid: 5968, TotalTime: 720, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml->(UTF-8), EstimatedImpact: 54% 2026-05-03T16:19:40.999 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 712, Count: 51, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T16:19:40.999 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T16:19:40.999 ProcessImageName: firefox.exe, Pid: 2732, TotalTime: 375, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11552, EstimatedImpact: 49% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 365, Count: 29, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 245, Count: 14, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T16:19:40.999 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T16:19:40.999 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T16:19:40.999 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 596, TotalTime: 123, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITDB8.tmp, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T16:19:40.999 ProcessImageName: dasHost.exe, Pid: 5616, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\fa095ecc-e13e-40e7-8e6c-5c49799ba6dc_0.bmp, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T16:19:40.999 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T16:19:40.999 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T16:19:40.999 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T16:19:40.999 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T16:19:40.999 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T16:19:40.999 ProcessImageName: AdobeARM.exe, Pid: 8016, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: FileCoAuth.exe, Pid: 10296, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-03.1459.10296.1.aodl, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1222.log, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 9344, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1523.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 9160, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[8].htm, EstimatedImpact: 16% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 12880, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528.log, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 2496, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T16:19:40.999 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T16:19:40.999 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T16:19:40.999 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1231.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T16:19:40.999 ProcessImageName: AdobeARM.exe, Pid: 9484, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 2% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T16:19:41.000 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 5964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1440.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1531.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 12988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1413.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 6288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1454.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3404, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1409.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 9016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1434.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 12092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 11776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1819.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 12548, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3688, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1520.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 2136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1533.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1503.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 7996, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 7196, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 3488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8784, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1438.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3176, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1542.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 10684, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1529.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 9920, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1436.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 3984, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1223.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1817.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 8456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 6760, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1449.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T16:19:41.000 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 3688, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-05-03T16:19:41.000 ProcessImageName: SDXHelper.exe, Pid: 13128, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T16:19:41.000 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: OfficeC2RClient.exe, Pid: 6692, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528a.log, EstimatedImpact: 0% 2026-05-03T16:19:41.000 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T16:24:26.240 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #40364, FileId: 0x17000000036a93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T16:26:55.764 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T16:42:00.758 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000005550790B9F1, sigsha=73b107874419500a45d7644995c35dcb8551dc8b, cached=false, source=2, resourceid=0x4444a674 2026-05-03T16:42:35.378 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T16:42:35.378 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T16:42:35.378 [Cloud] Queued cloud request. 2026-05-03T16:42:35.378 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T16:42:35.378 [Cloud] Dequeued cloud request. 2026-05-03T16:42:35.378 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T16:42:35.909 [Cloud] End of cloud request. 2026-05-03T16:42:35.909 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\Mup\tsclient\F\FreeCommander64.exe - Verknüpfung.lnk. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x5550790b9f1 2026-05-03T16:42:36.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000005550790B9F1, sigsha=73b107874419500a45d7644995c35dcb8551dc8b, cached=false, source=2, resourceid=0x2fa2502a 2026-05-03T16:42:43.159 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-03T16:42:43.159 [Cloud] Start of cloud request. Passive mode: 0 2026-05-03T16:42:43.159 [Cloud] Queued cloud request. 2026-05-03T16:42:43.159 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-03T16:42:43.159 [Cloud] Dequeued cloud request. 2026-05-03T16:42:43.159 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-03T16:42:43.659 [Cloud] End of cloud request. 2026-05-03T16:42:43.659 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\Mup\tsclient\M\FreeCommanderPortable.exe - Verknüpfung.lnk. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x5550790b9f1 2026-05-03T16:42:44.174 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T16:54:39.938 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #43152, FileId: 0x3d000000036707, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T16:54:39.985 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #43162, FileId: 0x42000000036707, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T16:57:05.766 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T17:12:10.766 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T17:27:15.766 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T17:42:20.766 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T17:57:25.826 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T18:12:30.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T18:19:41.138 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 7360, Count: 203, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T18:19:41.138 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T18:19:41.138 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T18:19:41.138 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T18:19:41.138 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T18:19:41.138 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T18:19:41.138 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T18:19:41.138 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T18:19:41.138 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T18:19:41.138 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T18:19:41.138 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 742, Count: 55, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: PDFXCview.exe, Pid: 5968, TotalTime: 720, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml->(UTF-8), EstimatedImpact: 54% 2026-05-03T18:19:41.138 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T18:19:41.138 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T18:19:41.138 ProcessImageName: firefox.exe, Pid: 9908, TotalTime: 435, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07136, EstimatedImpact: 54% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 380, Count: 33, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: firefox.exe, Pid: 2732, TotalTime: 375, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11552, EstimatedImpact: 49% 2026-05-03T18:19:41.138 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 305, Count: 19, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T18:19:41.138 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T18:19:41.138 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T18:19:41.138 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 596, TotalTime: 123, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITDB8.tmp, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: dasHost.exe, Pid: 5616, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\fa095ecc-e13e-40e7-8e6c-5c49799ba6dc_0.bmp, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T18:19:41.138 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T18:19:41.138 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T18:19:41.138 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T18:19:41.138 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T18:19:41.138 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T18:19:41.138 ProcessImageName: AdobeARM.exe, Pid: 8016, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: FileCoAuth.exe, Pid: 10296, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-03.1459.10296.1.aodl, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1222.log, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 46, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 5104, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1831.log, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9344, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1523.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 9160, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[8].htm, EstimatedImpact: 16% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 2496, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 12880, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T18:19:41.138 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1231.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: AdobeARM.exe, Pid: 9484, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T18:19:41.138 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 12988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1413.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 2216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1832.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 12548, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 5964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1440.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 7932, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1840.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3404, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1409.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 2136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1533.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 11776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1819.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T18:19:41.138 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1503.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3688, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1520.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1531.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1434.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 6288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1454.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 12092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539.log, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 7196, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 3488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 7996, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-05-03T18:19:41.138 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 9920, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1436.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 10684, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1529.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 6760, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1449.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3984, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1223.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8784, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1438.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 5376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1824.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 11360, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1844.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1817.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3176, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1542.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1820.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 13128, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 1292, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT505A.tmp, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 3688, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-05-03T18:19:41.138 ProcessImageName: SDXHelper.exe, Pid: 8556, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1837.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: OfficeC2RClient.exe, Pid: 6692, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528a.log, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T18:19:41.138 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T18:27:35.922 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T18:42:40.953 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T18:49:05.010 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #43810, FileId: 0x24000000033f86, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T18:49:05.042 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #43821, FileId: 0x2a000000033f86, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-03T18:57:45.976 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T19:12:50.993 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T19:27:56.005 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T19:43:01.014 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T19:58:06.021 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T20:13:11.026 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-03T20:19:41.278 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 7360, Count: 203, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T20:19:41.278 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T20:19:41.278 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T20:19:41.278 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T20:19:41.278 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T20:19:41.278 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T20:19:41.278 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T20:19:41.278 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T20:19:41.278 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T20:19:41.278 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% 2026-05-03T20:19:41.278 ProcessImageName: TeamViewer.exe, Pid: 7992, TotalTime: 742, Count: 55, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: PDFXCview.exe, Pid: 5968, TotalTime: 720, Count: 78, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml->(UTF-8), EstimatedImpact: 54% 2026-05-03T20:19:41.278 ProcessImageName: WmiPrvSE.exe, Pid: 7264, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 87% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 7932, TotalTime: 577, Count: 2, MaxTime: 562, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 13% 2026-05-03T20:19:41.278 ProcessImageName: powershell.exe, Pid: 6684, TotalTime: 494, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 7% 2026-05-03T20:19:41.278 ProcessImageName: firefox.exe, Pid: 9908, TotalTime: 435, Count: 41, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07136, EstimatedImpact: 54% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 395, Count: 35, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: firefox.exe, Pid: 2732, TotalTime: 375, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa11552, EstimatedImpact: 49% 2026-05-03T20:19:41.278 ProcessImageName: dllhost.exe, Pid: 6076, TotalTime: 320, Count: 21, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: msiexec.exe, Pid: 11396, TotalTime: 311, Count: 2, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: firefox.exe, Pid: 10596, TotalTime: 285, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa07604, EstimatedImpact: 37% 2026-05-03T20:19:41.278 ProcessImageName: WhatsApp.Root.exe, Pid: 1772, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 2440, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: backgroundTaskHost.exe, Pid: 8852, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 11% 2026-05-03T20:19:41.278 ProcessImageName: AdobeCollabSync.exe, Pid: 13000, TotalTime: 210, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-03.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: TabTip.exe, Pid: 7328, TotalTime: 171, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-03T20:19:41.278 ProcessImageName: ngentask.exe, Pid: 3192, TotalTime: 165, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-03T20:19:41.278 ProcessImageName: FileCoAuth.exe, Pid: 212, TotalTime: 151, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 1588, TotalTime: 124, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 596, TotalTime: 123, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITDB8.tmp, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: ngentask.exe, Pid: 8188, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 4% 2026-05-03T20:19:41.278 ProcessImageName: dasHost.exe, Pid: 5616, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\fa095ecc-e13e-40e7-8e6c-5c49799ba6dc_0.bmp, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 9332, TotalTime: 106, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2AB6F6C1-7FF4-4924-928C-92545E070123, EstimatedImpact: 7% 2026-05-03T20:19:41.278 ProcessImageName: PhoneExperienceHost.exe, Pid: 9552, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 676, TotalTime: 92, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3120, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 3% 2026-05-03T20:19:41.278 ProcessImageName: taskhostw.exe, Pid: 8100, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D1DF7F06B769BCCB3F4479041EC1F06E9CD3CB1A, EstimatedImpact: 83% 2026-05-03T20:19:41.278 ProcessImageName: SecurityHealthHost.exe, Pid: 11016, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5788, TotalTime: 76, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\BD423A98-114D-4B43-897F-AC90F4F18B2E, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: runonce.exe, Pid: 11532, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: RuntimeBroker.exe, Pid: 7732, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\index.windows.bundle, EstimatedImpact: 28% 2026-05-03T20:19:41.278 ProcessImageName: RUXIMICS.exe, Pid: 4532, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\CTAC.json, EstimatedImpact: 27% 2026-05-03T20:19:41.278 ProcessImageName: taskhostw.exe, Pid: 8, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 4% 2026-05-03T20:19:41.278 ProcessImageName: AdobeARM.exe, Pid: 8016, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10752, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6B493BD0-D936-4F47-AF25-A0EEB97E425C, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: Acrobat.exe, Pid: 4788, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\DarkTheme.acrotheme, EstimatedImpact: 6% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 2372, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21431\BITF536.tmp, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 6504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 8% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 4536, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: FileCoAuth.exe, Pid: 10296, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-03.1459.10296.1.aodl, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3256, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: OpenWith.exe, Pid: 10992, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 24% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1222.log, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: AggregatorHost.exe, Pid: 5628, TotalTime: 46, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10364, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1214.log, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9344, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1523.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5104, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1831.log, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: armsvc.exe, Pid: 3596, TotalTime: 45, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 9160, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[8].htm, EstimatedImpact: 16% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9512, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1142.log, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 2496, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 12880, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: Acrobat.exe, Pid: 11348, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 22% 2026-05-03T20:19:41.278 ProcessImageName: taskhostw.exe, Pid: 4520, TotalTime: 31, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9200, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1216.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1231.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: AdobeARM.exe, Pid: 9484, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 13232, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 5% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3500, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1029.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 2776, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A, EstimatedImpact: 6% 2026-05-03T20:19:41.278 ProcessImageName: dllhost.exe, Pid: 7180, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 9% 2026-05-03T20:19:41.278 ProcessImageName: backgroundTaskHost.exe, Pid: 8908, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 27% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 7932, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1840.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3404, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1409.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 12988, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1413.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1503.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9, EstimatedImpact: 10% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 11392, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1207.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OneDriveLauncher.exe, Pid: 9840, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 12548, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 2136, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1533.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 11384, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1203.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 2216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1832.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1213.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5964, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1440.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9016, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1434.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 11092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1210.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 12092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 11776, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1819.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 6288, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1454.log, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 7372, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BITD49E.tmp, EstimatedImpact: 3% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 7492, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04, EstimatedImpact: 19% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3688, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1520.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3528, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1531.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 3488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 7996, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 7196, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 10% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 12116, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1145.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: AdobeARM.exe, Pid: 5796, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9920, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1436.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1817.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 9740, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 6020, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3176, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1542.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1539a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8784, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1438.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 5376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1824.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8060, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1514a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 11360, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1844.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3984, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1223.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 9224, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1104a.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 6760, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1449.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 8844, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1209a.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1820.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10684, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1529.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 13128, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 10284, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 3688, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 1% 2026-05-03T20:19:41.278 ProcessImageName: SDXHelper.exe, Pid: 8556, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 5648, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\WebResourcesFileList.txt, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: AdobeARM.exe, Pid: 1468, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\AdobeARM.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 1292, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT505A.tmp, EstimatedImpact: 2% 2026-05-03T20:19:41.278 ProcessImageName: DismHost.exe, Pid: 10260, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 8% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 10068, TotalTime: 0, Count: 7, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1134.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: brynhildr.exe, Pid: 4176, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 3324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1837.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: OfficeC2RClient.exe, Pid: 6692, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260503-1528a.log, EstimatedImpact: 0% 2026-05-03T20:19:41.278 ProcessImageName: svchost.exe, Pid: 7020, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-03T20:23:20.528 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7BE447A9-0F4B-46D8-9C5B-890976684867cec.1dcdb3aaddd8869 2026-05-03T20:23:20.622 Verifying engine and signature files (source: 0) ... 2026-05-03T20:23:20.622 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpengine.dll] due to PPL. 2026-05-03T20:23:20.622 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasbase.vdm] (file in cache) 2026-05-03T20:23:20.622 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-03T20:23:20.638 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasdlta.vdm] 2026-05-03T20:23:20.638 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpavbase.vdm] (file in cache) 2026-05-03T20:23:20.638 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-03T20:23:20.653 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpavdlta.vdm] 2026-05-03T20:23:20.825 [Engine] IsHybridMode: 0 2026-05-03T20:23:20.825 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-03T20:23:20.825 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8E8CA90B832B3F768B6FEDF83DEFF0C314719E1D.bin): 0x00000002 2026-05-03T20:23:20.825 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8E8CA90B832B3F768B6FEDF83DEFF0C314719E1D.bin) 2026-05-03T20:23:20.825 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-03T20:23:20.825 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-03T20:23:20.825 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-03T20:23:20.825 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-03T20:23:32.685 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-03T20:23:32.685 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-03T20:23:32.700 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFFB97C8020, lRefCount: 5, hr=0 2026-05-03T20:23:32.700 [Engine] New active engine 00007FFF8A6A8020 replacing engine 00007FFFB97C8020. Number of active engines: 2 2026-05-03T20:23:32.716 EngineInit:Global ASOC is enabled 2026-05-03T20:23:32.716 EngineInit:ASOO is enabled for developer volumes 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-03T20:23:32.778 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\57c248f31c3d21d7fce9de0ecb5244c3bcf8f3fb Dynamic Signature Compilation Timestamp:05-01-2026 10:08:45 Persistence Type:Duration Time remaining:1728000000 2026-05-03T20:23:32.794 MpWriteUupSignatureVersion 1.449.432.0, hr = 0 2026-05-03T20:23:32.794 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-03T20:23:32.810 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-03T20:23:32.825 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-03T20:23:32.825 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-03T20:23:32.825 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-03T20:23:32.825 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-03T20:23:32.841 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-03T20:23:32.841 [Plugin] Initializing RTP plugin state... 2026-05-03T20:23:32.841 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-03T20:23:32.841 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎03‎-‎2026 10:19:41 Last Perf:‎05‎-‎03‎-‎2026 10:19:41 First RTP Scan:‎05‎-‎03‎-‎2026 10:19:41 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:3207 Misses:31462 BM Queue:0,425,0 Proc:0,230,0 File:0,207,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,2,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:44434 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:347401378 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:22965 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:101347 TotalHits:508532 InstanceCacheInserts:2406 InstanceCacheUpdates:0 InstanceCacheDeletes:53 InstanceCacheHits:154 InstanceCacheMisses:34319 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (6031/1939) Success: 1939, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-03T20:23:32.841 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3} 2026-05-03T20:23:32.841 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{515AD871-E4F0-4FB3-83D2-CBBA8728A07C} removed 2026-05-03T20:23:32.841 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-03T20:23:32.841 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BD0D44F1-EE20-4C3C-9028-258500C66DF9}\mpasbase.vdm in use, hr=0x80070020 2026-05-03T20:23:32.841 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.841 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.841 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.841 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.841 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-03-2026 20:23:32 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-03-2026 20:23:32 2026-05-03T20:23:32.841 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-03T20:23:32.841 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-03T20:23:32.857 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T20:23:32.857 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-03T20:23:32.857 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-03T20:23:32.857 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.857 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.857 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.857 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-03T20:23:32.857 MdCoreSvc is supported in this platform and OS Signature updated on 05-03-2026 20:23:32 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.432.0 AV Signature Version: 1.449.432.0 ************************************************************ 2026-05-03T20:23:32.857 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-03T20:23:32.857 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\7BE447A9-0F4B-46D8-9C5B-890976684867cec.1dcdb3aaddd8869 2026-05-03T20:23:32.872 Process scan (postsignatureupdatescan) started. 2026-05-03T20:23:32.935 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-03T20:23:32.950 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-03T20:23:33.263 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-03T20:23:33.263 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-03T20:23:33.263 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-03T20:23:33.263 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-03T20:23:33.263 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-03T20:23:33.263 [Engine] Engine 00007FFFB97C8020 no longer in use. Number of active engines: 1 2026-05-03T20:23:33.263 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-03T20:23:33.263 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-03T20:23:33.325 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-03T20:23:33.325 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-03T20:23:33.325 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-03T20:23:33.450 ProcessImageName: explorer.exe, Pid: 5092, TotalTime: 7360, Count: 203, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-03T20:23:33.450 ProcessImageName: AdobeARM.exe, Pid: 8296, TotalTime: 7207, Count: 33, MaxTime: 2265, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21431\6089\AcroRdrDCx64Upd2600121529_incr.msp, EstimatedImpact: 6% 2026-05-03T20:23:33.450 ProcessImageName: AcroCEF.exe, Pid: 9572, TotalTime: 3836, Count: 169, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\libs\microsoftGraph\microsoft-graph-js-sdk-web.js, EstimatedImpact: 30% 2026-05-03T20:23:33.450 ProcessImageName: DipAwayMode.exe, Pid: 4848, TotalTime: 2884, Count: 16, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll, EstimatedImpact: 0% 2026-05-03T20:23:33.450 ProcessImageName: AsPowerBar.exe, Pid: 12688, TotalTime: 2818, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 64% 2026-05-03T20:23:33.450 ProcessImageName: dllhost.exe, Pid: 9048, TotalTime: 2727, Count: 80, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\A65Y669HLG_123, EstimatedImpact: 54% 2026-05-03T20:23:33.450 ProcessImageName: firefox.exe, Pid: 1832, TotalTime: 2086, Count: 204, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 67% 2026-05-03T20:23:33.450 ProcessImageName: MOM.exe, Pid: 11332, TotalTime: 1837, Count: 23, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 52% 2026-05-03T20:23:33.450 ProcessImageName: AISuite3.exe, Pid: 3416, TotalTime: 1430, Count: 21, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-03T20:23:33.450 ProcessImageName: DeviceCensus.exe, Pid: 5048, TotalTime: 1388, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-03T20:23:33.450 ProcessImageName: websockify.exe, Pid: 11336, TotalTime: 897, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 58% 2026-05-03T20:23:33.450 ProcessImageName: WmiPrvSE.exe, Pid: 5936, TotalTime: 866, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 74% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-06-2026 07:42:28 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/06/2026 07:42:28.25833500 UTC (15734 ms since boot) 2026-05-06T07:42:28.052 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-06T07:42:28.082 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:42:28.082 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:42:28.142 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260506-074228-00000003-fffffffeffffffff.bin ... 2026-05-06T07:42:28.242 [WPP] Trace session started - MpWppTracing-20260506-074228-00000003-fffffffeffffffff.bin 2026-05-06T07:42:28.248 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-06T07:42:28.248 [RbM] Rollback manager succesfully initialized. 2026-05-06T07:42:28.248 [RbM] Rollback manager EnableRollbackManager called. 2026-05-06T07:42:28.257 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-06T07:42:28.257 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-06T07:42:28.257 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-06T07:42:28.257 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-06T07:42:28.257 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-06T07:42:28.262 MdCoreSvc is supported in this platform and OS 2026-05-06T07:42:28.262 MdCoreSvc is supported in this platform and OS 2026-05-06T07:42:28.262 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-06T07:42:28.264 [PlatUpd] Starting MdCoreSvc service 2026-05-06T07:42:28.321 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-06T07:42:32.086 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-06T07:42:32.086 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-06T07:42:32.086 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-06T07:42:32.086 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-06T07:42:32.086 [PlatUpd] CSP platform update started 2026-05-06T07:42:32.086 [PlatUpd] Defender MDM CSP platform update not required 2026-05-06T07:42:32.086 [PlatUpd] WMI/PS provider platform update started 2026-05-06T07:42:32.086 [PlatUpd] WMI/PS provider platform update not required 2026-05-06T07:42:32.086 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-06T07:42:32.086 MdCoreSvc is supported in this platform and OS 2026-05-06T07:42:32.086 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-06T07:42:32.086 [PlatUpd] Starting MdCoreSvc service 2026-05-06T07:42:32.086 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-06T07:42:32.086 [TS] Troublshooting mode is not available! 2026-05-06T07:42:32.086 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-06T07:42:32.086 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-06T07:42:32.117 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-06T07:42:32.117 [Service] Enabling AutoLoggers ... 2026-05-06T07:42:32.117 [Service] Enabling AMSI registration ... 2026-05-06T07:42:32.117 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-06T07:42:32.133 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 45676 Number of invalid entries is 0 Number of inserts issued is 1578842 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6489 Number of lookups is 107836780 Number of lookup misses is 5176567 Number of fast lookup misses is 54934170 Number of false fast lookups is 5176562 Number of invalidations is 731939 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-06T07:42:32.133 Verifying license file... 2026-05-06T07:42:32.133 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-05-06T07:42:32.148 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-06T07:42:32.148 Loaded module#0 MpComServer. 2026-05-06T07:42:32.148 Loaded module#1 StartupPolicies. 2026-05-06T07:42:32.148 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-06T07:42:32.148 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-06T07:42:32.148 COM server initialized successfully. 2026-05-06T07:42:32.164 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-06T07:42:32.179 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-06T07:42:32.179 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-06T07:42:32.179 [RTP] [RTP] FilterCommunicator object 0x0000028CDC08F260 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-06T07:42:32.195 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-06T07:42:32.195 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T07:42:32.195 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T07:42:32.195 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-06T07:42:32.195 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-06T07:42:32.195 [RTP] [RTP] FilterCommunicator object 0x0000028CDC08F470 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-06T07:42:32.195 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-06T07:42:32.195 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-06T07:42:32.195 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-06T07:42:32.195 [RTP] [RTP] StartCommunication 0x0000028CDC08F260 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-06T07:42:32.195 [init][RTP] RTPPlugin initialization completed 2026-05-06T07:42:32.195 OS boot count = 2 2026-05-06T07:42:32.195 OS Install = 0 2026-05-06T07:42:32.211 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-06T07:42:32.211 [KSL] Entering CKSLEngine::Initialize. 2026-05-06T07:42:32.211 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-06T07:42:32.211 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-06T07:42:32.211 [KSL] MpInstallKslD: hr=0x1 2026-05-06T07:42:32.211 [KSL] MpRegisterKslD: hr=0 2026-05-06T07:42:32.211 [KSL] MpStartKslD: hr=0 2026-05-06T07:42:32.211 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-06T07:42:32.211 Loading engine... 2026-05-06T07:42:32.226 Verifying engine and signature files (source: 1) ... 2026-05-06T07:42:32.226 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpengine.dll] due to PPL. 2026-05-06T07:42:32.226 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasbase.vdm] (file in cache) 2026-05-06T07:42:32.226 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasdlta.vdm] (file in cache) 2026-05-06T07:42:32.226 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpavbase.vdm] (file in cache) 2026-05-06T07:42:32.226 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpavdlta.vdm] (file in cache) 2026-05-06T07:42:32.273 [Engine] IsHybridMode: 0 2026-05-06T07:42:32.273 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-06T07:42:32.304 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-8E8CA90B832B3F768B6FEDF83DEFF0C314719E1D.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-06T07:42:39.054 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-06T07:42:39.054 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_MemScanPassLocalExceptionsToEngine new=0 old1 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-05-06T07:42:39.054 [Engine] New active engine 00007FFAAA2F8020 (no old engine). Number of active engines: 1 2026-05-06T07:42:39.054 EngineInit:Global ASOC is enabled 2026-05-06T07:42:39.054 EngineInit:ASOO is enabled for developer volumes 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.133 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.148 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.148 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.148 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.148 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b624b0da8c1870ecdd4ef98deb361e81f8306885 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:29 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\35c7bf6823f5f561a6c6162725e57a09a4c98e52 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:29 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\caefb083ecabe56a831d9807f231f91f5f0e2986 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:30 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b8547a5555fc9b51aea25e5d9607bce80759fb9 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:30 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79d0beb2c03e15f52af4cc282ae6d2790bc110fd Dynamic Signature Compilation Timestamp:04-24-2026 06:37:31 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f07b4d253afc62557c38b1d97663bce44acbb30b Dynamic Signature Compilation Timestamp:04-24-2026 06:37:31 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c01e8f9ca8f7d7ee7fd89d11b358980ff4ba38cd Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5ed85f41250532cca3e19bfa08c100c5d90500d3 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\56d0297c68520290cc39650380bc33f2d4fe11f9 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b0d31eb6500b4224000c166d9747d089c3af5b3 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:32 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f437ea1d9a19d51cc0ee5b27b1d791884f0cb53a Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eb50bffb6f8a866e6032c4137cead8cd85b31679 Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.148 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e3fc9f7fdff1dd41ecdd2a243a0a52acb4e3f5c Dynamic Signature Compilation Timestamp:04-24-2026 06:37:33 Persistence Type:Duration Time remaining:50065408 2026-05-06T07:42:39.195 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7b7e11fff1e1eb613332862dcf2b591e9679afab Dynamic Signature Compilation Timestamp:05-01-2026 23:00:12 Persistence Type:Duration Time remaining:1728000000 2026-05-06T07:42:39.195 MpWriteUupSignatureVersion 1.449.432.0, hr = 0 2026-05-06T07:42:39.195 [SigStatUpd] CSignatureStatus: back to good 2026-05-06T07:42:39.195 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-06T07:42:39.211 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-06T07:42:39.211 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:42:39.211 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-06T07:42:39.211 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-06T07:42:39.211 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-06T07:42:39.226 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-06T07:42:39.226 [Plugin] Initializing RTP plugin state... 2026-05-06T07:42:39.226 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-06T07:42:39.226 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2226 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12957 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2535 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-06T07:42:39.226 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3} 2026-05-06T07:42:39.226 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:42:39.226 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:42:39.226 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:42:39.226 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T07:42:39.226 MdCoreSvc is supported in this platform and OS 2026-05-06T07:42:39.226 Engine loaded! 2026-05-06T07:42:39.226 [DLP] Create FeatureControlState instance 2026-05-06T07:42:39.242 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-06T07:42:39.242 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-06T07:42:39.242 RegisterSModeChangeListener: hr = 0x1 2026-05-06T07:42:39.242 RegisterHybridModeChangeListener: hr = 0 2026-05-06T07:42:39.258 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-06T07:42:39.258 [SigReleaseHb] Initialized with Stage 0 2026-05-06T07:42:39.258 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-06T07:42:39.258 [SCC][CID=26984_5476] Initializing ... 2026-05-06T07:42:39.258 [SCC][CID=26984_5476] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-06T07:42:39.258 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-06T07:42:39.258 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-06T07:42:39.258 [NRI] Stopping NIS service ... 2026-05-06T07:42:39.258 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-06T07:42:39.258 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). 2026-05-06T07:42:39.258 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.432.0 AV Signature Version: 1.449.432.0 ************************************************************ 2026-05-06T07:42:39.258 Resource usage Monitoring is enabled 2026-05-06T07:42:39.258 Job Notification: New process added to job (4800) 2026-05-06T07:42:39.258 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-06T07:42:39.304 Job Notification: New process added to job (7708) 2026-05-06T07:42:39.304 Job Notification: New process added to job (7716) 2026-05-06T07:42:39.304 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7708] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7716]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-06T07:42:39.351 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-06T07:42:39.351 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-06T07:42:39.351 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-06T07:42:39.351 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-06T07:42:39.351 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-06T07:42:39.351 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T07:42:39.351 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T07:42:39.351 [RTP] Generating the base plugin configuration ... 2026-05-06T07:42:39.351 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-06T07:42:39.351 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:42:39.351 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-06T07:42:39.367 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-06T07:42:39.367 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:42:39.367 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-06T07:42:39.367 [RTP] [RTP] StartCommunication 0x0000028CDC08F470 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-06T07:42:39.367 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-06T07:42:39.367 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-06T07:42:39.398 Job Notification: Process exited from job (7708) 2026-05-06T07:42:39.414 Job Notification: Process exited from job (7716) 2026-05-06T07:42:39.414 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-06T07:42:39.695 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-06T07:42:39.695 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-06T07:42:39.695 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-06T07:42:39.726 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:40.133 [AutoPurge] Verification Routine tasks have started. 2026-05-06T07:42:40.133 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-06T07:42:40.336 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-06T07:42:40.336 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-06T07:42:40.367 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-06T07:42:40.711 Job Notification: New process added to job (7900) 2026-05-06T07:42:40.711 Task(GetDeviceTicket -AccessKey DB385E9E-5C76-87E6-8249-E8B3779BDA50 ) launched as network service 2026-05-06T07:42:41.086 Job Notification: Process exited from job (7900) 2026-05-06T07:42:41.148 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-06T07:42:41.148 [Cloud] Start of cloud request. Passive mode: 0 2026-05-06T07:42:41.164 [Cloud] Queued cloud request. 2026-05-06T07:42:41.164 [Cloud] Dequeued cloud request. 2026-05-06T07:42:41.164 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-06T07:42:41.164 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-06T07:42:41.164 [AutoPurge] Verification Routine tasks have ended. 2026-05-06T07:42:41.492 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c351880f624935c1b0fd0fd3f42a21fe4674d1a1 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2016b4d82bfd8354983956ea0b0c8e72c4e42b4b Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:42:41.508 Dynamic signature received Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2f00c614727288f16efc88537915928394cef9c4 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:42:41.508 Dynamic signature received Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\629b2e201a588da14dc81729d0b88469ce55c905 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:42:41.508 Dynamic signature received Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7828145419a5749c69cf92072cd235db33da3a2b Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:42:41.508 Dynamic signature received Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2b2104d012e78ca467e2ea3b8bbbe0838983f6e2 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b3bf28d624a01339853da23979da7832705121f1 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2c208f57eba3ffc5e93417456e40762302ce5ff3 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2d3db040ee9ff88b020962fa80ff6e28a76f2027 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5985dae5cd456f30f6e57ced273318bc6a635f07 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a4b91a89c39d007a44f3d5fdd209ac58187375c Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\02a09d28e52c32786b7c6d6734fa2dc0df8c93fb Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\525c7a7f47181d2531053135f107ec7140afb8b3 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62ba6b2a5c9f71ac6556a97239d6230832b495cb Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\88323b64674818696a6820e67908137e22820c0d Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3df8800af179391a69681ade5f34fb30635bf807 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\37f5b30c21dbfe4028b4fe208438e930cb7e27af Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\901257d266f069e06e03c8483d67c87fd1fc7c39 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1ee74759dcdaa748a3d21f76da2bbdd4e017f019 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6ccc4e0ddee1fcba28d4500a43b39c15a0b1e2b9 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e38e79351722e976fffb3b7d26de77405dc59b4d Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:42:41.523 Dynamic signature received Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8140471342dbfcefe00e9dbfcf89e8de89a1cde2 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99adea3df4cb12b31d6feaa683bf9d566e82d3f0 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f3471064d174ced5f63cc5f999de2c2bdbf3eb7c Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\60bcbb8f68b6bcf964626abd9ddfc66d072082aa Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9d923edd37b9960ebc2f62b1bb15338203f14d4 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:196610 Start time:05-06-2026 07:42:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:42:41 2026-05-06T07:42:41.523 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-06T07:42:41.523 [Cloud] End of cloud request. 2026-05-06T07:42:41.633 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-06T07:42:41.648 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-06T07:42:41.648 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-06T07:42:41.648 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-06T07:42:41.648 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T07:42:41.648 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T07:42:41.648 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-06T07:42:41.648 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-06T07:42:41.648 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-06T07:42:41.648 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:41.664 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:41.664 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:42:42.304 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:42:42.304 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:42:42.304 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-05-06T07:42:42.304 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:42:42.304 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-06T07:42:42.304 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-05-06T07:43:32.133 Process scan (poststartupscan) started. 2026-05-06T07:43:32.133 Process scan (poststartupscan) completed. 2026-05-06T07:43:32.539 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\2D0536E5-58ED-481A-9B4A-F82186BD97461e54.1dcdd2c08d69319 2026-05-06T07:43:32.648 Verifying engine and signature files (source: 0) ... 2026-05-06T07:43:32.648 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll] due to PPL. 2026-05-06T07:43:32.648 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasbase.vdm] (file in cache) 2026-05-06T07:43:32.648 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-06T07:43:32.664 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasdlta.vdm] 2026-05-06T07:43:32.664 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavbase.vdm] (file in cache) 2026-05-06T07:43:32.664 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-06T07:43:32.679 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavdlta.vdm] 2026-05-06T07:43:32.836 [Engine] IsHybridMode: 0 2026-05-06T07:43:32.836 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-06T07:43:32.851 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-89822B7411F1DB465033F7E1EE8B390B02057CBC.bin): 0x00000002 2026-05-06T07:43:32.851 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-89822B7411F1DB465033F7E1EE8B390B02057CBC.bin) 2026-05-06T07:43:32.851 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-06T07:43:32.851 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-06T07:43:32.851 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-06T07:43:32.851 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-06T07:43:44.648 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-06T07:43:44.648 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_MemScanPassLocalExceptionsToEngine new=0 old1 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-05-06T07:43:44.648 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFAAA2F8020, lRefCount: 5, hr=0 2026-05-06T07:43:44.648 [Engine] New active engine 00007FFAA5B78020 replacing engine 00007FFAAA2F8020. Number of active engines: 2 2026-05-06T07:43:44.664 EngineInit:Global ASOC is enabled 2026-05-06T07:43:44.664 EngineInit:ASOO is enabled for developer volumes 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.726 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c351880f624935c1b0fd0fd3f42a21fe4674d1a1 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\02a09d28e52c32786b7c6d6734fa2dc0df8c93fb Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1ee74759dcdaa748a3d21f76da2bbdd4e017f019 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2016b4d82bfd8354983956ea0b0c8e72c4e42b4b Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2b2104d012e78ca467e2ea3b8bbbe0838983f6e2 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2c208f57eba3ffc5e93417456e40762302ce5ff3 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2d3db040ee9ff88b020962fa80ff6e28a76f2027 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2f00c614727288f16efc88537915928394cef9c4 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\37f5b30c21dbfe4028b4fe208438e930cb7e27af Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3df8800af179391a69681ade5f34fb30635bf807 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a4b91a89c39d007a44f3d5fdd209ac58187375c Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\525c7a7f47181d2531053135f107ec7140afb8b3 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5985dae5cd456f30f6e57ced273318bc6a635f07 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\629b2e201a588da14dc81729d0b88469ce55c905 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62ba6b2a5c9f71ac6556a97239d6230832b495cb Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6ccc4e0ddee1fcba28d4500a43b39c15a0b1e2b9 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7828145419a5749c69cf92072cd235db33da3a2b Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\88323b64674818696a6820e67908137e22820c0d Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\901257d266f069e06e03c8483d67c87fd1fc7c39 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b3bf28d624a01339853da23979da7832705121f1 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\60bcbb8f68b6bcf964626abd9ddfc66d072082aa Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8140471342dbfcefe00e9dbfcf89e8de89a1cde2 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99adea3df4cb12b31d6feaa683bf9d566e82d3f0 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e38e79351722e976fffb3b7d26de77405dc59b4d Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9d923edd37b9960ebc2f62b1bb15338203f14d4 Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Disable Notification Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f3471064d174ced5f63cc5f999de2c2bdbf3eb7c Dynamic Signature Compilation Timestamp:01-01-1601 00:00:00 Persistence Type:VDM Version Source Version:283403445338113 Expiration Version:283403445338113 2026-05-06T07:43:44.742 MpWriteUupSignatureVersion 1.449.476.0, hr = 0 2026-05-06T07:43:44.742 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-06T07:43:44.758 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-06T07:43:44.758 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:43:44.758 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-06T07:43:44.758 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-06T07:43:44.758 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-06T07:43:44.773 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-06T07:43:44.773 [Plugin] Initializing RTP plugin state... 2026-05-06T07:43:44.773 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎06‎-‎2026 09:42:39 Last Perf:‎05‎-‎06‎-‎2026 09:42:39 First RTP Scan:‎05‎-‎06‎-‎2026 09:42:39 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:266 Misses:529 BM Queue:0,7,0 Proc:0,7,0 File:0,4,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:852 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:977536 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2608 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14900 TotalHits:1286 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2953 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (33/9) Success: 9, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-06T07:43:44.773 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-06T07:43:44.773 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1} 2026-05-06T07:43:44.773 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-06T07:43:44.773 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8FCC3469-82CA-4DF9-81F5-30B4B9F4D939} removed 2026-05-06T07:43:44.773 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D5F1DF14-EC3D-40ED-8268-C90909B351C3}\mpasbase.vdm in use, hr=0x80070020 2026-05-06T07:43:44.773 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.773 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.773 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.773 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.773 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-06-2026 07:43:44 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:43:44 2026-05-06T07:43:44.773 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-06T07:43:44.773 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-06T07:43:44.789 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:43:44.789 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-06T07:43:44.789 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:43:44.789 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.789 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.789 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.789 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T07:43:44.789 MdCoreSvc is supported in this platform and OS Signature updated on 05-06-2026 07:43:44 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.476.0 AV Signature Version: 1.449.476.0 ************************************************************ -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-06-2026 07:44:44 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/06/2026 07:44:44.846770600 UTC (15562 ms since boot) 2026-05-06T07:44:44.894 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-06T07:44:44.894 WARNING: the previous service shutdown was not expected. 2026-05-06T07:44:44.899 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:44:44.899 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:44:44.939 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260506-074444-00000003-fffffffeffffffff.bin ... 2026-05-06T07:44:45.009 [WPP] Trace session started - MpWppTracing-20260506-074444-00000003-fffffffeffffffff.bin 2026-05-06T07:44:45.014 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-06T07:44:45.014 [RbM] Rollback manager succesfully initialized. 2026-05-06T07:44:45.014 [RbM] Rollback manager EnableRollbackManager called. 2026-05-06T07:44:45.019 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-06T07:44:45.019 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-06T07:44:45.024 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-06T07:44:45.024 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-06T07:44:45.024 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-06T07:44:45.024 MdCoreSvc is supported in this platform and OS 2026-05-06T07:44:45.024 MdCoreSvc is supported in this platform and OS 2026-05-06T07:44:45.024 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-06T07:44:45.024 [PlatUpd] Starting MdCoreSvc service 2026-05-06T07:44:45.064 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-06T07:44:48.578 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-06T07:44:48.578 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-06T07:44:48.578 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-06T07:44:48.578 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-06T07:44:48.578 [PlatUpd] CSP platform update started 2026-05-06T07:44:48.578 [PlatUpd] Defender MDM CSP platform update not required 2026-05-06T07:44:48.578 [PlatUpd] WMI/PS provider platform update started 2026-05-06T07:44:48.578 [PlatUpd] WMI/PS provider platform update not required 2026-05-06T07:44:48.578 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-06T07:44:48.578 MdCoreSvc is supported in this platform and OS 2026-05-06T07:44:48.578 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-06T07:44:48.578 [PlatUpd] Starting MdCoreSvc service 2026-05-06T07:44:48.578 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-06T07:44:48.578 [TS] Troublshooting mode is not available! 2026-05-06T07:44:48.578 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-06T07:44:48.578 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-06T07:44:48.610 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-06T07:44:48.610 [Service] Enabling AutoLoggers ... 2026-05-06T07:44:48.610 [Service] Enabling AMSI registration ... 2026-05-06T07:44:48.610 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-06T07:44:48.625 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 45676 Number of invalid entries is 0 Number of inserts issued is 1578842 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6489 Number of lookups is 107836780 Number of lookup misses is 5176567 Number of fast lookup misses is 54934170 Number of false fast lookups is 5176562 Number of invalidations is 731939 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-06T07:44:48.625 Verifying license file... 2026-05-06T07:44:48.625 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll]. File not in cache (0x1) 2026-05-06T07:44:48.641 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] 2026-05-06T07:44:48.656 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-06T07:44:48.656 Loaded module#0 MpComServer. 2026-05-06T07:44:48.656 Loaded module#1 StartupPolicies. 2026-05-06T07:44:48.656 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-06T07:44:48.672 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-06T07:44:48.672 COM server initialized successfully. 2026-05-06T07:44:48.672 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-06T07:44:48.688 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-06T07:44:48.688 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-06T07:44:48.703 [RTP] [RTP] FilterCommunicator object 0x000001522190AC50 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-06T07:44:48.703 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-06T07:44:48.703 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T07:44:48.703 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T07:44:48.703 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-06T07:44:48.703 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-06T07:44:48.703 [RTP] [RTP] FilterCommunicator object 0x000001522190AE60 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-06T07:44:48.703 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-06T07:44:48.703 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-06T07:44:48.703 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-06T07:44:48.703 [RTP] [RTP] StartCommunication 0x000001522190AC50 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-06T07:44:48.703 [init][RTP] RTPPlugin initialization completed 2026-05-06T07:44:48.703 OS boot count = 2 2026-05-06T07:44:48.703 OS Install = 0 2026-05-06T07:44:48.719 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-06T07:44:48.719 [KSL] Entering CKSLEngine::Initialize. 2026-05-06T07:44:48.719 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-06T07:44:48.719 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-06T07:44:48.719 [KSL] MpInstallKslD: hr=0x1 2026-05-06T07:44:48.719 [KSL] MpRegisterKslD: hr=0 2026-05-06T07:44:48.735 [KSL] MpStartKslD: hr=0 2026-05-06T07:44:48.735 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-06T07:44:48.735 Loading engine... 2026-05-06T07:44:48.735 Verifying engine and signature files (source: 1) ... 2026-05-06T07:44:48.735 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll] due to PPL. 2026-05-06T07:44:48.735 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasbase.vdm]. File not in cache (0x1) 2026-05-06T07:44:49.703 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasbase.vdm] 2026-05-06T07:44:49.703 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-06T07:44:49.735 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasdlta.vdm] 2026-05-06T07:44:49.735 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavbase.vdm]. File not in cache (0x1) 2026-05-06T07:44:50.172 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavbase.vdm] 2026-05-06T07:44:50.172 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-06T07:44:50.188 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpavdlta.vdm] 2026-05-06T07:44:50.235 [Engine] IsHybridMode: 0 2026-05-06T07:44:50.235 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-06T07:44:50.250 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-89822B7411F1DB465033F7E1EE8B390B02057CBC.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-06T07:44:56.469 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-06T07:44:56.469 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_MemScanPassLocalExceptionsToEngine new=0 old1 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-05-06T07:44:56.469 [Engine] New active engine 00007FFD03F98020 (no old engine). Number of active engines: 1 2026-05-06T07:44:56.485 EngineInit:Global ASOC is enabled 2026-05-06T07:44:56.485 EngineInit:ASOO is enabled for developer volumes 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.563 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T07:44:56.610 MpWriteUupSignatureVersion 1.449.476.0, hr = 0 2026-05-06T07:44:56.610 [SigStatUpd] CSignatureStatus: back to good 2026-05-06T07:44:56.610 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-06T07:44:56.625 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-06T07:44:56.625 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T07:44:56.625 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-06T07:44:56.625 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-06T07:44:56.625 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-06T07:44:56.641 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-06T07:44:56.641 [Plugin] Initializing RTP plugin state... 2026-05-06T07:44:56.641 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2046 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11620 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2300 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-06T07:44:56.641 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-06T07:44:56.641 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1} 2026-05-06T07:44:56.641 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:44:56.641 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:44:56.641 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T07:44:56.641 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T07:44:56.641 MdCoreSvc is supported in this platform and OS 2026-05-06T07:44:56.641 Engine loaded! 2026-05-06T07:44:56.641 [DLP] Create FeatureControlState instance 2026-05-06T07:44:56.641 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-06T07:44:56.641 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-06T07:44:56.641 RegisterSModeChangeListener: hr = 0x1 2026-05-06T07:44:56.641 RegisterHybridModeChangeListener: hr = 0 2026-05-06T07:44:56.656 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-06T07:44:56.656 [SigReleaseHb] Initialized with Stage 0 2026-05-06T07:44:56.656 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-06T07:44:56.656 [SCC][CID=27375_5208] Initializing ... 2026-05-06T07:44:56.656 [SCC][CID=27375_5208] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-06T07:44:56.656 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-06T07:44:56.656 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-06T07:44:56.656 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-06T07:44:56.656 [NRI] Stopping NIS service ... 2026-05-06T07:44:56.656 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-06T07:44:56.656 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.476.0 AV Signature Version: 1.449.476.0 ************************************************************ 2026-05-06T07:44:56.672 Resource usage Monitoring is enabled 2026-05-06T07:44:56.672 Job Notification: New process added to job (4408) 2026-05-06T07:44:56.672 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-06T07:44:56.719 Job Notification: New process added to job (6784) 2026-05-06T07:44:56.719 Job Notification: New process added to job (6808) 2026-05-06T07:44:56.719 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:6784] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6808]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-06T07:44:56.735 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-06T07:44:56.750 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-06T07:44:56.750 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-06T07:44:56.750 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-06T07:44:56.750 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-06T07:44:56.750 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T07:44:56.750 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T07:44:56.750 [RTP] Generating the base plugin configuration ... 2026-05-06T07:44:56.750 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-06T07:44:56.750 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:44:56.750 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-06T07:44:56.750 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-06T07:44:56.750 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:44:56.750 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-06T07:44:56.750 [RTP] [RTP] StartCommunication 0x000001522190AE60 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-06T07:44:56.750 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-06T07:44:56.766 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-06T07:44:56.813 Job Notification: Process exited from job (6784) 2026-05-06T07:44:56.813 Job Notification: Process exited from job (6808) 2026-05-06T07:44:56.813 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-06T07:44:57.110 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-06T07:44:57.110 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-06T07:44:57.110 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-06T07:44:57.235 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T07:44:59.813 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:44:59.813 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:44:59.813 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-06T07:44:59.813 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-06T07:44:59.813 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-06T07:45:48.672 Process scan (poststartupscan) started. 2026-05-06T07:45:48.672 Process scan (poststartupscan) completed. 2026-05-06T07:45:49.172 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-06T07:45:49.188 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-06T07:45:51.766 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:45:51.766 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:45:51.766 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-06T07:45:51.766 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-06T07:45:51.766 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-06T07:46:48.719 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T07:46:48.719 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-06T07:46:48.719 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T07:49:56.531 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-06T07:49:56.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T07:54:45.391 [AutoPurge] Cleanup Routine tasks have started. 2026-05-06T07:54:45.438 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-06T07:54:45.438 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-06T07:54:45.438 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-06-2026 07:54:45 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 07:54:45 2026-05-06T07:54:45.500 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-06T07:54:45.500 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-06T07:54:45.500 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-06T07:54:45.500 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-06T07:54:45.500 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-06T07:54:45.516 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:F51E4F71-B196-4F62-9579-67F3AA15DB15, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-06T07:54:45.516 Scheduled scan with Id F51E4F71-B196-4F62-9579-67F3AA15DB15 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-06T07:54:45.516 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-06T07:54:45.516 [SFC] System file cache build is not needed (already completed) 2026-05-06T07:54:45.750 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-06T07:54:45.750 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-06T07:54:45.750 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-06T07:54:45.750 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-06T07:54:45.750 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-06T07:54:45.859 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-05-06T07:54:46.031 Engine:Setting original file name "TeamViewer Installer" for "c:\program files\teamviewer\uninstall.exe", hr=0x800710da 2026-05-06T07:54:46.234 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_cs.dll", hr=0x800710da 2026-05-06T07:54:46.266 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-06T07:54:46.281 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-05-06T07:54:46.375 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #2938, FileId: 0x3f000000062595, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T07:54:46.859 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-06T07:54:47.422 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-06T07:54:47.469 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_hu.dll", hr=0x800710da 2026-05-06T07:54:47.531 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T07:54:47.547 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-06T07:54:47.547 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T07:54:47.578 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-06T07:54:47.594 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-06T07:54:48.453 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-06T07:54:48.625 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-06T07:54:48.844 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-06T07:54:48.859 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-06T07:54:49.141 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-06T07:54:49.203 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-06T07:54:49.266 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-06T07:54:49.453 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-06T07:54:49.641 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-06T07:54:49.797 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-06T07:54:49.953 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-06T07:54:49.969 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:54:49.969 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-06T07:54:50.000 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-06T07:54:50.094 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-06T07:54:50.156 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-06T07:54:50.531 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-06T07:54:50.781 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-06T07:54:50.813 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-06T07:54:51.234 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-06T07:54:51.438 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-06T07:54:51.969 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-06T07:54:52.000 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-06T07:54:52.063 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:54:52.297 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-06T07:54:52.531 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-06T07:54:52.688 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-06T07:54:52.906 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-06T07:54:53.000 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-06T07:54:53.016 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-06T07:54:53.047 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-06T07:54:53.281 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-06T07:54:53.359 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-06T07:54:53.516 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-06T07:54:53.625 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-06T07:54:54.125 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-06T07:54:54.141 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-06T07:54:54.438 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-06T07:54:54.547 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-06T07:54:55.453 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-06T07:54:55.500 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-06T07:54:55.500 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-06T07:54:55.516 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-06T07:54:55.625 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-06T07:54:55.734 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-06T07:54:55.938 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-06T07:54:56.438 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\winsxs\amd64_networking-mpssvc-ui_31bf3856ad364e35_10.0.22000.653_none_73afee5687447108\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-06T07:54:56.672 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-06T07:54:56.672 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-06T07:54:56.781 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 62494846(ms) from now at 03:16 (01:16 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-06T07:54:56.797 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-06T07:54:56.828 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-06T07:54:56.844 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-06T07:54:56.859 Job Notification: New process added to job (8116) 2026-05-06T07:54:56.891 Job Notification: New process added to job (8124) 2026-05-06T07:54:56.891 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-06T07:54:56.906 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:8116] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8124]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-06T07:54:56.922 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-06T07:54:57.016 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-06T07:54:57.016 Job Notification: New process added to job (1404) 2026-05-06T07:54:57.016 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-06T07:54:57.031 Job Notification: New process added to job (4756) 2026-05-06T07:54:57.047 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:1404] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4756]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-06T07:54:57.094 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-06T07:54:57.109 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-06T07:54:57.125 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-06T07:54:57.453 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-05-06T07:54:57.656 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-06T07:54:57.672 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-06T07:54:57.750 Aggressive catchup quick scan threshold: 2571547312952 / 25920000000000 2026-05-06T07:54:57.906 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-06T07:54:57.969 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-06T07:54:58.219 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-06T07:54:58.219 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:54:58.219 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:54:58.219 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-06T07:54:58.219 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:54:58.219 [RTP] No config change detected. Not updating plugin configuration. 2026-05-06T07:54:58.219 [RTP] No config changes found. No configuration switch. 2026-05-06T07:54:58.219 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-06T07:54:58.344 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-06T07:54:58.500 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-06T07:54:58.563 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-06T07:54:58.844 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-06T07:54:58.859 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-06T07:54:59.188 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-06T07:54:59.219 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.lt-lt.dll", hr=0x800710da 2026-05-06T07:54:59.266 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-06T07:54:59.281 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-06T07:54:59.391 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-06T07:54:59.406 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-06T07:54:59.453 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-06T07:54:59.891 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-06T07:54:59.984 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-06T07:55:00.156 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-06T07:55:00.188 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-06T07:55:00.344 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-06T07:55:00.484 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-06T07:55:00.547 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-06T07:55:00.578 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-06T07:55:00.719 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-06T07:55:01.000 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:01.328 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-06T07:55:01.359 Job Notification: Process exited from job (1404) 2026-05-06T07:55:01.375 Job Notification: Process exited from job (4756) 2026-05-06T07:55:01.391 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-06T07:55:01.406 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:01.453 Job Notification: Process exited from job (8116) 2026-05-06T07:55:01.453 Job Notification: Process exited from job (8124) 2026-05-06T07:55:01.484 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:02.188 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:02.281 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:02.609 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-06T07:55:02.656 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-06T07:55:02.828 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-06T07:55:02.938 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-06T07:55:02.984 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-06T07:55:03.000 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-06T07:55:03.359 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-06T07:55:03.438 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-06T07:55:03.516 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-06T07:55:03.609 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-06T07:55:03.625 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-06T07:55:03.719 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-06T07:55:03.859 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-06T07:55:03.953 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-06T07:55:04.031 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-06T07:55:04.063 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-06T07:55:04.078 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-06T07:55:04.281 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-06T07:55:04.281 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-06T07:55:04.438 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-06T07:55:04.938 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-06T07:55:05.188 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-06T07:55:05.250 Engine:Setting original file name "stobject.dll" for "c:\windows\winsxs\amd64_microsoft-windows-stobject_31bf3856ad364e35_10.0.22000.708_none_45a5d433da92062e\stobject.dll.mun", hr=0x800710da 2026-05-06T07:55:05.688 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-06T07:55:05.750 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-06T07:55:05.813 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-06T07:55:05.891 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-06T07:55:06.031 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-06T07:55:06.031 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-06T07:55:06.203 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-06T07:55:06.422 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2615.101.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-05-06T07:55:06.438 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-06T07:55:06.688 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-06T07:55:06.813 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-06T07:55:07.109 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-06T07:55:07.203 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-06T07:55:07.328 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-06T07:55:07.672 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-06T07:55:07.750 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-06T07:55:07.797 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-06T07:55:08.031 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-06T07:55:08.047 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-06T07:55:08.172 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-06T07:55:08.219 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-06T07:55:08.391 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-06T07:55:08.500 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-06T07:55:08.500 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:08.766 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-06T07:55:09.047 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-06T07:55:09.078 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-06T07:55:09.125 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-06T07:55:09.219 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-06T07:55:09.547 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-06T07:55:09.641 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:09.672 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-06T07:55:09.781 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:10.047 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:10.344 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-06T07:55:10.469 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-06T07:55:10.563 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-06T07:55:10.969 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-06T07:55:11.000 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-06T07:55:11.016 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-06T07:55:11.328 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-06T07:55:11.594 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-06T07:55:11.625 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-06T07:55:11.766 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-06T07:55:11.906 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.en-us.dll", hr=0x800710da 2026-05-06T07:55:11.922 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-06T07:55:11.938 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-06T07:55:12.172 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-06T07:55:12.344 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-06T07:55:12.375 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-06T07:55:12.406 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:12.469 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-06T07:55:12.859 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-06T07:55:12.922 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-06T07:55:12.922 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-06T07:55:13.000 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-06T07:55:13.516 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-06T07:55:13.641 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-06T07:55:13.719 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-06T07:55:13.750 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-06T07:55:13.922 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-06T07:55:14.016 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-06T07:55:14.063 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-06T07:55:14.188 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:14.297 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-06T07:55:14.453 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-06T07:55:14.563 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-06T07:55:14.641 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-06T07:55:14.891 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-06T07:55:14.922 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-06T07:55:15.000 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-06T07:55:15.109 Engine:Setting original file name ".NET Host Resolver - 8.0.20" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2604.60161.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-06T07:55:15.781 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-06T07:55:16.297 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-06T07:55:16.328 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-06T07:55:16.391 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-06T07:55:16.438 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-06T07:55:17.063 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-06T07:55:17.500 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-06T07:55:17.563 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-06T07:55:17.750 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-06T07:55:18.000 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-06T07:55:18.047 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-06T07:55:18.375 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-06T07:55:18.453 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-06T07:55:18.531 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-06T07:55:18.563 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-06T07:55:18.672 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-06T07:55:19.109 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_no.dll", hr=0x800710da 2026-05-06T07:55:19.203 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-06T07:55:19.484 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-06T07:55:19.594 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-06T07:55:19.609 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-06T07:55:19.766 Engine:Setting original file name "libVoiceFabric.dll" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2604.60161.0_x64__8wekyb3d8bbwe\voicefabric.dll", hr=0x800710da 2026-05-06T07:55:20.250 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-06T07:55:20.531 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-06T07:55:20.688 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-06T07:55:20.906 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-06T07:55:21.016 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:21.047 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-06T07:55:21.063 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:21.109 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-06T07:55:21.219 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-06T07:55:21.281 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-06T07:55:21.359 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-06T07:55:21.453 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-06T07:55:21.469 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-06T07:55:21.484 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-06T07:55:21.531 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-06T07:55:21.547 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-06T07:55:21.797 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-06T07:55:21.813 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-06T07:55:21.859 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-06T07:55:21.953 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-06T07:55:22.078 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-06T07:55:22.500 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-06T07:55:22.531 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.fr-ca.dll", hr=0x800710da 2026-05-06T07:55:22.781 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-06T07:55:23.063 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-06T07:55:23.219 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-06T07:55:23.297 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:23.484 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-06T07:55:23.813 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-06T07:55:23.891 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-06T07:55:24.078 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-06T07:55:24.172 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-06T07:55:24.688 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-06T07:55:24.750 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-06T07:55:24.797 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-06T07:55:24.828 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-06T07:55:24.828 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-06T07:55:24.891 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-06T07:55:25.188 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-06T07:55:25.203 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-06T07:55:25.406 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sv.dll", hr=0x800710da 2026-05-06T07:55:25.719 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-06T07:55:25.797 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-06T07:55:25.844 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.et-ee.dll", hr=0x800710da 2026-05-06T07:55:26.047 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-06T07:55:26.391 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-06T07:55:26.719 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-06T07:55:26.797 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-06T07:55:26.859 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-06T07:55:27.344 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-06T07:55:27.734 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-06T07:55:28.125 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-06T07:55:28.172 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-06T07:55:28.188 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.sv-se.dll", hr=0x800710da 2026-05-06T07:55:28.422 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-06T07:55:28.766 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-06T07:55:28.859 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-06T07:55:28.906 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-05-06T07:55:29.016 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-06T07:55:29.109 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-06T07:55:29.125 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-06T07:55:29.281 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-05-06T07:55:29.375 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-06T07:55:29.641 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-06T07:55:29.672 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-06T07:55:30.469 Engine:Setting original file name "Microsoft Cognitive Services Speech SDK" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2604.60161.0_x64__8wekyb3d8bbwe\microsoft.cognitiveservices.speech.extension.audio.sys.dll", hr=0x800710da 2026-05-06T07:55:30.469 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-06T07:55:30.766 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-06T07:55:30.875 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:31.000 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-06T07:55:31.438 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-06T07:55:31.547 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-06T07:55:31.609 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-06T07:55:31.656 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-06T07:55:31.719 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-06T07:55:31.734 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:31.875 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-06T07:55:31.953 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-06T07:55:32.063 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-06T07:55:32.125 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-06T07:55:32.234 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:32.359 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-06T07:55:32.703 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-06T07:55:32.781 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-06T07:55:33.016 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-06T07:55:33.250 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-06T07:55:33.359 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-06T07:55:33.797 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-06T07:55:33.891 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-06T07:55:34.219 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-06T07:55:34.609 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-06T07:55:34.797 Engine:Setting original file name "c2rintl.dll" for "c:\program files\common files\microsoft shared\clicktorun\c2rintl.it-it.dll", hr=0x800710da 2026-05-06T07:55:35.063 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-06T07:55:35.391 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-05-06T07:55:35.531 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-06T07:55:35.672 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-06T07:55:36.250 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-06T07:55:36.484 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-06T07:55:36.500 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-06T07:55:36.594 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:36.734 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-06T07:55:36.750 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-06T07:55:37.563 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-06T07:55:37.609 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-06T07:55:37.688 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-06T07:55:37.984 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-06T07:55:38.016 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-05-06T07:55:38.250 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-06T07:55:38.344 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-06T07:55:38.391 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-06T07:55:38.406 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-06T07:55:38.563 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-06T07:55:39.344 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-06T07:55:39.594 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-06T07:55:39.609 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:39.656 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-06T07:55:39.891 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-06T07:55:40.000 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-06T07:55:40.344 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-06T07:55:40.344 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-06T07:55:40.344 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-06T07:55:40.609 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-06T07:55:40.781 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-06T07:55:41.359 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-06T07:55:41.500 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-06T07:55:41.625 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-06T07:55:41.656 Engine:Setting original file name "TWINUI.dll" for "c:\windows\winsxs\amd64_microsoft-windows-twinui_31bf3856ad364e35_10.0.22000.2538_none_ecbf26dcf11a684d\twinui.dll.mun", hr=0x800710da 2026-05-06T07:55:41.703 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-06T07:55:42.234 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:42.859 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-06T07:55:42.891 Engine:Setting original file name "_Project Import.exe" for "c:\program files\microsoft office\root\office16\projimpt.exe", hr=0x800710da 2026-05-06T07:55:43.016 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-06T07:55:43.063 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-06T07:55:43.281 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-shell32_31bf3856ad364e35_10.0.22000.2482_none_e551341849a7f566\shell32.dll.mun", hr=0x800710da 2026-05-06T07:55:43.344 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-06T07:55:43.453 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-06T07:55:43.531 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-06T07:55:43.719 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-06T07:55:43.734 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-05-06T07:55:43.766 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-06T07:55:43.938 Engine:Setting original file name "apisetstub" for "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-utility-l1-1-0.dll", hr=0x800710da 2026-05-06T07:55:43.953 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-06T07:55:44.016 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-06T07:55:44.094 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-06T07:55:44.125 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-06T07:55:44.141 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-06T07:55:44.531 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-06T07:55:44.719 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-06T07:55:44.781 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-06T07:55:44.813 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-06T07:55:45.125 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-06T07:55:45.250 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-06T07:55:45.266 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-06T07:55:45.281 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-06T07:55:45.656 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-06T07:55:46.063 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-06T07:55:46.172 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-05-06T07:55:46.297 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-05-06T07:55:46.422 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-06T07:55:46.500 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-05-06T07:55:46.672 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-05-06T07:55:46.781 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-05-06T07:55:46.922 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-05-06T07:55:47.063 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-05-06T07:55:47.109 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-05-06T07:55:47.141 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-05-06T07:55:47.438 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-05-06T07:55:47.516 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-05-06T07:55:47.531 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-05-06T07:55:47.547 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-06T07:55:47.938 OriginalFileName Maintenance::10067 files in Moac, 244 skipped (cached), 1 filename set 2026-05-06T07:55:47.938 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-06T07:55:50.938 Engine:Triggered AR EMS scan 2026-05-06T07:55:50.938 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.953 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.969 Engine:EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.984 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.984 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.984 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:50.984 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.000 Engine:EMS scan for process: svchost pid: 1356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.000 Engine:EMS scan for process: svchost pid: 1372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.000 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.000 Engine:EMS scan for process: svchost pid: 1468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.016 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.016 Engine:EMS scan for process: svchost pid: 1540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.016 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.031 Engine:EMS scan for process: svchost pid: 1828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2312, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.047 Engine:EMS scan for process: svchost pid: 2348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.063 Engine:EMS scan for process: svchost pid: 2864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.078 Engine:EMS scan for process: svchost pid: 2960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.078 Engine:EMS scan for process: svchost pid: 3032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.094 Engine:EMS scan for process: svchost pid: 3116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.094 Engine:EMS scan for process: svchost pid: 3384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.094 Engine:EMS scan for process: svchost pid: 3392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.094 Engine:EMS scan for process: svchost pid: 3512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.109 Engine:EMS scan for process: svchost pid: 3540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.109 Engine:EMS scan for process: svchost pid: 3560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.125 Engine:EMS scan for process: svchost pid: 3576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.125 Engine:EMS scan for process: svchost pid: 4008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.125 Engine:EMS scan for process: svchost pid: 3288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.141 Engine:EMS scan for process: svchost pid: 3304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.141 Engine:EMS scan for process: svchost pid: 3420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.141 Engine:EMS scan for process: svchost pid: 4128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.156 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.156 Engine:EMS scan for process: svchost pid: 4312, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.156 Engine:EMS scan for process: svchost pid: 4340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.156 Engine:EMS scan for process: svchost pid: 4416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: svchost pid: 4892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: svchost pid: 5884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: svchost pid: 5984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: dllhost pid: 4656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: svchost pid: 6636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.172 Engine:EMS scan for process: svchost pid: 6644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.188 Engine:EMS scan for process: svchost pid: 6752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.188 Engine:EMS scan for process: svchost pid: 6248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.188 Engine:EMS scan for process: svchost pid: 3752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.188 Engine:EMS scan for process: svchost pid: 7128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.203 Engine:EMS scan for process: svchost pid: 856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.203 Engine:EMS scan for process: svchost pid: 5204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.203 Engine:EMS scan for process: svchost pid: 6708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.203 Engine:EMS scan for process: svchost pid: 6364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.219 Engine:EMS scan for process: svchost pid: 1892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.219 Engine:EMS scan for process: svchost pid: 5288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.219 Engine:EMS scan for process: svchost pid: 5124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.219 Engine:EMS scan for process: svchost pid: 3452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.219 Engine:EMS scan for process: svchost pid: 5524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.234 Engine:EMS scan for process: svchost pid: 4788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.234 Engine:EMS scan for process: svchost pid: 4932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.234 Engine:EMS scan for process: svchost pid: 2404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.234 Engine:EMS scan for process: svchost pid: 2252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.234 Engine:EMS scan for process: svchost pid: 3296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.250 Engine:EMS scan for process: svchost pid: 7380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:55:51.250 Engine:EMS scan for process: svchost pid: 3292, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-06T07:56:01.813 [RTP] [Mini-filter] OpenWithoutRead notification (557, 16281, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-06T07:56:24.406 ExpensiveFile:Scan time for `\\?\C:\Program Files\Microsoft Office\root\Office16\livecapture.bundle` is 9109 units 2026-05-06T07:57:35.172 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21929, FileId: 0x17000000039a4f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T07:57:39.375 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #21946, FileId: 0xb0000000b650b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T07:57:41.703 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-05-06T07:57:41.703 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-05-06T07:57:41.703 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:57:41.703 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:57:41.703 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-06T07:57:41.703 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-06T07:57:41.703 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-06T07:57:43.016 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-05-06T07:57:43.110 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-05-06T07:57:55.172 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-05-06T07:57:55.953 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-05-06T07:58:50.000 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #24481, FileId: 0x125000000016a3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T07:59:54.766 QuickScan:ScanID:F51E4F71-B196-4F62-9579-67F3AA15DB15: Quick scan finished with error 0 2026-05-06T07:59:55.281 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-06T07:59:55.281 [RTP] Duplicating the current plugin configuration object... 2026-05-06T07:59:55.281 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-06T07:59:55.281 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-06T07:59:55.281 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T07:59:55.281 [RTP] No config change detected. Not updating plugin configuration. 2026-05-06T07:59:55.281 [RTP] No config changes found. No configuration switch. 2026-05-06T07:59:55.281 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-06T07:59:56.797 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T07:59:56.797 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-06T07:59:56.813 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-06T08:00:59.235 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #24569, FileId: 0x1a00000001a94c, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T08:01:00.469 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-05-06T08:01:00.594 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-05-06T08:01:00.610 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-05-06T08:01:07.969 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{0CF51F3A-BAE8-40E1-B752-105690C0466D}{69ff0a0f-491f-11f1-a180-d850e63fb470}.TM.blf. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #25322, FileId: 0x2300000001ab45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T08:01:07.969 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{0CF51F3A-BAE8-40E1-B752-105690C0466D}{69ff0a0f-491f-11f1-a180-d850e63fb470}.TMContainer00000000000000000002.regtrans-ms. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #25321, FileId: 0x1800000001ab5e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-06T08:05:01.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T08:20:06.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T08:35:11.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T08:44:56.656 [RbM] Audited automatic rollback of Platform 0x4001265ae0bc3 --> 0x4001265a40006. hr = 0 2026-05-06T08:50:16.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T09:05:21.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T09:20:26.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T09:35:31.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T09:44:56.483 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T09:44:56.483 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T09:44:56.483 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T09:44:56.483 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T09:44:56.483 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T09:44:56.483 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T09:44:56.483 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T09:44:56.483 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 499, Count: 43, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T09:44:56.483 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T09:44:56.483 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 165, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T09:44:56.483 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T09:44:56.483 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T09:44:56.483 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T09:44:56.483 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T09:44:56.483 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T09:44:56.483 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T09:44:56.483 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T09:44:56.483 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T09:44:56.483 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T09:44:56.483 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T09:50:36.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T10:05:41.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T10:20:46.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T10:35:51.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T10:50:56.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T11:06:01.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T11:21:06.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T11:36:11.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T11:44:56.498 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T11:44:56.498 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T11:44:56.498 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T11:44:56.498 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T11:44:56.498 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T11:44:56.498 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 559, Count: 47, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T11:44:56.498 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T11:44:56.498 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T11:44:56.498 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 165, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T11:44:56.498 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T11:44:56.498 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T11:44:56.498 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 7, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T11:44:56.498 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T11:44:56.498 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T11:44:56.498 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T11:44:56.498 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T11:44:56.498 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: dllhost.exe, Pid: 4656, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T11:44:56.498 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T11:44:56.498 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T11:51:16.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T12:06:21.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T12:21:26.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T12:36:31.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T12:51:36.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T13:06:41.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T13:21:46.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T13:36:51.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T13:44:56.512 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T13:44:56.512 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T13:44:56.512 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T13:44:56.512 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T13:44:56.512 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T13:44:56.512 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 574, Count: 51, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T13:44:56.512 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T13:44:56.512 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T13:44:56.512 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 165, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T13:44:56.512 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T13:44:56.512 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T13:44:56.512 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 9, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T13:44:56.512 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T13:44:56.512 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T13:44:56.512 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T13:44:56.512 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T13:44:56.512 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: dllhost.exe, Pid: 4656, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T13:44:56.512 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T13:44:56.512 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T13:51:56.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T14:07:01.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T14:22:06.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T14:37:11.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T14:52:16.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T15:07:21.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T15:22:26.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T15:37:31.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T15:44:56.526 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T15:44:56.526 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T15:44:56.526 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T15:44:56.526 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T15:44:56.526 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T15:44:56.526 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 604, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T15:44:56.526 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T15:44:56.526 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T15:44:56.526 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 165, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T15:44:56.526 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T15:44:56.526 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T15:44:56.526 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 11, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T15:44:56.526 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T15:44:56.526 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T15:44:56.526 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T15:44:56.526 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T15:44:56.526 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: dllhost.exe, Pid: 4656, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T15:44:56.526 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T15:44:56.526 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T15:52:36.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T16:07:41.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T16:22:46.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T16:37:51.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T16:52:56.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T17:08:01.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T17:23:06.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T17:38:11.913 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T17:44:56.852 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T17:44:56.852 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T17:44:56.852 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T17:44:56.852 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T17:44:56.852 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T17:44:56.852 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 604, Count: 55, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T17:44:56.852 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T17:44:56.852 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 210, Count: 48, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T17:44:56.852 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T17:44:56.852 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T17:44:56.852 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T17:44:56.852 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T17:44:56.852 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 13, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T17:44:56.852 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T17:44:56.852 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T17:44:56.852 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T17:44:56.852 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T17:44:56.852 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: dllhost.exe, Pid: 4656, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T17:44:56.852 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T17:44:56.852 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T17:53:17.006 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T18:08:22.076 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T18:23:27.128 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T18:38:32.167 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T18:53:37.196 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T19:08:42.217 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T19:23:47.232 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T19:38:52.244 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-06T19:44:57.138 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T19:44:57.138 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T19:44:57.138 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T19:44:57.138 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T19:44:57.138 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T19:44:57.138 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 634, Count: 59, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T19:44:57.138 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 512, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\f698fa4dd9a6dfc2da42b4a12e71e53e5be612fc\content.phf, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: powershell.exe, Pid: 7308, TotalTime: 384, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 16% 2026-05-06T19:44:57.138 ProcessImageName: dasHost.exe, Pid: 5268, TotalTime: 225, Count: 56, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 202, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpengine.dll, EstimatedImpact: 100% 2026-05-06T19:44:57.138 ProcessImageName: ngentask.exe, Pid: 7272, TotalTime: 180, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 3% 2026-05-06T19:44:57.138 ProcessImageName: ngentask.exe, Pid: 7244, TotalTime: 165, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-06T19:44:57.138 ProcessImageName: ngentask.exe, Pid: 7288, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: vc_redist.x64.exe, Pid: 2984, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{48B43274-462A-46E9-8CFB-582C41FDF0D1}\.ba\1031\thm.wxl, EstimatedImpact: 48% 2026-05-06T19:44:57.138 ProcessImageName: ngentask.exe, Pid: 1148, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 2% 2026-05-06T19:44:57.138 ProcessImageName: , Pid: 4, TotalTime: 121, Count: 11, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: OfficeClickToRun.exe, Pid: 5660, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: dllhost.exe, Pid: 4656, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: AggregatorHost.exe, Pid: 5304, TotalTime: 93, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 2348, TotalTime: 93, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: OfficeC2RClient.exe, Pid: 3476, TotalTime: 91, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\1EF92BB4-6E4B-45D9-BD9A-9933675E0907, EstimatedImpact: 3% 2026-05-06T19:44:57.138 ProcessImageName: dllhost.exe, Pid: 2836, TotalTime: 90, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{27bada35-0225-4fed-a34e-891258af73ad}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: RUXIMICS.exe, Pid: 6712, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Logs\PLUG\RUXIMLog.002.etl, EstimatedImpact: 48% 2026-05-06T19:44:57.138 ProcessImageName: taskhostw.exe, Pid: 2880, TotalTime: 76, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-06T19:44:57.138 ProcessImageName: vc_redist.x86.exe, Pid: 3248, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 32% 2026-05-06T19:44:57.138 ProcessImageName: tzsync.exe, Pid: 4528, TotalTime: 61, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezoneMapping.xml, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: spoolsv.exe, Pid: 3724, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\SendToOneNote.gpd, EstimatedImpact: 20% 2026-05-06T19:44:57.138 ProcessImageName: taskhostw.exe, Pid: 3584, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 5288, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\OfficeC2RA56567BF-31C3-438A-8E74-83EA8EAA149A\BITBD6F.tmp, EstimatedImpact: 3% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 1124, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: OfficeC2RClient.exe, Pid: 5116, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: OfficeC2RClient.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0954a.log, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: OfficeC2RClient.exe, Pid: 2128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260506-0957a.log, EstimatedImpact: 1% 2026-05-06T19:44:57.138 ProcessImageName: svchost.exe, Pid: 7108, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\aimgr.msix, EstimatedImpact: 0% 2026-05-06T19:44:57.138 ProcessImageName: brynhildr.exe, Pid: 4080, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-06T19:48:59.359 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\17749C8B-69E9-48DB-9D5F-8DABFB4679381df0.1dcdd916088a693 2026-05-06T19:48:59.453 Verifying engine and signature files (source: 0) ... 2026-05-06T19:48:59.453 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpengine.dll] due to PPL. 2026-05-06T19:48:59.453 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasbase.vdm] (file in cache) 2026-05-06T19:48:59.453 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-06T19:48:59.484 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasdlta.vdm] 2026-05-06T19:48:59.484 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpavbase.vdm] (file in cache) 2026-05-06T19:48:59.484 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-06T19:48:59.500 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpavdlta.vdm] 2026-05-06T19:48:59.672 [Engine] IsHybridMode: 0 2026-05-06T19:48:59.672 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-06T19:48:59.672 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-71DE8F10C0D6F2ADE58B96A652D8413959FD9A49.bin): 0x00000002 2026-05-06T19:48:59.687 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-71DE8F10C0D6F2ADE58B96A652D8413959FD9A49.bin) 2026-05-06T19:48:59.687 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-06T19:48:59.687 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-06T19:48:59.687 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-06T19:48:59.687 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-06T19:49:11.593 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-06T19:49:11.593 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-05-06T19:49:11.625 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFD03F98020, lRefCount: 5, hr=0 2026-05-06T19:49:11.625 [Engine] New active engine 00007FFCFBB18020 replacing engine 00007FFD03F98020. Number of active engines: 2 2026-05-06T19:49:11.625 EngineInit:Global ASOC is enabled 2026-05-06T19:49:11.625 EngineInit:ASOO is enabled for developer volumes 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.687 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-06T19:49:11.703 MpWriteUupSignatureVersion 1.449.477.0, hr = 0 2026-05-06T19:49:11.703 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-06T19:49:11.718 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-06T19:49:11.718 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-06T19:49:11.718 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-06T19:49:11.718 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-06T19:49:11.718 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-06T19:49:11.734 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-06T19:49:11.734 [Plugin] Initializing RTP plugin state... 2026-05-06T19:49:11.734 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-06T19:49:11.734 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎06‎-‎2026 09:44:56 Last Perf:‎05‎-‎06‎-‎2026 09:44:56 First RTP Scan:‎05‎-‎06‎-‎2026 09:44:56 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2643 Misses:23491 BM Queue:0,26,0 Proc:0,25,0 File:0,19,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:28682 Pending:0 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:286334852 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:16 TotalStreamCon:26169 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:59204 TotalHits:347050 InstanceCacheInserts:1750 InstanceCacheUpdates:0 InstanceCacheDeletes:452 InstanceCacheHits:48 InstanceCacheMisses:30912 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (968/440) Success: 440, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-06T19:49:11.734 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA} 2026-05-06T19:49:11.734 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-06T19:49:11.734 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D86F1427-866C-4D52-8854-8BCBC655361B} removed 2026-05-06T19:49:11.734 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FF18BFFD-1C91-4F08-905E-B27F3F3B39D1}\mpasbase.vdm in use, hr=0x80070020 2026-05-06T19:49:11.734 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.734 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.734 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.734 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.734 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-06-2026 19:49:11 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-06-2026 19:49:11 2026-05-06T19:49:11.750 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-06T19:49:11.750 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-06T19:49:11.750 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T19:49:11.750 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-06T19:49:11.750 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-06T19:49:11.750 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.750 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.750 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.750 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-06T19:49:11.750 MdCoreSvc is supported in this platform and OS Signature updated on 05-06-2026 19:49:11 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.477.0 AV Signature Version: 1.449.477.0 ************************************************************ 2026-05-06T19:49:11.750 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-06T19:49:11.750 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\17749C8B-69E9-48DB-9D5F-8DABFB4679381df0.1dcdd916088a693 2026-05-06T19:49:11.765 Process scan (postsignatureupdatescan) started. 2026-05-06T19:49:11.828 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-06T19:49:11.843 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-06T19:49:12.156 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-06T19:49:12.156 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-06T19:49:12.156 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-06T19:49:12.156 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-06T19:49:12.156 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-06T19:49:12.156 [Engine] Engine 00007FFD03F98020 no longer in use. Number of active engines: 1 2026-05-06T19:49:12.156 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-06T19:49:12.156 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-06T19:49:12.203 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-06T19:49:12.203 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-06T19:49:12.203 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-06T19:49:12.312 ProcessImageName: SrTasks.exe, Pid: 7800, TotalTime: 3330, Count: 391, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2, EstimatedImpact: 44% 2026-05-06T19:49:12.312 ProcessImageName: Integrator.exe, Pid: 6212, TotalTime: 2373, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\Professional2021R_Trial-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 11% 2026-05-06T19:49:12.312 ProcessImageName: OfficeClickToRun.exe, Pid: 3080, TotalTime: 1757, Count: 127, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20106\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-05-06T19:49:12.312 ProcessImageName: DeviceCensus.exe, Pid: 3756, TotalTime: 1451, Count: 6, MaxTime: 765, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 37% 2026-05-06T19:49:12.312 ProcessImageName: OfficeClickToRun.exe, Pid: 7424, TotalTime: 1099, Count: 28, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-05-06T19:49:12.312 ProcessImageName: wevtutil.exe, Pid: 964, TotalTime: 843, Count: 2, MaxTime: 828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 65% 2026-05-06T19:49:12.312 ProcessImageName: AddInUtil.exe, Pid: 7872, TotalTime: 744, Count: 14, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 44% 2026-05-06T19:49:12.312 ProcessImageName: svchost.exe, Pid: 1468, TotalTime: 664, Count: 61, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe, EstimatedImpact: 0% 2026-05-06T19:49:12.312 ProcessImageName: WmiPrvSE.exe, Pid: 4536, TotalTime: 662, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 83% 2026-05-06T19:49:12.312 ProcessImageName: wevtutil.exe, Pid: 8152, TotalTime: 546, Count: 2, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 61% 2026-05-06T19:49:12.312 ProcessImageName: Integrator.exe, Pid: 3556, TotalTime: 516, Count: 60, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-13-2026 12:34:42 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/13/2026 12:34:42.71688700 UTC (19781 ms since boot) 2026-05-13T12:34:42.080 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-13T12:34:42.088 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:34:42.088 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:34:42.241 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260513-123442-00000003-fffffffeffffffff.bin ... 2026-05-13T12:34:42.343 [WPP] Trace session started - MpWppTracing-20260513-123442-00000003-fffffffeffffffff.bin 2026-05-13T12:34:42.348 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-13T12:34:42.348 [RbM] Rollback manager succesfully initialized. 2026-05-13T12:34:42.348 [RbM] Rollback manager EnableRollbackManager called. 2026-05-13T12:34:42.353 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-13T12:34:42.358 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 2026-05-13T12:34:42.358 MpWriteUupPlatformVersion 4.18.26030.3011, hr = 0 2026-05-13T12:34:42.358 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-13T12:34:42.363 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-13T12:34:42.368 MdCoreSvc is supported in this platform and OS 2026-05-13T12:34:42.368 MdCoreSvc is supported in this platform and OS 2026-05-13T12:34:42.368 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T12:34:42.368 [PlatUpd] Starting MdCoreSvc service 2026-05-13T12:34:42.423 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0" 2026-05-13T12:34:45.954 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-13T12:34:45.954 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-13T12:34:45.954 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-13T12:34:45.954 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-13T12:34:45.954 [PlatUpd] CSP platform update started 2026-05-13T12:34:45.954 [PlatUpd] Defender MDM CSP platform update not required 2026-05-13T12:34:45.954 [PlatUpd] WMI/PS provider platform update started 2026-05-13T12:34:45.954 [PlatUpd] WMI/PS provider platform update not required 2026-05-13T12:34:45.954 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-13T12:34:45.954 MdCoreSvc is supported in this platform and OS 2026-05-13T12:34:45.954 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T12:34:45.954 [PlatUpd] Starting MdCoreSvc service 2026-05-13T12:34:45.954 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-13T12:34:45.954 [TS] Troublshooting mode is not available! 2026-05-13T12:34:45.954 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T12:34:45.954 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-13T12:34:45.985 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-13T12:34:45.985 [Service] Enabling AutoLoggers ... 2026-05-13T12:34:45.985 [Service] Enabling AMSI registration ... 2026-05-13T12:34:45.985 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-13T12:34:46.000 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 46001 Number of invalid entries is 0 Number of inserts issued is 1579570 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6496 Number of lookups is 107910426 Number of lookup misses is 5181209 Number of fast lookup misses is 54979433 Number of false fast lookups is 5181204 Number of invalidations is 732341 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-13T12:34:46.000 Verifying license file... 2026-05-13T12:34:46.000 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\msmplics.dll] (file in cache) 2026-05-13T12:34:46.000 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-13T12:34:46.016 Loaded module#0 MpComServer. 2026-05-13T12:34:46.016 Loaded module#1 StartupPolicies. 2026-05-13T12:34:46.016 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T12:34:46.016 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T12:34:46.016 COM server initialized successfully. 2026-05-13T12:34:46.016 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-13T12:34:46.032 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll ... 2026-05-13T12:34:46.032 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\mprtp.dll] due to PPL. 2026-05-13T12:34:46.047 [RTP] [RTP] FilterCommunicator object 0x0000021B1D88C240 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T12:34:46.047 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-13T12:34:46.047 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:34:46.047 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:34:46.047 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-13T12:34:46.047 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-13T12:34:46.047 [RTP] [RTP] FilterCommunicator object 0x0000021B1D89B9A0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T12:34:46.047 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-13T12:34:46.047 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-13T12:34:46.047 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-13T12:34:46.047 [RTP] [RTP] StartCommunication 0x0000021B1D88C240 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T12:34:46.047 [init][RTP] RTPPlugin initialization completed 2026-05-13T12:34:46.047 OS boot count = 2 2026-05-13T12:34:46.047 OS Install = 0 2026-05-13T12:34:46.063 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-13T12:34:46.063 [KSL] Entering CKSLEngine::Initialize. 2026-05-13T12:34:46.063 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-13T12:34:46.063 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-13T12:34:46.063 [KSL] MpInstallKslD: hr=0x1 2026-05-13T12:34:46.063 [KSL] MpRegisterKslD: hr=0 2026-05-13T12:34:46.063 [KSL] MpStartKslD: hr=0 2026-05-13T12:34:46.063 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T12:34:46.063 Loading engine... 2026-05-13T12:34:46.079 Verifying engine and signature files (source: 1) ... 2026-05-13T12:34:46.079 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpengine.dll] due to PPL. 2026-05-13T12:34:46.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasbase.vdm] (file in cache) 2026-05-13T12:34:46.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasdlta.vdm] (file in cache) 2026-05-13T12:34:46.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpavbase.vdm] (file in cache) 2026-05-13T12:34:46.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpavdlta.vdm] (file in cache) 2026-05-13T12:34:46.125 [Engine] IsHybridMode: 0 2026-05-13T12:34:46.125 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-13T12:34:46.157 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-71DE8F10C0D6F2ADE58B96A652D8413959FD9A49.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-13T12:34:53.063 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-13T12:34:53.063 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_EnableIpV6Reporting new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-05-13T12:34:53.063 [Engine] New active engine 00007FFDF34A8020 (no old engine). Number of active engines: 1 2026-05-13T12:34:53.079 EngineInit:Global ASOC is enabled 2026-05-13T12:34:53.079 EngineInit:ASOO is enabled for developer volumes 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.157 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a37ea34390297f37bd8babffa23b92908ec9666c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae7f01fea3c6bf358dd91cbe01aa4dc093eb7ba5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\64bff40ec98c3b3fd369ff52000b89bd43b57cf5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\788d3a9ca7c5d6e99ba1b4cc20cb37de0d864e4c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\524fb2b3d96687376a8913d40996d16b8cec431c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:31 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3d75a6cf878a7ee62a5edf539662344805278263 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:31 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e15df8806d3440074d0418d2ec7390f362977f56 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6327ac39779aea9af7c9d0c918328196857593c8 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\214c1a3f8a698565a1029f30e60865fba73e9b6c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fb81bf1c339b9e3b160a219505f0944a48b1aacb Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5cbcc272052ff0eeb292e4a97e5f7ebc0f96b0c8 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.172 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9737ad241e76c23ed8cfb9ee33032ee3913f039b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\afde081964bfd3a6b88a4da92377919b4ef700dc Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f2b60685a96526c021d1caa8f1a78c5d8e19ccf6 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\034f60842adaed83189cf99482259be99836cc56 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe71bd66759359e8c64560666e59a3abd5edab58 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3063d8dd7adee2d946e0c002d3f2198872dbb599 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0c4fdd98f53695a914effd18ccad4af9057a79e9 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1f9af6a92074546f32369f25e6494ac9c7b03fbe Dynamic Signature Compilation Timestamp:05-01-2026 15:18:35 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6bb1155d754f3dd1ee70cd6c814db7379aef447 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\66d5d4220d590ef8181fb06b18ebf66f766e5058 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d54ae1180575335e42922a4ecc31680835039b82 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:36 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d1ec32751554919a0e7dd28581fcf8c211d62432 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ed6c9b5dcdf0fb706bf704054e5a7bbb2b876135 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a60ac1c93680e494eb8c480f3e10398993cfb023 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:37 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\10572034e7a43a04967c2024cb341e217fee782b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d48d817a0322726c8ee544bc93cfc5b361fc682e Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\623fddf1a6e45c1657d4013daeff2820c36e2a22 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:38 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\67b12f856f3790544fd1553b98de4b8c6491ee80 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\42ef781589943a96c36643e6f0bad717c550814b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\40991564c4980609dfff134c7fa2f8a7b8b9c14a Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e9fd7cb314a47c9354f38e23d6367c3a20c9c16 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:39 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1080f5be4166797b60a9b3f441b7778fc7050ed5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:40 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\91ce7360f8e948baa72327c7ef52d20edd7939c1 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:40 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2877a173e1a2bcfe48d9a1e55578d151eeb264a2 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:41 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b0b0940bf02bce066c8f2aae5ac34c56e6b35f98 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:41 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\328d988b0a35d385adb0364f540ce762ee70989b Dynamic Signature Compilation Timestamp:05-01-2026 15:18:42 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\278301b479b7f8af9e8b33dfc1847c9bbd08dc16 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:42 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3185471581d590ab54b81875218951913fa9b793 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:44 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\20dcb3cef9e1da7fc9553f4b951cf42a3d158f7c Dynamic Signature Compilation Timestamp:05-01-2026 15:18:44 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdd5dee32910baf7706a17de1a789a9851a78132 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e47e396fc34943ff48b72ceaf56b28a577b0ee5 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.188 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ac96b8789ce01b499e962452cf245b68a8d5246 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:45 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cedbd927b0682953fe759c910459f136fe93c8c7 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:46 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\abb410a5870e36b1a7b3f4bc13245cd04dd8e253 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:46 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b4b8db705bbffce93b0d96ed57244e0a58612995 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a4b8dd1b4a818f8a7b29b7adccb91f6dc0671f74 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\09bc755c2b4eb96136c423482b1ecb1dae6fc811 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\851646e93aafacd5ac3d7444d170d70880dfbaa1 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:58 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\067e1b9d1540852306b0b3571494e407ddd004d9 Dynamic Signature Compilation Timestamp:05-01-2026 15:18:58 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5708fd1a12610220658c23b5fc37f278f3e56b5f Dynamic Signature Compilation Timestamp:05-01-2026 15:18:59 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c5c6fb2d1730f84bf96d2a1efa7c43f648d0a75c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:14 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5ea79242865383ab7546c68307722879f9fbae4b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5af73969736c0694242f883c497bed6a45cc6ec9 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0843e22d8ae59a1b6fb12c4991bc898d0c93276d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cb3c701d7a5fd32506264b4b77f6bdaa00ad13b6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:15 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\05300957d37ba6ba01d556379cc5003ea6e7881a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:16 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\da8d0872d91d52f4151e896cac044a2121a2d5ca Dynamic Signature Compilation Timestamp:05-01-2026 16:56:16 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2bd5c584cd7177ba6f6ab17fa445145a73fa59a3 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6d17bc9db58fa9ad3d492762817a54992f1057d5 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e77b3708bb2d2b48afb5f38ec82655205b356e27 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:17 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f6e74aa1c22a25b6dfb3dbf90d1740051c68e085 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7d05456d7f3c28fe53b535de4e15248b7c911f6c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d1284d96ff183882f7d8b7514ddafdcc0db67b0d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:18 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ec84c9ae477733046bbe2eb96adc17a61e1d23c4 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f69451f681a9a63534f982dab57744801ed5fce Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\33184f2134a668f9b702c4b7c8d91961ccacf62a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:19 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\77c439db3a0b61bb6c667b0fee96e3a8e557ef83 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6930aeee137f7bd735fb62f8ef8766f732c6e99b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3e54a4bdfe8d32951a51ff0ad3c82d95716c57df Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f61bb28f7e1d7666bbe7e906f4d2655918d12aee Dynamic Signature Compilation Timestamp:05-01-2026 16:56:20 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.204 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75d90c56c528a95a6523c7efbe685642055302c6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7fd2045f78a4b50cfbe9ddbbd598df0c7008b8f1 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5e2e1f1aa1104232ac58e8dacc97104081b208f8 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:21 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2542a558a721f424fdf4b1258e2ff66fdd7ae2ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\85184316dbaf249fa90b13912f97f0191cf6354b Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cf83d18a3de5abcdd2d20529f1f44d88abf97b09 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:22 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd0fa8cc26e5cc1a5531a39f1af5c6aa99f6faa5 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ecd8d855f607ab21d12a76f70a26e2c289a75488 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\624a8e51d4e4ce4b1302c8494b7008a1e671ed9f Dynamic Signature Compilation Timestamp:05-01-2026 16:56:23 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\144b2a1f16b4c727c2d7ee42609ead3ad072894a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1cbfe3d3f11f17f2a08ee11cc25a8a630dab115 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\df24c6b3317a436207734c2a106400f0fa3f43d6 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:24 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e6a425020624e392f4bbd14b922d402376d89b3e Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d2c0257256978d35c1d4d2faacabc66e2affb602 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\70a17dce5911e857ba45df620b908b2dbe341800 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:25 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9393c1eb9c274f450e6528f75a9a199c3e57b11d Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\faeee822267c626d1eab21ce8d60aab4d8271758 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a77c65dfe96d3bddc5868d05a9b75027071450bf Dynamic Signature Compilation Timestamp:05-01-2026 16:56:26 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\78f67d01e4c856736d870f499aa3403812fc9a74 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:27 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7cdc67c7eb6588c3f62b533eecb969c07a60e460 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:28 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c3c4f384515bb6245b92d875fac64360e6fd77a3 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:29 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\937b1563c0503cd44c601fd0a75bdf759144a7ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:29 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e220e26819db38a2006c6fe6ed0a73c2f0859930 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9836eb86eccff9ea015d97ff7720b1dad83fd20a Dynamic Signature Compilation Timestamp:05-01-2026 16:56:30 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ed2fead095710bbebb877aa5e6bbcfbd861a5297 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:31 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\12000b12e54e13427dc525bd749898dae1d3b7bc Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b8013051e3ef55dcfb2374dfb288c192ec454ed Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\99fe86ebd901811f983df57371318b2d999f32d1 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:32 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\220f9e94e0232e0952d8510fb420210b415c5267 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2e637667c7ae066652721bbe38a0d6c4780aeed7 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9e298fd1d3e6f545821019ff382f870a6a90736c Dynamic Signature Compilation Timestamp:05-01-2026 16:56:33 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4c12a83d286b4d8766026ac9d26d44f86df6a3ab Dynamic Signature Compilation Timestamp:05-01-2026 16:56:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6316050beafada0c0ee877e0e5cabfbe5f454472 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:34 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\be984154fb4f22b176da3f59b73274acb449fcec Dynamic Signature Compilation Timestamp:05-01-2026 17:46:42 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4dea43befcd640198d6d2e2cef7c0aa50ed699f8 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:42 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5472eaaf57da8da157d1f038c222b55b29db1720 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b68054b66dd526d400031637c719e07390fecc21 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\95eeaaa65ea12eda89faf066823698a8378b5f2b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:43 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.219 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\38cf7431bdcf8de4bf5b013442129fdc24f08805 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:44 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e1f61e87c43432a4861c7970aa0fcdf675e2e359 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:44 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\542e1bd888de7bf100c715e8922291fb95193c6d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\631c4e4a8b504f4ab4a454450311419d2178298d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\772b3247d836beb22bf77b2cf472092b3bd696f4 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d8660b33b1796fbf6000097782cce2e0a5352630 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:45 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7f1e7683a50152312e34fcd83953be63e3778ad Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\90372607743180a40db1ac976e950e17c0daa663 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31ddbf1cf02bcfa3f2ca4ee8ad6bf1924238cbc2 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:46 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bd376463e83523401069d3f61198a4520577ba76 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\966acd9ba0dcfd640628f16a37619052d0e0d41d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd13bd10fb59b0c4bc107f7c0de16ddfafa24832 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:47 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9b7b26e1a850cdb186c9961df03811ded9be6a82 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e863bab68d7216257e908186f564ccf3ac6be1b8 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52056ba1955403217f6528d54894389b88014acd Dynamic Signature Compilation Timestamp:05-01-2026 17:46:48 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe4fa22162ee5a9961a8952a34dd04f6888b148f Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\763210ff3e031058dc3b448b304356448d7eb7ca Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2f954fed4191a2e5743fc2c0e5eb0859905eec99 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:49 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a7041609adbe381bf73118a338981e7e2b06585b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7673c8600249a723f6c38364a0f2eceaab686877 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b5cd9fbf91792259afeefbe7cdf90347ca7c03b5 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\135e490dd33131e097f2106e4297c4ddb76a2953 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:50 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0382392a482016c0f1929ea45d1ce0bd342c3f83 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b45d87fa25db8fa36b1963ef47733f442fc42602 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14871022fea6023466ca0d4a865118d6e4953fcd Dynamic Signature Compilation Timestamp:05-01-2026 17:46:51 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\af5ff3066ee1e9df1fadd9a4951b1b0196d66fcb Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b6e51c887202c27b6cf630b471a1a7382f2cd58c Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a1eabbaf7d0587d3b64a08a7d786bba1483cd9c0 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:52 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6409bb1d86b8d75d8646a13491896206b21c8b8d Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\96fadda3d39e9db6ffcaef2c262377a0e9bddee0 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6fcb653c16036e26a8897305f185023b57ae842b Dynamic Signature Compilation Timestamp:05-01-2026 17:46:53 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f408e05fd75fe75a83e7b84be45c93168e55370 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\717f81afc794fa1ea60726491cca8f17582581a9 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\adadf795703beaac3ea8f3c1049c4e43110cd35c Dynamic Signature Compilation Timestamp:05-01-2026 17:46:54 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\657c49d658ccae926cd0fa75079847cc29ad3da2 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:55 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3869d549bfb724456f857f79688dba80ae5cebee Dynamic Signature Compilation Timestamp:05-01-2026 17:46:55 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4273defc9bdf43fd3375485e609212a51a8c9586 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:56 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e598b14f1ddca534d25f5d53d1f6b6c96826fef3 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.235 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4b3f040f3e8aa0075a1232c13247f321e6af57ac Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\885533744e1e909a2fea44aed5cac6598353a050 Dynamic Signature Compilation Timestamp:05-01-2026 17:46:57 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\34c04b32e1fd424d5437f92d3fcdc8fd61f2c34b Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\61cd7987fc0e0741553b3cda54cf2db86d5adb20 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d9dffb7063b0218735e752d5e7d2ba77708dfcbb Dynamic Signature Compilation Timestamp:05-01-2026 17:47:08 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\224aeed77b00379528457f2c30dcc56745e88f7e Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\173ca5267402020a41997d4c239bfb242c012971 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6d7b8b26ec5bae7b061d679c5541797cdb232f3 Dynamic Signature Compilation Timestamp:05-01-2026 17:47:09 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b28e7a4d4c706750f9ab0a1189d75a8fe684f8da Dynamic Signature Compilation Timestamp:05-01-2026 17:47:10 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52002162e55abd1b1883431231848b1e063392b7 Dynamic Signature Compilation Timestamp:05-01-2026 23:00:14 Persistence Type:Duration Time remaining:50065408 2026-05-13T12:34:53.250 MpWriteUupSignatureVersion 1.449.477.0, hr = 0 2026-05-13T12:34:53.250 [SigStatUpd] CSignatureStatus: Changed to DUE_TRY_1 2026-05-13T12:34:53.250 [SigStatUpd] CSignatureStatus: Triggering signature update... 2026-05-13T12:34:53.297 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-13T12:34:53.297 [SigStatUpd] CSignatureStatus: Signature update triggered! 2026-05-13T12:34:53.297 [SigStatUpd] CSignatureStatus: UpdateWaitTimer #1 scheduled 2026-05-13T12:34:53.297 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-13T12:34:53.297 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7788] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7796]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:34:53.313 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-13T12:34:53.313 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:34:53.313 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-13T12:34:53.313 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-13T12:34:53.313 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T12:34:53.329 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-13T12:34:53.329 [Plugin] Initializing RTP plugin state... 2026-05-13T12:34:53.329 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2758 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2443 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13778 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2725 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-13T12:34:53.329 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-13T12:34:53.329 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA} 2026-05-13T12:34:53.344 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:34:53.344 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:34:53.344 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:34:53.344 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T12:34:53.344 MdCoreSvc is supported in this platform and OS 2026-05-13T12:34:53.344 Engine loaded! 2026-05-13T12:34:53.344 [DLP] Create FeatureControlState instance 2026-05-13T12:34:53.344 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-13T12:34:53.344 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-13T12:34:53.344 RegisterSModeChangeListener: hr = 0x1 2026-05-13T12:34:53.344 RegisterHybridModeChangeListener: hr = 0 2026-05-13T12:34:53.360 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-13T12:34:53.360 [SigReleaseHb] Initialized with Stage 0 2026-05-13T12:34:53.360 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-13T12:34:53.360 [SCC][CID=31078_5708] Initializing ... 2026-05-13T12:34:53.360 [SCC][CID=31078_5708] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-13T12:34:53.360 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-13T12:34:53.360 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-13T12:34:53.360 [NRI] Stopping NIS service ... 2026-05-13T12:34:53.360 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-13T12:34:53.360 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26030.3008 AS Signature Version: 1.449.477.0 AV Signature Version: 1.449.477.0 ************************************************************ 2026-05-13T12:34:53.375 Resource usage Monitoring is enabled 2026-05-13T12:34:53.375 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T12:34:53.375 Job Notification: New process added to job (4796) 2026-05-13T12:34:53.375 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-13T12:34:53.407 Job Notification: New process added to job (7872) 2026-05-13T12:34:53.407 Job Notification: New process added to job (7880) 2026-05-13T12:34:53.407 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:7872] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7880]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:34:53.469 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-13T12:34:53.469 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T12:34:53.469 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T12:34:53.469 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T12:34:53.469 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T12:34:53.469 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:34:53.469 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:34:53.469 [RTP] Generating the base plugin configuration ... 2026-05-13T12:34:53.469 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-13T12:34:53.469 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:34:53.469 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-13T12:34:53.469 Job Notification: Process exited from job (7872) 2026-05-13T12:34:53.469 Job Notification: Process exited from job (7880) 2026-05-13T12:34:53.469 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-13T12:34:53.469 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-13T12:34:53.469 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:34:53.469 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-13T12:34:53.485 [RTP] [RTP] StartCommunication 0x0000021B1D89B9A0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T12:34:53.485 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-13T12:34:53.485 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-13T12:34:53.657 Job Notification: New process added to job (8056) 2026-05-13T12:34:53.672 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-13T12:34:53.672 Job Notification: New process added to job (8064) 2026-05-13T12:34:53.688 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:8056] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8064]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:34:53.797 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-13T12:34:53.797 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-13T12:34:53.797 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T12:34:53.813 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:54.282 [AutoPurge] Cleanup Routine tasks have started. 2026-05-13T12:34:54.282 [AutoPurge] Verification Routine tasks have started. 2026-05-13T12:34:54.282 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T12:34:54.297 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-13T12:34:54.297 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-13T12:34:54.297 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-13-2026 12:34:54 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-13-2026 12:34:54 2026-05-13T12:34:54.329 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-13T12:34:54.329 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-13T12:34:54.329 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-13T12:34:54.329 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-13T12:34:54.329 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-13T12:34:54.469 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-13T12:34:54.485 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-13T12:34:54.500 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-13T12:34:54.813 Job Notification: New process added to job (8180) 2026-05-13T12:34:54.829 Task(GetDeviceTicket -AccessKey 6F3CED27-E3D2-B958-17CE-69F6528162D0 ) launched as network service 2026-05-13T12:34:55.563 Job Notification: Process exited from job (8180) 2026-05-13T12:34:55.891 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-13T12:34:55.891 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T12:34:55.891 [Cloud] Queued cloud request. 2026-05-13T12:34:55.891 [Cloud] Dequeued cloud request. 2026-05-13T12:34:55.891 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T12:34:56.110 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T12:34:56.141 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-13T12:34:56.141 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T12:34:56.141 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:34:56.141 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:56.141 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:34:56.141 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T12:34:56.141 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-13T12:34:56.141 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-13T12:34:56.141 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:56.141 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-13T12:34:56.141 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:56.157 [AutoPurge] Verification Routine tasks have ended. 2026-05-13T12:34:56.157 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:34:56.297 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-13T12:34:56.297 [Cloud] End of cloud request. 2026-05-13T12:34:56.391 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:34:56.391 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:34:56.391 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-05-13T12:34:56.391 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:34:56.391 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T12:34:56.391 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-05-13T12:34:56.641 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:35:27.016 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\9B8B10D6-3457-4801-BED7-5445BBE0E3F5fb8.1dce2d4f858dcc0 2026-05-13T12:35:27.219 Verifying engine and signature files (source: 0) ... 2026-05-13T12:35:27.219 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpengine.dll] due to PPL. 2026-05-13T12:35:27.219 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm] (file in cache) 2026-05-13T12:35:27.219 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-13T12:35:27.250 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasdlta.vdm] 2026-05-13T12:35:27.250 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm] (file in cache) 2026-05-13T12:35:27.250 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-13T12:35:27.266 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavdlta.vdm] 2026-05-13T12:35:27.422 [Engine] IsHybridMode: 0 2026-05-13T12:35:27.422 [KSL]KSL(1.1.25111.3024) Is available via CAMP. KslDevice : KslD 2026-05-13T12:35:27.422 Current mpengine.dll version(1.1.26040.8) is newer than mpengine_etw.dll version(1.1.26030.3008). Updating C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll ... 2026-05-13T12:35:27.438 C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll updated. 2026-05-13T12:35:27.657 Job Notification: New process added to job (7192) 2026-05-13T12:35:27.657 Job Notification: New process added to job (7176) 2026-05-13T12:35:27.938 Job Notification: Process exited from job (7192) 2026-05-13T12:35:27.938 Job Notification: Process exited from job (7176) 2026-05-13T12:35:27.938 Job Notification: New process added to job (7876) 2026-05-13T12:35:27.954 Job Notification: New process added to job (7820) 2026-05-13T12:35:28.141 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T12:35:28.172 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T12:35:28.485 Job Notification: Process exited from job (7876) 2026-05-13T12:35:28.500 Job Notification: Process exited from job (7820) 2026-05-13T12:35:28.500 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-42DCBFB77F3795C880C7C00372FF21EDDC7A2614.bin): 0x00000002 2026-05-13T12:35:28.500 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-42DCBFB77F3795C880C7C00372FF21EDDC7A2614.bin) 2026-05-13T12:35:28.500 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-13T12:35:28.500 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-13T12:35:28.500 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-13T12:35:28.500 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-05-13T12:35:29.016 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T12:35:29.016 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T12:35:30.750 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:35:30.750 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:35:30.750 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-13T12:35:30.750 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T12:35:30.750 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-13T12:35:41.094 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-13T12:35:41.094 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-13T12:35:41.094 Engine upgrade detected 0x1000165ae0bc0. Saving old engine files to last known good engine files ... 2026-05-13T12:35:41.110 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFDF34A8020, lRefCount: 7, hr=0 2026-05-13T12:35:41.110 [Engine] New active engine 00007FFDED9B5810 replacing engine 00007FFDF34A8020. Number of active engines: 2 2026-05-13T12:35:41.110 EngineInit:Global ASOC is enabled 2026-05-13T12:35:41.110 EngineInit:ASOO is enabled for developer volumes 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:35:41.188 MpWriteUupSignatureVersion 1.449.595.0, hr = 0 2026-05-13T12:35:41.188 [SigStatUpd] CSignatureStatus: back to good 2026-05-13T12:35:41.188 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-13T12:35:41.219 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-13T12:35:41.219 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:35:41.219 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-13T12:35:41.219 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-13T12:35:41.219 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T12:35:41.235 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-13T12:35:41.235 [Plugin] Initializing RTP plugin state... 2026-05-13T12:35:41.235 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-13T12:35:41.235 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎13‎-‎2026 14:34:53 Last Perf:‎05‎-‎13‎-‎2026 14:34:53 First RTP Scan:‎05‎-‎13‎-‎2026 14:34:53 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:455 Misses:693 BM Queue:0,12,0 Proc:0,12,0 File:0,7,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:1685 Pending:1 RegSize:307530 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:1622562 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2960 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:16214 TotalHits:3282 InstanceCacheInserts:27 InstanceCacheUpdates:0 InstanceCacheDeletes:25 InstanceCacheHits:0 InstanceCacheMisses:3324 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (97/35) Success: 35, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-13T12:35:41.235 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2} 2026-05-13T12:35:41.235 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T12:35:41.235 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{18F0B478-BDA5-4440-817A-272C2908F9DE} removed 2026-05-13T12:35:41.235 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA}\mpasbase.vdm in use, hr=0x80070020 2026-05-13T12:35:41.235 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.235 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.235 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.235 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.235 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-13-2026 12:35:41 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-13-2026 12:35:41 2026-05-13T12:35:41.235 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:35:41.235 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-13T12:35:41.250 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-13T12:35:41.250 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-13T12:35:41.250 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:35:41.250 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.250 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.250 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.250 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T12:35:41.250 MdCoreSvc is supported in this platform and OS Signature updated on 05-13-2026 12:35:41 Product Version: 4.18.26030.3011 Service Version: 4.18.26030.3011 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.595.0 AV Signature Version: 1.449.595.0 ************************************************************ 2026-05-13T12:35:41.250 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-13T12:35:41.250 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\9B8B10D6-3457-4801-BED7-5445BBE0E3F5fb8.1dce2d4f858dcc0 2026-05-13T12:35:41.360 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-13T12:35:41.360 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 05-13-2026 12:35:41 ************************************************************ 2026-05-13T12:35:41.516 Job Notification: Process exited from job (8056) 2026-05-13T12:35:41.532 Job Notification: Process exited from job (8064) 2026-05-13T12:35:41.719 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-13T12:35:41.719 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-13T12:35:41.719 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T12:35:41.735 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T12:35:41.735 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T12:35:41.735 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T12:35:41.735 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:35:41.735 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:35:41.735 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:35:41.735 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-13T12:35:46.000 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-13T12:35:54.282 [Engine] Engine 00007FFDF34A8020 no longer in use. Number of active engines: 1 2026-05-13T12:35:54.375 ProcessImageName: update.exe, Pid: 6648, TotalTime: 8303, Count: 446, MaxTime: 1234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 22% 2026-05-13T12:35:54.375 ProcessImageName: TeamViewer_Service.exe, Pid: 4768, TotalTime: 1650, Count: 15, MaxTime: 984, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\update.exe, EstimatedImpact: 51% 2026-05-13T12:35:54.375 ProcessImageName: taskhostw.exe, Pid: 7532, TotalTime: 656, Count: 2, MaxTime: 625, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-05-13T12:35:54.375 ProcessImageName: WmiPrvSE.exe, Pid: 3720, TotalTime: 420, Count: 58, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf->(UTF-16LE), EstimatedImpact: 15% 2026-05-13T12:35:54.375 ProcessImageName: MpSigStub.exe, Pid: 4024, TotalTime: 327, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\9B8B10D6-3457-4801-BED7-5445BBE0E3F5fb8.1dce2d4f858dcc0\mpengine.dll, EstimatedImpact: 100% 2026-05-13T12:35:54.375 ProcessImageName: tv_x64.exe, Pid: 7592, TotalTime: 214, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\setupapi.dev.log, EstimatedImpact: 33% 2026-05-13T12:35:54.375 ProcessImageName: tv_x64.exe, Pid: 708, TotalTime: 196, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\setupapi.dev.log, EstimatedImpact: 78% 2026-05-13T12:35:54.375 ProcessImageName: svchost.exe, Pid: 552, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29554.1001-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-05-13T12:35:54.375 ProcessImageName: wuauclt.exe, Pid: 2572, TotalTime: 124, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\SoftwareDistribution\Download\Install\AM_Engine_Patch_1.1.26030.3008.exe, EstimatedImpact: 7% 2026-05-13T12:35:54.375 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache, EstimatedImpact: 1% 2026-05-13T12:35:54.375 ProcessImageName: svchost.exe, Pid: 3992, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\2bdbbb3618f766ea186aac15068fb42eca76192e\content.phf, EstimatedImpact: 1% 2026-05-13T12:35:54.375 ProcessImageName: brynhildr.exe, Pid: 4344, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-13T12:35:54.407 [Engine] RSIG_UNLOADENGINE, 00007FFDF34A8020, err=0x0 2026-05-13T12:35:54.407 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B6248A6E-B0F8-4046-8D35-A26B29C8B7AA} removed 2026-05-13T12:36:02.313 Process scan (postsignatureupdatescan) completed. 2026-05-13T12:36:43.049 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-05-13T12:36:43.049 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:36:43.049 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:36:43.049 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-13T12:36:43.049 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-13T12:36:43.049 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-13T12:36:43.111 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-13T12:36:57.269 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:36:57.277 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:36:57.278 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:37:10.504 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.063.0405.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5049, FileId: 0xe0000000b66f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:37:52.220 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-13T12:37:56.252 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-05-13T12:37:56.955 [RTP] [Mini-filter] OpenWithoutRead notification (4922, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-13T12:38:02.174 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #11794, FileId: 0xc0000000b6bb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:38:02.595 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 5312 units 2026-05-13T12:38:14.283 Engine:Triggered SMS scan for filename: explorer.exe, pid: 8212, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-05-13T12:39:53.369 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T12:40:34.467 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15750, FileId: 0x37000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.514 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15755, FileId: 0x39000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.529 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15758, FileId: 0x2e000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.529 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15760, FileId: 0x42000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.529 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15756, FileId: 0x2d000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.529 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15761, FileId: 0x37000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.545 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15757, FileId: 0x3a000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.701 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15778, FileId: 0x3c000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.701 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15776, FileId: 0x3a000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.717 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15777, FileId: 0x47000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.764 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15791, FileId: 0x41000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.764 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15793, FileId: 0x4f000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.779 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15790, FileId: 0x4e000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.779 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15792, FileId: 0x42000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.865 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15799, FileId: 0x44000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.865 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15801, FileId: 0x51000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.889 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15802, FileId: 0x45000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.889 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15798, FileId: 0x50000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.998 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15823, FileId: 0x55000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.998 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15825, FileId: 0x56000000011965, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:34.998 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15824, FileId: 0x49000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:35.014 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15822, FileId: 0x48000000011e24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:37.408 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15981, FileId: 0x1a60000000130da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:37.408 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15983, FileId: 0x1a70000000130da, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:38.636 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\37ae5257-0a1e-4005-868f-5e566cfbb906. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #16042, FileId: 0x1520000000023f4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:39.533 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #16046, FileId: 0x166000000009e0b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:41.251 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-13T12:40:48.783 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF63688975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16537, FileId: 0x10c000000013175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:48.814 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj027C15948. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16539, FileId: 0x10d000000013175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:48.814 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj071E28914. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16541, FileId: 0x2600000001316d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:48.845 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9137C891F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16545, FileId: 0xcf00000001318b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:48.877 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj086F76997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16546, FileId: 0xd000000001318b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:49.115 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj60A0039E8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16558, FileId: 0x3700000001318f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:49.146 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70CF80991. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16557, FileId: 0x3600000001318f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:49.349 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC3BA6290A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16575, FileId: 0x27000000013222, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:49.969 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C7906905. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16591, FileId: 0x20000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:49.982 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj161FEC9FB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16592, FileId: 0x9f000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.011 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCF5E879E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16593, FileId: 0x22000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.244 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70AC139B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16595, FileId: 0x15b000000004be0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.275 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5002A494F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16596, FileId: 0x23000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.306 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3388F197D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16597, FileId: 0x24000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.517 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD32F48947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16610, FileId: 0x26000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.533 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj16FB95978. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16611, FileId: 0x3200000001322d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj02F76C97A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16619, FileId: 0x29000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE27C40910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16621, FileId: 0x2b000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj660415911. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16622, FileId: 0x2c000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjACA48190C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16618, FileId: 0xa0000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7F2AD798E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16620, FileId: 0x2a000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.856 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj66F077998. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16625, FileId: 0x2d000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.973 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC4E7569CC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16628, FileId: 0x2e000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:50.993 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEFFD8691C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16630, FileId: 0x2f000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.035 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC28433900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16634, FileId: 0x30000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.062 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2BCA849EB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16635, FileId: 0x31000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.084 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2895C596D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16636, FileId: 0x32000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.170 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj37327295D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16646, FileId: 0x34000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.170 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA46DEA91C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16645, FileId: 0x33000000013229, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.252 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF07B68970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16657, FileId: 0xa1000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.268 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9AEB809C4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16662, FileId: 0xa2000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.314 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1BD7093E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16666, FileId: 0xa3000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.330 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6EB2119FA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16672, FileId: 0xa4000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.502 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE867E397C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16688, FileId: 0xa6000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.502 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCFDC8C98B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16683, FileId: 0xb000000001324a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.564 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3D75B4926. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16691, FileId: 0xa8000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.564 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE2664A94E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16689, FileId: 0xa7000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.564 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDB28019F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16692, FileId: 0xa9000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.595 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj779B20977. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16694, FileId: 0xaa000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.611 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB493D7901. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16696, FileId: 0xab000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.674 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC981D8977. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16701, FileId: 0xac000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:40:51.689 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj20CCBF9DF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16702, FileId: 0xad000000013242, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:41:03.361 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17086, FileId: 0x11800000000dc06, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:41:03.455 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17090, FileId: 0x4e00000000f41e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:41:03.595 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17098, FileId: 0x34000000011984, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:41:38.783 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17306, FileId: 0x2100000000c9e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0xba56fb9d Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0xc2e84d10 2026-05-13T12:42:03.814 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17528, FileId: 0x1d0000000110e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:44:53.374 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-13T12:44:53.374 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-13T12:44:53.389 Job Notification: New process added to job (13204) 2026-05-13T12:44:53.389 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-13T12:44:53.389 Aggressive catchup quick scan threshold: 6222078842514 / 25920000000000 2026-05-13T12:44:53.405 Job Notification: New process added to job (972) 2026-05-13T12:44:53.405 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:13204] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:972]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:44:53.468 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 49904956(ms) from now at 04:36 (02:36 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-13T12:44:53.499 Job Notification: New process added to job (11584) 2026-05-13T12:44:53.499 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-13T12:44:53.514 Job Notification: New process added to job (2596) 2026-05-13T12:44:53.514 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11584] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2596]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:44:53.921 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-13T12:44:53.921 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:44:53.921 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:44:53.921 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-13T12:44:53.921 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:44:53.921 [RTP] No config change detected. Not updating plugin configuration. 2026-05-13T12:44:53.921 [RTP] No config changes found. No configuration switch. 2026-05-13T12:44:53.921 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-13T12:45:14.524 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:11584] from process [\Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20136\OfficeClickToRun.exe][Pid:7048]. OriginalDesiredAccess: [0x101411] ResultingAccess: [0x101410] 2026-05-13T12:45:14.524 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpCmdRun.exe][Pid:13204] from process [\Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20136\OfficeClickToRun.exe][Pid:7048]. OriginalDesiredAccess: [0x101411] ResultingAccess: [0x101410] 2026-05-13T12:45:16.548 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-13T12:45:16.548 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-13T12:45:16.548 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-13T12:45:16.548 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-13T12:45:16.564 [PlatUpd] Verified C:\Windows\SystemTemp\B928DB1D-0BEC-401A-98E8-3294FAD9D570\MpUpdate.dll. Calling MpUpdateStub(0) ... 2026-05-13T12:45:18.564 [PlatUpd] MpUpdateStub() succeeded. Stub DLL: C:\Windows\SystemTemp\B928DB1D-0BEC-401A-98E8-3294FAD9D570\MpUpdate.dll. 2026-05-13T12:45:18.564 [KSL] Entering CKSLEngine::DisableKSL. 2026-05-13T12:45:18.564 [KSL] Entering CKSLEngine::shutdownImpl. 2026-05-13T12:45:18.721 [KSL] Leaving CKSLEngine::shutdownImpl(0). 2026-05-13T12:45:18.721 [KSL] Leaving CKSLEngine::DisableKSL(0). 2026-05-13T12:45:18.721 [KSL] OnPlatformUpdate: hr=[0x8000000a] Type=[1] KslServiceExists=[1] KslActive=[1] KslState=[2] 2026-05-13T12:45:18.721 [PlatUpd] DlpActive 0, CopyAccActive 0 2026-05-13T12:45:18.721 [PlatUpd] PlatformUpdate is now allowed. Resuming platform update from C:\Windows\SystemTemp\B928DB1D-0BEC-401A-98E8-3294FAD9D570. 2026-05-13T12:45:18.721 [PlatUpd] NewLocation set to [C:\Windows\SystemTemp\B928DB1D-0BEC-401A-98E8-3294FAD9D570] to indicate we are in the middle of an update. 2026-05-13T12:45:18.736 Job Notification: New process added to job (4024) 2026-05-13T12:45:18.752 Task(-RestartService) launched as PPL process 2026-05-13T12:45:18.752 Job Notification: New process added to job (7680) -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-13-2026 12:45:23 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/13/2026 12:45:23.87496400 UTC (660812 ms since boot) 2026-05-13T12:45:23.085 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-13T12:45:23.085 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:45:23.085 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:45:23.101 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260513-124523-00000003-fffffffeffffffff.bin ... 2026-05-13T12:45:23.101 [WPP] Trace session started - MpWppTracing-20260513-124523-00000003-fffffffeffffffff.bin 2026-05-13T12:45:23.101 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-13T12:45:23.101 [RbM] Rollback manager succesfully initialized. 2026-05-13T12:45:23.101 [RbM] Rollback manager EnableRollbackManager called. 2026-05-13T12:45:23.101 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-13T12:45:23.101 [PlatUpd] Stage 1 - Starting platform update from %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-13T12:45:24.773 [PlatUpd] Updated service binary of WdNisSvc from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\NisSrv.exe" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe" 2026-05-13T12:45:24.773 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdBoot.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\Drivers\WdBoot.sys 2026-05-13T12:45:24.773 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdFilter.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\Drivers\WdFilter.sys 2026-05-13T12:45:24.773 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdNisDrv.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\Drivers\WdNisDrv.sys 2026-05-13T12:45:25.163 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdDevFlt.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\Drivers\WdDevFlt.sys 2026-05-13T12:45:25.163 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\KslD.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\Drivers\KslD.sys 2026-05-13T12:45:27.116 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpOav.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpOav.dll" 2026-05-13T12:45:27.116 [PlatUpd] Updated SOFTWARE\WOW6432Node\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\X86\MpOav.dll" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\X86\MpOav.dll" 2026-05-13T12:45:27.132 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-13T12:45:27.132 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-13T12:45:27.132 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-13T12:45:27.132 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-13T12:45:27.132 [PlatUpd] CSP platform update started 2026-05-13T12:45:27.132 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{195B4D07-3DE2-4744-BBF2-D90121AE785B}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\DefenderCSP.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\DefenderCSP.dll" 2026-05-13T12:45:27.132 [PlatUpd] CSP version com.microsoft/1.3/MDM/Defender update not required. 2026-05-13T12:45:27.132 [PlatUpd] WMI/PS provider platform update started 2026-05-13T12:45:27.132 [PlatUpd] Powershell module update started: ConfigDefender 2026-05-13T12:45:27.132 [PlatUpd] Powershell module update completed: ConfigDefender 2026-05-13T12:45:27.132 [PlatUpd] Powershell module update started: ConfigDefenderPerformance 2026-05-13T12:45:27.149 [PlatUpd] Powershell module update completed: ConfigDefenderPerformance 2026-05-13T12:45:27.433 [PlatUpd] WMI repository update completed 2026-05-13T12:45:27.433 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{A7C452EF-8E9F-42EB-9F2B-245613CA0DC9}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\ProtectionManagement.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\ProtectionManagement.dll" 2026-05-13T12:45:27.433 [PlatUpd] Unload current WMI provider so that new instance can be loaded 2026-05-13T12:45:27.543 [PlatUpd] WMI/PS provider platform update completed 2026-05-13T12:45:27.543 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-13T12:45:27.543 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-13T12:45:27.543 MdCoreSvc is supported in this platform and OS 2026-05-13T12:45:27.543 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T12:45:27.543 [PlatUpd] Updated service binary of MDCoreSvc from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\MpDefenderCoreService.exe" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe" 2026-05-13T12:45:27.543 [PlatUpd] Because we updated service binary, and MdCoreSvc service was already running, we need to restart the service 2026-05-13T12:45:28.730 [PlatUpd] Firewall rules updated for %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe 2026-05-13T12:45:28.730 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 7 required update. hrMui: 0x1 hrEtw: 0 2026-05-13T12:45:28.730 [PlatUpd] Stage 1 - NewLocation updated from C:\Windows\SystemTemp\B928DB1D-0BEC-401A-98E8-3294FAD9D570 to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 to indicate we are in the middle of an update 2026-05-13T12:45:28.730 [PlatUpd] Stage 1 - Service binary path updated to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe". 2026-05-13T12:45:28.730 [PlatUpd] Stage 1 - Removed BlockedLocation [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0] to indicate we are loaded successfully. 2026-05-13T12:45:28.761 Task(-RestartService) launched as PPL process 2026-05-13T12:45:28.761 MpPostPlatformUpdate is requesting a service restart. We will abort the current service start -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-13-2026 12:45:28 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/13/2026 12:45:28.933362100 UTC (666640 ms since boot) 2026-05-13T12:45:28.933 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-13T12:45:28.933 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:45:28.933 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:45:28.949 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260513-124528-00000003-fffffffeffffffff.bin ... 2026-05-13T12:45:28.949 [WPP] Trace session started - MpWppTracing-20260513-124528-00000003-fffffffeffffffff.bin 2026-05-13T12:45:28.949 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-13T12:45:28.949 [RbM] Rollback manager succesfully initialized. 2026-05-13T12:45:28.949 [RbM] Rollback manager EnableRollbackManager called. 2026-05-13T12:45:28.949 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-13T12:45:28.949 [PlatUpd] Stage 2 - Service started from new location. Removed NewLocation value: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-13T12:45:28.965 [PlatUpd] [Catalog] Installed catalog file : C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\catalogs\MpExtDeps.cat as wd_mpextdeps.cat. 2026-05-13T12:45:28.965 [PlatUpd] Stage 2 - Updated BackupLocation to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0. 2026-05-13T12:45:28.965 [PlatUpd] MpRemoveMpUxRegistration failed (Ignored). hr = 0x800401f0 2026-05-13T12:45:29.199 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-13T12:45:29.199 [PlatUpd] Stage 2 - ReinforceServiceAcl (hr = 0) 2026-05-13T12:45:29.199 [PlatUpd] Stage 2 - Readded platform files to MOAC after ACL and Trust Label enforcement. hr=0 2026-05-13T12:45:29.199 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-13T12:45:31.511 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-13T12:45:31.511 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-13T12:45:31.511 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-13T12:45:31.511 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-13T12:45:31.511 [PlatUpd] CSP platform update started 2026-05-13T12:45:31.511 [PlatUpd] Defender MDM CSP platform update not required 2026-05-13T12:45:31.511 [PlatUpd] WMI/PS provider platform update started 2026-05-13T12:45:31.511 [PlatUpd] WMI/PS provider platform update not required 2026-05-13T12:45:31.511 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-13T12:45:31.511 MdCoreSvc is supported in this platform and OS 2026-05-13T12:45:31.511 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T12:45:31.511 [PlatUpd] Starting MdCoreSvc service 2026-05-13T12:45:31.511 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-13T12:45:31.511 [TS] Troubleshooting mode is not available! 2026-05-13T12:45:31.511 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T12:45:31.511 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-13T12:45:31.511 Service is asked to be reenabled. 2026-05-13T12:45:31.558 Task(-EnableService) launched as PPL process 2026-05-13T12:45:31.558 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-13T12:45:31.558 [Service] Enabling AutoLoggers ... 2026-05-13T12:45:31.558 [Service] Enabling AMSI registration ... 2026-05-13T12:45:31.558 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-13T12:45:31.574 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 46123 Number of invalid entries is 0 Number of inserts issued is 1580583 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6503 Number of lookups is 107953221 Number of lookup misses is 5184530 Number of fast lookup misses is 55006979 Number of false fast lookups is 5184525 Number of invalidations is 733225 Number of maintenance invalidations is 518215 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-13T12:45:31.574 Verifying license file... 2026-05-13T12:45:31.574 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll]. File not in cache (0x1) 2026-05-13T12:45:31.574 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] 2026-05-13T12:45:31.590 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-13T12:45:31.590 Loaded module#0 MpComServer. 2026-05-13T12:45:31.590 Loaded module#1 StartupPolicies. 2026-05-13T12:45:31.590 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T12:45:31.590 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T12:45:31.590 COM server initialized successfully. 2026-05-13T12:45:31.605 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-13T12:45:31.605 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-13T12:45:31.605 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-13T12:45:31.668 [RTP] [RTP] FilterCommunicator object 0x00000202183057B0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T12:45:31.668 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-13T12:45:31.668 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:45:31.668 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:45:31.668 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-13T12:45:31.668 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-13T12:45:31.668 [RTP] [RTP] FilterCommunicator object 0x00000202183059C0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T12:45:31.668 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-13T12:45:31.668 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-13T12:45:31.668 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-13T12:45:31.668 [RTP] [RTP] StartCommunication 0x00000202183057B0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T12:45:31.668 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-13T12:45:31.668 [init][RTP] RTPPlugin initialization completed 2026-05-13T12:45:31.668 OS boot count = 2 2026-05-13T12:45:31.668 OS Install = 0 2026-05-13T12:45:31.699 [init] MpAddMpUxRegistrationForToast succeeded 2026-05-13T12:45:31.715 [KSL] Entering CKSLEngine::Initialize. 2026-05-13T12:45:31.715 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-13T12:45:31.715 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-13T12:45:31.715 [KSL] MpInstallKslD: hr=0 2026-05-13T12:45:31.715 [KSL] MpRegisterKslD: hr=0 2026-05-13T12:45:31.715 [KSL] MpStartKslD: hr=0 2026-05-13T12:45:31.715 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T12:45:31.715 Loading engine... 2026-05-13T12:45:31.730 Verifying engine and signature files (source: 1) ... 2026-05-13T12:45:31.730 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpengine.dll] due to PPL. 2026-05-13T12:45:31.730 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm]. File not in cache (0x1) 2026-05-13T12:45:32.558 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm] 2026-05-13T12:45:32.558 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasdlta.vdm] (file in cache) 2026-05-13T12:45:32.558 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm]. File not in cache (0x1) 2026-05-13T12:45:32.918 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm] 2026-05-13T12:45:32.918 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavdlta.vdm] (file in cache) 2026-05-13T12:45:32.933 [Engine] IsHybridMode: 0 2026-05-13T12:45:32.933 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-13T12:45:32.933 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5966C72D3E93A0018E0270BC315C0CF48C9C8CEB.bin): 0x00000002 2026-05-13T12:45:32.949 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5966C72D3E93A0018E0270BC315C0CF48C9C8CEB.bin) 2026-05-13T12:45:32.949 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-13T12:45:32.949 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-13T12:45:32.949 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-13T12:45:32.949 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-13T12:45:42.834 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-13T12:45:42.834 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_DC_DisableAadDeviceIdQuery new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-13T12:45:42.834 [Engine] New active engine 00007FFDC1535810 (no old engine). Number of active engines: 1 2026-05-13T12:45:42.849 EngineInit:Global ASOC is enabled 2026-05-13T12:45:42.849 EngineInit:ASOO is enabled for developer volumes 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T12:45:42.912 MpWriteUupSignatureVersion 1.449.595.0, hr = 0 2026-05-13T12:45:42.912 [SigStatUpd] CSignatureStatus: back to good 2026-05-13T12:45:42.912 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-13T12:45:42.943 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-13T12:45:42.943 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T12:45:42.943 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-13T12:45:42.943 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-13T12:45:42.943 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T12:45:42.959 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-13T12:45:42.959 [Plugin] Initializing RTP plugin state... 2026-05-13T12:45:42.959 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:13 TotalStreamCon:3452 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:3748 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3454 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-13T12:45:42.959 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-13T12:45:42.959 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2} 2026-05-13T12:45:42.959 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:45:42.959 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:45:42.959 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T12:45:42.959 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T12:45:42.959 MdCoreSvc is supported in this platform and OS 2026-05-13T12:45:42.959 MdCoreSvc is supported in this platform and OS 2026-05-13T12:45:42.959 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T12:45:42.959 [PlatUpd] Starting MdCoreSvc service 2026-05-13T12:45:42.959 Engine loaded! 2026-05-13T12:45:42.959 [DLP] Create FeatureControlState instance 2026-05-13T12:45:42.974 RegisterSModeChangeListener: hr = 0x1 2026-05-13T12:45:42.974 RegisterHybridModeChangeListener: hr = 0 2026-05-13T12:45:42.974 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-13T12:45:42.974 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-13T12:45:42.974 [PlatUpd] Updated install location from C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0\ to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\ 2026-05-13T12:45:42.990 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-13T12:45:42.990 [SigReleaseHb] Initialized with Stage 0 2026-05-13T12:45:42.990 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-13T12:45:42.990 [SCC][CID=680703_4408] Initializing ... 2026-05-13T12:45:42.990 [SCC][CID=680703_4408] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-13T12:45:42.990 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-13T12:45:42.990 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-13T12:45:42.990 [NRI] Stopping NIS service ... 2026-05-13T12:45:42.990 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-13T12:45:42.990 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.595.0 AV Signature Version: 1.449.595.0 ************************************************************ 2026-05-13T12:45:42.990 Resource usage Monitoring is enabled 2026-05-13T12:45:42.990 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-13T12:45:42.990 Job Notification: New process added to job (2756) 2026-05-13T12:45:43.021 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T12:45:43.115 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-13T12:45:43.115 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T12:45:43.130 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T12:45:43.130 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T12:45:43.130 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T12:45:43.130 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T12:45:43.130 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T12:45:43.130 [RTP] Generating the base plugin configuration ... 2026-05-13T12:45:43.130 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-13T12:45:43.130 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:45:43.130 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-13T12:45:43.130 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-13T12:45:43.130 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T12:45:43.130 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-13T12:45:43.130 [RTP] [RTP] StartCommunication 0x00000202183059C0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T12:45:43.130 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-13T12:45:43.130 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-13T12:45:43.412 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T12:45:43.427 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-13T12:45:43.427 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-13T12:45:43.427 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T12:45:43.599 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:45:45.605 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:45.620 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:45:45.620 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:46.167 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:45:46.167 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:45:46.167 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-13T12:45:46.167 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T12:45:46.167 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-13T12:45:47.620 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:47.620 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:45:47.620 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:50.370 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:50.386 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:45:50.386 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:50.636 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys 2026-05-13T12:45:50.933 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-05-13T12:45:50.948 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-05-13T12:45:50.964 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2 2026-05-13T12:45:51.730 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys 2026-05-13T12:45:52.391 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:52.407 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:45:52.407 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:54.407 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:45:54.407 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:45:54.422 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:46:31.611 Process scan (poststartupscan) started. 2026-05-13T12:46:31.611 Process scan (poststartupscan) completed. 2026-05-13T12:46:32.111 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T12:46:32.126 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T12:46:34.704 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:46:34.704 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:46:34.704 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-13T12:46:34.704 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T12:46:34.704 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-13T12:47:02.720 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #5230, FileId: 0x4f00000003757d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:47:02.767 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #5233, FileId: 0x61000000037579, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:47:07.299 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-13T12:47:07.299 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-13T12:47:07.299 [RTP] Duplicating the current plugin configuration object... 2026-05-13T12:47:07.299 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T12:47:07.299 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-13T12:47:07.299 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-13T12:47:07.299 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-13T12:47:08.111 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-13T12:47:37.474 Engine:Process C:\Windows\System32\MRT.exe (PPID:9952:134231499749911184) is tainted: TaintType:0x4A6B3613A1967. TaintReason:n/a, EnableCfa:1 BEGIN BM telemetry GUID:{3D64251B-99B2-16A8-2A3C-83584BAF34F3} SignatureID:1309189267396967 SigSha:d304e169dc9544f53f0388d170992c2806ed4541 ThreatLevel:0 ProcessID:9952 ProcessCreationTime:134231499749911184 SessionID:0 CreationTime:05-13-2026 12:47:37 ImagePath:C:\Windows\System32\MRT.exe Taint Info:Friendly: Y; Reason: 1309189267396967,; Modules: ; Parents: C:\Windows\SoftwareDistribution\Download\Install\Windows-KB890830-x64-V5.141.exe:4360:1, Operations:None END BM telemetry 2026-05-13T12:47:38.521 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T12:47:38.537 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T12:47:38.537 [Cloud] Queued cloud request. 2026-05-13T12:47:38.537 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T12:47:38.537 [Cloud] Dequeued cloud request. 2026-05-13T12:47:38.537 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T12:47:38.537 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-05-13T12:47:38.537 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T12:47:38.537 [Cloud] Queued cloud request. 2026-05-13T12:47:38.537 [Cloud] Dequeued cloud request. 2026-05-13T12:47:38.537 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T12:47:38.787 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-13T12:47:38.787 [Cloud] End of cloud request. 2026-05-13T12:47:38.912 [Cloud] End of cloud request. 2026-05-13T12:47:39.302 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T12:47:42.480 Engine:Triggered SMS scan for filename: MRT.exe, pid: 9952, sigseq: 0x4A6B3613A1967, origin: signature, sendMemoryScanReport: 0 Internal signature match:subtype=Lowfi, sigseq=0x000488612FEDDE65, sigsha=e44d5569860c6384257d171ad98cba61d7185c1b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009778B8F578E7, sigsha=83a2a45218d497e5ad84d65a1bb20d415c6ea273, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006D6115311D8E, sigsha=d85bc537c142547fd2a61cf9f59fb7db56fe5053, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006361BFFB6D4A, sigsha=884e817595951d89c5c5f6f215992957aff07d05, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00016878DC5CF85F, sigsha=b968a54056dab533eeff98cca756d231cd9e6146, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011F616D7C494E, sigsha=881c49ee304387215559836770ee71d54704a7de, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BC783924130D, sigsha=b177fe5eb24ba057cab0dc0d14596f4eef76af07, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B8789B061AC3, sigsha=cb56e722815c9c9e3dad92eb488afefd12bf9fbb, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000877864825297, sigsha=4d3ac23dcfd94538620a11b505c0bab1102d6e33, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000063619500F119, sigsha=12a4fcb190c063a6d70196bd8f5b2433910f1cad, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006C78AC9FCB68, sigsha=9e7109f0979f32e087891bb2040d936559001255, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000647809DCE557, sigsha=d44d18071b75c20db159f1ede319a5b147c34293, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001FA61472D3361, sigsha=d53892c38eeb07d7781b80be54ff512aea7663fe, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010B78052C2CD3, sigsha=7b76c0e344eb7494072ff656199d99d5de283a42, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D5785D7CBF22, sigsha=b26d03a9cf9cfb5463046c39ea743d4c675d3c4d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009978BD981E41, sigsha=0192ec317005bd95851ebf0c807fab45d0a0b417, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000040782B90B198, sigsha=db867eda1b5e53d774f58f9f1348bdcb735f9b15, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000088780A6ED919, sigsha=5b9ee5e8977b1a66ecac24e6a925022f08935bf5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C961378EE673, sigsha=517a8e47fc2d09954b859c99db9a1977dfd33237, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005C78DD96774C, sigsha=e7a991f75954373941367a101d9065d98d499a0f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00015E7875D405ED, sigsha=35b219713cba1f57a6a90fb12570c8187ba5cdd0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013078D9F08137, sigsha=0a4734b53039e401bf146456a60c5e491c0484fd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000637864FD2C9A, sigsha=2b4d8c0913b4974480ebfd085d6d23103060e665, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D678D6793E2E, sigsha=5e3b1ae34d9c083c634f83e3fc3518576e0bbc1f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D17891EF374B, sigsha=73866073d08c27bb4151bee7257977c81d5b83f7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A36111B06A56, sigsha=25d9dde80c2f8664bbdc151ebd95347c56a63fc0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001147878B98F49, sigsha=c03bb012666c84fa8b477b13ea224af9d6a123b8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B47842548650, sigsha=3f6146c08e80de624d0b68beedc7be3e90c4bd68, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011F61D0476BF3, sigsha=ce73c02c3dcc528ef37e30be1f7ba1fae1e511a5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000056614DCEBC2E, sigsha=e63e539842de6fbb3e616a9790e93fae99e5270a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EA78C7E47CFD, sigsha=4b75edc225cf760e30b732ec591eaef4fef62102, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C3783A004EF7, sigsha=4afd2de933208ae7be2f3b966f669a682111fdff, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013A7850D18E3A, sigsha=180e08af5d771c660705df7a8c2bef5518d099c7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001197880908B64, sigsha=24340c0561ff30cdadd4c92d532dca5d69517f16, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008978C473FF41, sigsha=3393efa4c06a16b9b6960422aafb3c5c43d2a5c4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B3784B0FB5CD, sigsha=bd81f5f0bf347b8cc7caf1b10ee5aa8f3019e491, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E4787DC35CFD, sigsha=80719b47d3752b6519a18b39e620507ee8a4423f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007C7880CD9974, sigsha=594f50fc48669f2613b9f5d1e1d657d76f4baf25, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BF78322141E7, sigsha=06212e8b18acf1c43b2711cca23876e9351594ab, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000061611BD04C1A, sigsha=0f14aa13bda643a27a5d19fe5aef728d2b39429c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AB61A0DCCD14, sigsha=647f58a198b0e3465f57aafa53896386a33dddbd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000ED78C8FAD10F, sigsha=335549ce66903abbebc15273acb1c2348ec07c65, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011678FAF517D1, sigsha=a648793f543b531cd54e4002a8418c24cde9e6cf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009261FC0C48A8, sigsha=9db037d57d26e6769c1d38c32e028ae1d574feb9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AD612D3A3D1D, sigsha=248ee9cf7db10d1e88cc8c4b2f0ea9a67b136c8b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000079616F44EFAB, sigsha=9a4c5b8800dd059e52a3702d6d0dfa9ddf4846fb, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000126783CDE99E5, sigsha=cafcaf0377fb4e3efeb864b1b974f674582be3d0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000035610EE8E91F, sigsha=422578c96d4a5bffb8c1a1eac5a1b573b315f405, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AA61931E063A, sigsha=b5d81a65e5fbe55d98366c59a12101f6f0e12a25, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00014D7861FAA7BD, sigsha=0d8b8022f50cac58c3985b6c1b454cab65cc57cf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005A78C7EB1FCB, sigsha=c91bc75a4b706ff967a961e2aef7f343e08e3388, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00017278BCF791BD, sigsha=5a7aac223afd782573415c10cd47b4f2b86bc3cc, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010E784027BA31, sigsha=87e61f508d821c999d86d1db2c52c2fce06f74ca, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000511789E6B5625, sigsha=0eea46ac78893dd4a6ce8a48968329a7efe736c6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AE61F5424B02, sigsha=1d0892f2e33397f988bc95154e3e17d6b9e79377, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009178AC914ADC, sigsha=2d5ca6f014e0190e9aaaf8e99a46995982d0f07e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00015E78C97DCB9C, sigsha=34f3d7be95e4839664127488daf7bf78ad1022a5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A278BB58220E, sigsha=fc5a9bd652fa06e74c33fab51f8bfe584f084d04, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000142781A761366, sigsha=5c9a45708cd1380ba01997a4b603a02f38cbfa51, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A77831F6A08E, sigsha=6f2dd6a58b8563154f0ad363d87760494ee1c70e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000547897908584, sigsha=85d7f4e26bfddcfa258d59bd6755aed3536b9667, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0002056116D8E114, sigsha=6fb3406ca211f9e92987923c0e1e1d3d1feb99ee, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A77810A00DFB, sigsha=c885666088c0a9004d101996e74f341e38954cf7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B3616F2B7EF3, sigsha=b9b2913050e81f0f826ea0631fc8a6bf057e8390, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B878CFED451A, sigsha=0a3f2f9d9bee640ae643a70752c86bd3dff40164, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AA78F3D34CC7, sigsha=77c3fa011231ab89d1f0ffb4d9fb813b5bc78744, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012978A9114A3E, sigsha=19bffaf614c09ac9561ad2faea5bbcfa3758836c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009978C7BCB759, sigsha=35892ae81c9397a8d629122c52d520f87dea776b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A36135D00E3B, sigsha=9a388f144d3293c96c95ff0c596a60b32ab7a217, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00015578A675787A, sigsha=796204926ca0213fa378cf1a288c54dbb32ffac1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F978AB1761C2, sigsha=a7613033a17369c84a54456c74bbcbd6a007209d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011C61C8342498, sigsha=379d873ad3c930657500d2e7408dab89b65042d2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D5785735B908, sigsha=76e2b46ba628c0fae83104730f0eeb7a6ddf3db3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006661E360CC29, sigsha=254379247f762b0c0dc8de6bf6cc4368cc708cf9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000102789DF1B4F6, sigsha=be85f1b4e688425990fd9fc8e4811ff382163085, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007861D12990D3, sigsha=8c2dfc429eb8a2a74ab618fdc8df4bcf8eb5f08a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E9781E269B62, sigsha=0a072d046820e70f472e8c47bd7060572be6fbd2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A778550C4C0A, sigsha=98f07936452da5e9f56cc1a761df5c54305ff86f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00020478E7B1CF69, sigsha=1256839bcef7a4e7ade6b1500877e65574039ff0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0002347837A7D24F, sigsha=7d0c3a2b83d01b6af9221ff3ffabccb886e9acae, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D1782E890EE9, sigsha=d526dad4f267753c559e96e7a3be3bc17d8f0177, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A078B0339D1D, sigsha=e21456977d56426c410870ac1d5371a71fc1e801, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000061780470668F, sigsha=4721361e2b6edc7ccfb459ac98ddf683706ca01a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A978AB410894, sigsha=5f26b632d0691aeacd8fb80d3d7c586f89622b05, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DD78DB50D1FA, sigsha=36cb16f1fcb16a0741cc069ba5b0cfebd8845fa0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009578689273A8, sigsha=19d11750a688e84610db6f2d32ac8f379bd32094, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001B6782B4383DC, sigsha=3802a478458e0744906efd82aeb4b0a184f382c3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D46141D84268, sigsha=0eb95183503870565c11de593271d75e0146dbb4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AF78773778C7, sigsha=be28ddb329c4bc3da94466630bbf48a12df35576, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000079783A250B73, sigsha=e84e7788ad5e5b391f6e35b2ab6bb20b11b7d18b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00029178C0DA32D4, sigsha=9e2b4092a6910bd4b9bf2a26e26962a5312d517a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00021178E7C7BC26, sigsha=edcb69cf3d765676de72bfcd74da96144b34213e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000099782EDC5EE7, sigsha=fdda690351753299b0aa2b496663dca199cc5081, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D778D283C523, sigsha=836e0b4f3ead3941b703bc6da6192047c919386a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006D78C844228A, sigsha=d285910f2415d6f9f7cc7663155c47ac1e48c2e5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012B7871F25107, sigsha=b19daa98082a1763fc463e548a56fd953915ff01, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F178F574EC38, sigsha=34f443ce63bc930ba5cb36cca2a7b444ba1f5d70, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D77878C9899A, sigsha=f26f846a718e44ede2de0c67611cd39df2e8bd28, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D678F5B7FDAE, sigsha=374df17c7588bb1ebd4cb958addc202a123ad3c4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009E7847DF7ECE, sigsha=e4fcc5983001a2409cadfd0771952d9dfdf5455a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003178C09DB1B2, sigsha=889a34d6c06b527b86e30d289a805a55c827ffa2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000058619D8673C1, sigsha=4df2708e94ffc94d1307a6a484b570d2170dcb5a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AA78718E6F52, sigsha=2adc3809fe340c31dd2a8c22ca6a0eb2bf5c8159, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010B782D08D1B9, sigsha=ccd68f533199715afe2d7286702ed80a21a1eeac, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BD7864C41C09, sigsha=b006634ff1002a4223faef0f5b972446d2f87d9c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A37883719C11, sigsha=c767e7d6f5d65efdcec34c7e0611259d01b5adc8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B978935ACA96, sigsha=56caa821a71244ea25fe58286a26f40756af1958, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005778E8082EDD, sigsha=83ee3268dceb164a629fdec5ca3bb6e824dd0e0a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F9788352FECD, sigsha=a7393da4c1cd0d7b3b2e916331db1cf46748e474, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BB7897FB83F6, sigsha=7535613891e94a550bd33d24bacdbb3cfab55bac, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00050978195E95FA, sigsha=9ed4e06615b3b48a3e66d5aa10d528ea4695df81, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000060787B5D8821, sigsha=dad97e23ead40a85620f7216c3713e5b1b3eb00e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007C787241BD27, sigsha=9a29aa99e79febbd44c675b8760fd5de57bc358f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C678764418EB, sigsha=ae17e459dbf22cc8ed207c4fcec8cc5bee13393d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BD786121421E, sigsha=2d8cfbba23055aa72a25c383cf4f1cee8bb3f067, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00014E783DFED915, sigsha=b29ac0f73abf5737bcdda2085d4717977c8d5e3c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012578DCFB8003, sigsha=e39819d1392156cf31dd92c3b0914a771baf06ed, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007B783419E051, sigsha=bb076d3ecf4f91860f287579653af91b6d40eb6d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F878DFCE5AE7, sigsha=be092afea93f74e3f226e03f70d020d87a9506c0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000206611992D335, sigsha=e07d31096f53d0866f620bd066321fa0d4de9b8d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007178F6972617, sigsha=1b0f3caf0326952e08ecd594af98f0e51b3ffdf9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007F783EE899B2, sigsha=7093497eea02b8adbb340d7d546fc412295db6d8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008061A053F04D, sigsha=b2ba723216c3633e8b289f39bced861de1f614d1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DE782D7EFA9D, sigsha=8578b9ea40ae248357eefc33d8b1a32dab228568, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000307896F80654, sigsha=61766485afa11752f85d5c5ef9d9203339b6fede, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005461C5674BBD, sigsha=c0b1d28872c1aa916d0febed073c97d4a231e410, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000063784821D1F4, sigsha=7ee838b9904de86e89b0d57bceaf1c595c0841a1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009E78B71D42CB, sigsha=14ac9522d235f62dcba90e54d3946958878c0280, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AC78962FC711, sigsha=3eb9af048a3fb4e3e3cfdf3acbd8b159f815c811, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001B37806BFCFA3, sigsha=7b47019ffc9225e99c750979ff709d0cbbc0d171, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000677832C334F6, sigsha=465e986fc397865ee6d05d5c0704c3670174b035, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006B788BDB8C5F, sigsha=fb20752eabaf5567b99e0957b071ad9e2e7452ac, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006678AB1E59A3, sigsha=e16d26d34299c7eff89fbdbf01ba3895b2336584, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009978D4D25E09, sigsha=6866968a6897ee34c7ae14b103df28008fde4dea, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00045B614741E71A, sigsha=b49e57930918ce29d92187ff1ecdeb4a0f56a776, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007A783E82D38A, sigsha=0be93efc1eab2e77532d54501deaf7b8b3562867, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B878202651DA, sigsha=774caab437e7dc1cf5301c7df48c86cdda751d1c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008278D9DE6BA6, sigsha=ef2dc4f95e045933839ffbce77f194e80122fc8a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A1783151FF07, sigsha=9775ed58acfea26878e9b1a6e320d4042b22a158, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001B178994F0C81, sigsha=33766f9b161543719ad6a6681a4f4133685ac4c5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00019278770797D0, sigsha=f20a4b648b6a0c0c1ed71be9e090f0b63163e030, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000061785D0529E0, sigsha=dab96c9fbc722d6a2fca214e79e04a5adb9aafdf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000927852833FCD, sigsha=faa9149ad833fcc8c4ec6818fc76010ba5a3dd37, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004D781DA1EA16, sigsha=6ff5d5b8d87a6e65fbfaa2504f731844894df04e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E06102F568B8, sigsha=1bc01b17bb15175c949b079a390b488b247d9dbb, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A578070831E5, sigsha=f1a6549b2d4fb90853ab6528b12c30af86d8b3e3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006A7819B15F20, sigsha=39fe94bc3ca54fb45383970b541a031fefcbf771, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009C78816A007D, sigsha=0485c78a82c5106a10e9c0d09dd4189f6f746c57, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008878ABACB488, sigsha=fa4ba23669cf4bf155a72b847521b8c6e678013a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C2782C6B208B, sigsha=985d163bea159893ce22dfe5e3ed2a6730caf750, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000937834D3595F, sigsha=dd6793da77ab0189c52bd9f1089ae130ab7be1b5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D77844E5C5BF, sigsha=e14922c4195ac195b9a043e81721c3e52688bd08, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007478121A86A1, sigsha=067f91151a76278bc1e6d949fd5db87646ee483a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011E78D897F96A, sigsha=0652fd95571b3b2dd96378d4fe26a7b20342acd4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007478EEBBD8E2, sigsha=e512b3a3d2a267b36744ed2fdf26581041cb2c9b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010B788D5490BC, sigsha=326dc79c9694c379355fe59a38214eebf84d64db, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008678ACD6DC6E, sigsha=283b98b629456a4246594ddd5092cef5f7dd4540, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005E78F64B6AA1, sigsha=ea3fa272774a540b3957799ace2523320f05ffd5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002978FCF515BA, sigsha=70e9d57282d3a9009887d13e890b98f445580976, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001B678B5E6DAD6, sigsha=a1e7d5a3021f9f0f9f70e89556fe8ec50a28864f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000048787AF6443B, sigsha=fa2efdad9cc1ccc058e7d28c69ef1792ec1b5b0a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000089787E78B996, sigsha=fafe5483ea61106a9b0d1758b2b2bd51c9925adc, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000727889C7FAD5, sigsha=725f762a45a4d109e6675a0e22478b89c8b2bff9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001E9782A59907A, sigsha=e21b53915169eedece976a2695ee2076f05f8523, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E47837DFDE74, sigsha=01d109ef9b98f5357d9900976a0f4a22709fc309, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F878370A7529, sigsha=e98de2d9c473c97dcf4316b7f36bd6fccc30d94f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C8783542C4B7, sigsha=ee236db3a8b873f0043456a0ca87aaceabc74641, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000767855FB6A56, sigsha=05b3b8fc2999890a4a2b50f14112a171c9d2c20b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010E7872DD44FB, sigsha=f3e6de1e5cd825d5d5465f362ad0a3a78361e15d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003278756C733D, sigsha=3c89a2bf215b11ad25fc256b522c65e7c172821f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000060787A721EAB, sigsha=0d7ea48ed924e79c4ff5a10963febdd5c258593c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001CF7805B4888B, sigsha=e544508802cbb74d50fc6f432d36c668dcee2fdf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000224611CC299DD, sigsha=7ce1386b32dc65be08cd0c17b0c9587d580bf426, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009B786E1A61F5, sigsha=b5eb25803df69da874570886029c542ddc370af5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0002B76187023C2F, sigsha=51d6a8f09cafb77032483ae028a3c1577b57841b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006D61FD56F7FD, sigsha=f96a176552026303a988a1d75d7ed8fac8ddd1b9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001AC7885A696E5, sigsha=15e35757dafaa54e8014f60f3736f0a74195e7d0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0003AD78C57D0AEB, sigsha=db68c001f2f0f85aa93d311bdd827434d8fdbc6e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DB788753A978, sigsha=3a785bcf6748fb5dcac3206d55b361240ae892dc, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0002C278E5AA79B0, sigsha=2b51c4f2bb45702972273e6fe7b626bcec94ded3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EB788BC6206C, sigsha=4de3f548e98f9fca3c6611fd16e1dc844b163d2b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006F61B1BB8F0C, sigsha=7b896348967492a84c8fa7ac8079aa2a4c4926d4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004878BBBFD3B1, sigsha=add5c0b8491ab0893c8db9a16376d0a10d8b00e3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B37874139331, sigsha=9af90628573694c72f8051ef34f5ce97b4a03613, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008878EA61D82D, sigsha=87f9a716137f0b78dcbec5b3faf84c572d9a923f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009B78240FB740, sigsha=3672a979c6247bb4a44fe23d598f3204ec3749b2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012078B7D328D1, sigsha=15d8601484625513e94ac362af875f0488bcc75a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007A782D01D6E0, sigsha=2d3a0ff853b2a2ad10baca75c87e3519dfc6f561, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A278A29F519C, sigsha=c86f6a72e44c7bcd53df0c06140776380ad4f9d6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DD784C325B52, sigsha=f9299e3658eb20c1c433de2ba018176931b361be, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E78AA7E2F07, sigsha=cedf2fbfd206fde3e138838d4e77356ec52aa37a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000897875FEFCEB, sigsha=bc0a4dfcf4d54728f57e2eba372130b46b3e2569, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E7616B56E83C, sigsha=0f62ef0be0f16908dd678c93b9654637c3d29d00, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006F78C09470ED, sigsha=2a8728781da5e0e9c93cdcffb39b143f67e53814, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010461C0467D17, sigsha=bd9364e01be82693c40cac0565cb2505f3d86dc4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D178F5889025, sigsha=230d7af00be5b4cdd067764504ac2f2e3fd0f96b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E78DC0C79B8, sigsha=c918925e3261d4eef936aca60c5ef0c4e04c6e2b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B278D209C612, sigsha=75bf3f005bf54dd22d5fd8b1b26b6d653be3c074, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003278D946DC77, sigsha=0ff77868954804c20391238d9d822aaa07001706, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008C615E704FB5, sigsha=a15103e29de1475def5ecf087487187c80ce8079, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D1786BA20763, sigsha=9807d9ed4ee5113d4891fc5e9cd5e68c078b9c24, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000497895786D28, sigsha=19c16cebef329f8d574953a9f7b687e0efec9cb5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B078DB5A9974, sigsha=7726b6bf63b1d08d5f719624a5c9598132327ace, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000308784C816C88, sigsha=9d0dd5237e8f34bc3f1afb54d13df5529b672307, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BB788C899FC9, sigsha=41aa9fb88c7727556a6fe2f30bbc3241edb995d2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008F7869344DE2, sigsha=a5ea5a7fca620e5080d7bb236bb6b42180383175, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CF78F468D689, sigsha=297314f8d65938912b01f66a0c62175db7d0c178, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B2789E1E7456, sigsha=bb2c0e93ea39c19a848004b8a8b7d0657a2be151, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BE78A0FCA0E7, sigsha=0acdbb4ce67a4a24d7a1eb5993ab5dca30ce3719, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005578850A89A5, sigsha=e02af4c2b4858f799a65c2b3a48436475877e5e8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AF785CBDE10E, sigsha=d754f5bff8b42127e504082ddcaeb5c5614d36af, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000060783D329DB4, sigsha=2e5687453b4a186bd59ff7f279df084c5fbdeb09, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000062788D2AB365, sigsha=011d8a5183cb07eaecbbc767299c43558440a4a8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000927883BE3B54, sigsha=19f7d9b96e22884261ccb9cdabb2407f26e0c3f7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000807873867454, sigsha=a9da7ce84808a0072871cb2f12e33fb0dc0d33fa, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00040E788A7A3910, sigsha=17d5ecd7bc0c88630e84e9c8ac7d5b407f002df3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005578A2F22B68, sigsha=688e7b32a28abeaa40ff1e29deb36ced4757462c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F078B2AA43FA, sigsha=ae387e0b945e81fb60815a27a5430a129e7cfbf5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004F7873E5AD23, sigsha=f2da36c720ca5b54c63427b84d761e8c0844405b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009A78D8D614CF, sigsha=6e1215a19136943930e951de7ed5f45cc535a1c3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CE78454F3E6D, sigsha=0fae88a9862f5958c0c53ee45ba08f5f5bdc2a72, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004678BEF5CB86, sigsha=f51b4172b7b3d1822c824016a04d5d7334e771e0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002D7817C555E4, sigsha=6a85aebfb9ae2acfb24b787295ef94757b3b2672, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008F616579B239, sigsha=39cb0bfd194c80246680ef96a33087582c9ba865, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010578731C25BF, sigsha=bde1d4c7d497128a51e96bad042b3c7efee6ccd2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001B978D79FC227, sigsha=a46a0128d921e4b43c32bea8bcc84c996287db82, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008778F642613C, sigsha=a746edd87bca038e68b8ad607f164ab67b2fccf7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F78DB048675, sigsha=a7ad4726a9d22f9db1eba3116ac078da0a62db80, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E612F6A5ED0, sigsha=62cf5eb9484746032c331f02e16105765e5d1511, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BD78677D775A, sigsha=073a2474e7ba74c21ad48088bcb72eef9090cfa9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007778E73BAC6F, sigsha=6d0180f1a5a3cdd0cb3b1db64ef99af17d6de046, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000225785A2F1776, sigsha=90925ba9256045aaad99306a831dca41b1c0e586, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001227882E30470, sigsha=b004bac1d0f0a57f23c05e1eb21414a40567d08c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009F787CC11436, sigsha=78916d4fb69cfa0ca893e7051702369924238bcd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004378E9435C32, sigsha=afa814c404e50a10ca357a781c63e7b183b0cecf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000066780BBC7F2E, sigsha=d9301e56fe160d9dd71a1fe2a40b49ea53a8a258, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000717855AC9A17, sigsha=e54750d6ed7b2379dd764d636851fd5266d8e83f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00025278C309E384, sigsha=40852d2a8fb290e21b0cc8b7e4e548ee28759acd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AB786BC43AC9, sigsha=115ade2e5fad135db7bcd56fc1dff0d84dbcb631, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004A7819E14093, sigsha=69e90f5bf1c9d3f9e72a85fc9c5fa9ee622b73db, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008E78A0EE3142, sigsha=1f089913b8e292992f2d75064099ba5bfbdfa3ce, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005478583827BA, sigsha=17d8855846676d46c739cdc184e697d2d3e3959a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005478F50DCA29, sigsha=c634842924bbaa402355e7a0055562fa5575a8ed, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005678DD0B41CF, sigsha=fb794ddde8f49935463eb618c82aa2fa9ef030e6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008178D60801D3, sigsha=5ac767aad9c1da0174cfd9074dea5cf84f71a8a5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AF78917877BF, sigsha=491e7e1541db25b674dc4a927eefb028ccd8c435, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004D61F988740E, sigsha=b85f072902ecdb156da52d6bed10ec2d74c4f8a7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004161ED32115F, sigsha=f201dc2b39105a51b3c9488c382922d6bbc2a4b5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005E7883851775, sigsha=0e8d8afbc921475b50d03c1968edbea3959a8e6e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004E61B00CE23E, sigsha=0d7c52655ffb246df2d79aa39475e5f6cbad2523, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005F78665F6406, sigsha=0cc8fe0a47137bdb9e09097ff229488297487295, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009D78570C64F8, sigsha=feedd807c71eefab13c2871e69fdc66764ae5799, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009B782B785612, sigsha=95e537e391b33d1e2519ef86ec8bb1fcf0b3990b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007C78ADEB7787, sigsha=a831e90dc505c2835d84ad18a0b659870f0c058a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007B785AD6319B, sigsha=3d0124c23d5bd93218ddd5a72a97e9f3e2e7889c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009378FB5A723B, sigsha=ff73f60854fa51e65dba47b3efdf27528e804fe6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000040787D502580, sigsha=44548c053d02fc4d9dd4971c333e16a64ce51355, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010378FF7C4BD9, sigsha=f1a9e8f6d8751dd9865118f420025933c7262e73, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009278CCF4FD07, sigsha=1fce9fd6390e910c344023789c6d5b1b2660e699, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A6786B43D370, sigsha=f0cd28d2d59ed53bca9b6cba2e12a4fda6892d28, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010878344BCB8E, sigsha=a73148774d1575fe1b2098e9f8d47cf3eeac3ff4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F0780F1DB8AB, sigsha=9dcd78ed9675570b8745b266e5f05a30f2b96274, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000108785244D2F2, sigsha=8dcccc4a56f8545615b9493c72781dd0c6a83082, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000657869C5FE7B, sigsha=15a4b1dd2efc6512d12dd4936224d06d9f810660, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A878147C79B8, sigsha=412af62e188d7ec1e634b02f4255336ec540bcf8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001D87854AE2364, sigsha=d95e936d408f2c61b349530ab6e097385c7407ab, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D878F61F458D, sigsha=711e8898be833293b3b7d7a4cad74eeb0409c9d1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AC78694B65C8, sigsha=dfed17ce9635117d2d57472224db6ba977bca350, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0002007808439E9D, sigsha=903d6ad046ab9ad16a5869cdc76a5770729f409f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000987849FDC338, sigsha=1d9edd244ea048f9f4c345184aa04ba31da6a5dc, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007E7888F86C5C, sigsha=b8c4c0cda6003a718cf410d4445ce8dd777dada4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007E78C27A35C0, sigsha=f18f4d407d60ed1cbbec5a3b6cdea696462a0f61, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008478BDA4F062, sigsha=1b87c83645d892b99cb34f690d4766b8aa240b07, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000927826FFF8BC, sigsha=16f890627f0cdf27a3e457f6e35ed487158ceb82, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A0787CA3B286, sigsha=b1ee86b4977d48bb0e141a7e01bea5c02a17c9f3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008D780E4CEE6E, sigsha=52062acd702391419827ec66f0eecea8d3e74123, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011578AF4BC91F, sigsha=4562281d83bb5d55111544642ee08835ea33b495, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000076780BB7187A, sigsha=e522eb861c8e2840674c54f6c19533f4b77afbce, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00010078DA6C4448, sigsha=ebdd625b7c847c82b0c463aaf76c85fa875e2ba6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000031619B3F376A, sigsha=8bf56289318a894967a6b7e62952d1636b247788, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000090782671F9FE, sigsha=9ea31e3210c96d13dfe58d06e63150227451d499, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004678417C0366, sigsha=e9cec9393ca4a26177b07b0fc5e2a357bcf4b81b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000073782DEBFCD3, sigsha=6792e88e96db099bf157c371919061e4882e5cfa, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00020B781135A093, sigsha=fa909418dafdff21933ef60ee61f4cd5313ded9f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C278D9B14133, sigsha=b41deeb7c70fd774d91b6f24fab3945bbcd5bce7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000085783415F4BA, sigsha=4c32a6b1a151ad50580a3c545028442234f7cc7c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E78DFF54524, sigsha=177fee13a00e0f4b7437547331be9c3323fd1780, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00016E7807CED8E8, sigsha=69d6195f3f6e910516f39180e409ac9f644848da, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013378E9864A26, sigsha=f4c654892de68c6a87dae6e8d07a55c640b27e69, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000199787F26B9B4, sigsha=6e7b6d1bfd45c0012e9894268fc04f7502f3ed07, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009C789A9A1489, sigsha=ce10d7767cbb6d241d7366f1c0b5d313da11fb7d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003B78F5CBF175, sigsha=2c2021edc2664689bdb84f883cf1db0c9a636f26, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000070782F59FBDA, sigsha=96c995d05aefcfd50528ad3d88021d7521660c53, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A278BF314A6B, sigsha=6278c89049c5a2f5509b4e27595f143afbc0854c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A47888354614, sigsha=c979bffc10b59e31be9e7984c48d3854d2206f5a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A578ABDE98FE, sigsha=eb87e2e8b7d4c90379418a380ca1c2733a9fd687, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000767871A3814B, sigsha=1862dd11f2c2aa092d7cedc0df4117ad5a95ad35, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001027863EB5EF1, sigsha=9c38ec3bff00ef1390056a00c3d78dbe770c1b9a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002D788BA517CC, sigsha=ff06a5b0e6bb231146be292f4cfa58f6584f493b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C078516A799C, sigsha=05aa27e7c2d19013cd5c6d14e31beceb0fbf2592, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005761668EFC70, sigsha=6e14fea39bf7088caa87de098192cb8a4f17e5ed, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000617825A44C3D, sigsha=555e3d972dbe688d1ff3f6544f623e9a7706d08a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006C787A3F2786, sigsha=02dc38088a17bf21a7f5d5bab9412d5ed8a945b8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DB781D2107C5, sigsha=478a104eb250b58f8c8aa0980221cfab48261278, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007E78B4330630, sigsha=799f70346509cd339b909a389b94fab1b4aa9b76, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007778322CDC15, sigsha=edba04af6c7c628dcbdb2b2a627bde206b2934d8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000586111754976, sigsha=7b114a05295f2359dd454608aa9b5b9b7b627c78, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007B784F15084D, sigsha=5df3bfa2a43a3c729798d14a6c9eae65df468896, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C7783DD7780F, sigsha=c868f04d7b6eefdb2a50eeb19e067e8b22e1f060, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009578208CBE43, sigsha=e51ce98372ed0ad771ea76b84e35aa7ccb06b4c7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006478FE732CA2, sigsha=46c061d97416f9721d23e044b6142452617b6620, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003578E2010C6E, sigsha=1ff0e0b57f62c4af01ff667b251bcfa8d88612a0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009A786E1F68CE, sigsha=ab7e6ed63c8ba62a42ca148e202d3dc6e194e43b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D978A63D5D81, sigsha=f98720de38cf969c241ddb349a75064342267d8a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008578A38D0104, sigsha=e77e355867aede87eaf56671b5189f34eec18dad, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009A783386A94C, sigsha=aac74f095a2db40b67c3caf157d99a9ef8a446db, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BB78FFECBA06, sigsha=8a269ce11ec6552deed8fb241e04593ba8f2d436, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BB783D254C54, sigsha=c0e4354bb11c9371feabfa5e05efc0d28b9b69f5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000091617221270E, sigsha=260e42b43fcfc742dd8510ba5eade0192d3ef382, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EB78C947DD82, sigsha=515ae6eb977bef057d599927e5df6488688b9475, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005E7837714DDA, sigsha=33cbc98bff387523d439c59e6b4629477f53561a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B778C884E69F, sigsha=cc52387054de88226c6b6d9f4060314e22c059db, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000617866B9637B, sigsha=917f6d2319913f51885ab4c927d5ab28da162f3a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AA785AE9B24E, sigsha=5d7795778a8fd8bcd8f9232b1947d8b3338e60e3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004A789FBEB1F2, sigsha=d062dcf2d78529408b06db66b3f3e87f81152bff, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C67827F74E52, sigsha=ed54a23daf4e7fdc1368849cf931d48b72e35b41, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C478F27A02AD, sigsha=009a5a46cbef3181f095589ae959f771b0238681, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00001778A2AC30AC, sigsha=3d2d128d6fc48a07e5ddc3007adeec3ca1d0911e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001A0789A84C8AD, sigsha=166989f0f6ba61b9c8fc7956bb39bb0778835a42, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AB783A220FE5, sigsha=11d4176165ac3985caaf0b5331e9c984177507a6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D878750CA638, sigsha=a4bb07bd1bcd1330cec0fb409496aba645478394, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C778E3E3CE43, sigsha=964695a6cf9b62f146e48a59659d922f16cebba5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F78EAF6214D, sigsha=570276b7f74d2ccac73258a9da92dbc51ae028d8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005F7885E68483, sigsha=084f6de611e7ccf9c9eb84c65887ac8f52255f8d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C8783DEBDBA9, sigsha=8db020d83ca163783e9d3fc9428e8a708a6baf6d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000069786A107E76, sigsha=0709283b614c4ff4f53ca50e4255256f55104e2c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002878F2F73C1C, sigsha=fe8af52f53c07ed79efd34b303fb8af3e2d6bad6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005561CC8446CE, sigsha=480ae7150a0a6b8f04a334438e155fd2c2b08ff7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0003DF78F74F724E, sigsha=b13d902f4ee864452778ac721bccfdfc570c06a9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EA781F7A9FB1, sigsha=92c3b62f2714059eb7fc61f59f3787261e1fdb53, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000079782F531FD0, sigsha=4c00290a5c6e38dcd6f0091dc61918667d20cce0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000317831E24749, sigsha=bb815b59878baa29248c4867d33db5c7dd7e3e28, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A97865E497C2, sigsha=e0ad3356d5e9acd38bc083e4a0b1a7c80f24fb48, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B978B853C661, sigsha=80020573fd9565869c3aaf3b7354f5db2384ed46, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006C7848294B68, sigsha=4a0215227e7a2de27cdc9c371dd3db54e275672b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A4784200CBB4, sigsha=c68c93951c7404069067946e48d60ee6c551c818, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000178787D69BF35, sigsha=e3b3483f0e095a940ca1e9be9f0a48219c6511bd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011878A2B2A510, sigsha=b72adcecedbf6b0632437a237186e9506bb073e9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001597809C6FCD9, sigsha=4c8677f573de078c1a58208943a27244a2eb8913, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004E78D1E360CD, sigsha=8c9856f2d9d955806d3a848fc61e204846e4371a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006578D168EEEC, sigsha=a6ddddd60f8217d73dbf0fc43658cee6f9496b43, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000FB78916052B8, sigsha=05660effefb231494fa5c1786302aa29eea461fd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008378EC00A59F, sigsha=66985d06155adf663a848e3b071a189e0b7af141, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000847814B36053, sigsha=85c4e9a960dafc0c563e4e15eded525ede251eda, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00001878E843859F, sigsha=4f88ec8120f49f028a578b0d7f61aa6c831854b2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F78B3F20F00, sigsha=4d4dbea627a0986366e43613c98f297a501e5b16, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000FA784C400D0F, sigsha=2dfd4c2ff38f159e3afad81a58c72dece978e807, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F788C02DDDC, sigsha=97bcc7293bfe0fe1505e099bb9a697b9d09565f6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F61247BE582, sigsha=4702febaed91e88510ff41512b7a3f4e6b71db9b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007C782E06CBDB, sigsha=3b20bfd081e29e64da089a58be95d29ecd41bd6b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002078D998735C, sigsha=8a8ce2c346412bca03d4b6309e473fec3e619266, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003A7849BB42E0, sigsha=3bafcd1f2992b77f157e280615c96b223a2ae1e4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E7780C2B6EDB, sigsha=3e3880c0b39bea8450e0ef36ecd8cac7fc0d4a2c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AB78C7E551E6, sigsha=e8bed4a3cf32651f439e403234276e8815aaf80b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008661602E13AE, sigsha=ae279a7519029a0bfee850525e4a0e7a9b33d8ef, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000151786E8540B9, sigsha=861552c914200b5052a4d6e263f699c543ab8da7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013761D40C8ED4, sigsha=038f1e2d68ae17ab2751e74504b9ee05afaae8b6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011C782BFF59BA, sigsha=47792aaa152fb38e9d2be0335df8a9f4ffa5fe11, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003F781B2E4006, sigsha=9eb8189dd5fca7e5bf1b098bc2e096e8f74bddfe, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AB61A72563E6, sigsha=478c8594dcad8ac13570d866a133af741a20aaa5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006178D1041410, sigsha=b57a3b73ed2af2c48aaf7f0f72b1fd97b3f7063e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000FF782F1E1EBD, sigsha=fb557c4b4f314634c1f2704b7992d69b9d997f96, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005278C2E3CBDB, sigsha=b05db105d709c220ac456a26e8ec514598e8bd26, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008578AA419739, sigsha=368fdd84a472f6d00fdcefab2c68720b411237a6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006678D83DD950, sigsha=cb8bc96568d9255f006424858feacb00298608f8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008778F7BFC7B1, sigsha=00cdb8fb0d046282768152d2ce72a83bc738a149, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000947867C8386B, sigsha=27d4d8edb524ab98330c694d38d22a62b18d8d77, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000587804556A86, sigsha=3c273198b3ff275486e4eb62f536baa54d5115d6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A0789B8D8CD0, sigsha=0f65407d65fa7a72d6c4345b74bd1f685d6b8c54, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005D78BBB9B9E6, sigsha=7745fb2961507e5ee1fd5e0b0e4aa21f409b8d8d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000080782124ECE6, sigsha=70b943dfe3fd4406ab3f611007dd4ff8d9bb58b2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B878469FFEC1, sigsha=d0caccef249a249afc390535c3d31c34ba5e65ed, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B878B128DA84, sigsha=3ed642c22f6ebf0498ab8bde2c961ffe03637584, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EC786F704837, sigsha=9f26d48db3818e7e9dd0eedffb28e51614c3c322, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00018178D79E21F1, sigsha=56ed828343c17f80178322b5df6679a5a0a26df1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000050789EE7E425, sigsha=1324ba572c55d8235a4eef69e7dbd4daacca80b7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004078542137F9, sigsha=9bf259ca99b54974d1ebf3ec1cd53b3f2c699e24, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005078345315FB, sigsha=ff184388c9348ecc1d48ceffd8f45eebeb9d69cf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BF78CCF89BFD, sigsha=8193dd50945c411dab531c0d84d2ca6a0a40399f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000109786E540976, sigsha=65f08b19bf218a0652e55650938515f95ace95d1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002161CA9344FF, sigsha=ae6410f4b6cdfddbbc6e8c5665a4302c3006551d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000737814388AE8, sigsha=a41026ee2c9b1014a1486a07f5fa7fa4b460beda, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009B783999D64F, sigsha=d27141e5b31b3f5eec4108202ad2f5504c14a413, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00017E780DC6A5D1, sigsha=5233d2d2098e128f7908cd0c9c913835426455d8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0001EE7862836D99, sigsha=4e6aad03c676612d50e935a3a996ab5d8bf6c998, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012E788C0A6058, sigsha=907c8589adc195ad4ca7ce18cd19c0983df20983, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00012A789CC5FD36, sigsha=fa405b980423480a078978ee095c172e3af915de, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008778D6848EDC, sigsha=ccfbd97ac26cd646b908a32ad66172ab32acea05, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A0787CC2F666, sigsha=96cd6666c79a48882ec3ac3f65190b11337beda9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005378D86AA20F, sigsha=54f285a051b23a97951b8c6674646cfab7186080, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005E784E61762B, sigsha=19e52faa672a00e925bd8d8b3a28a00e3267277b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C378C7AAF053, sigsha=396564cdd0f7a8185aea5e32126bd1f50200bd9b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CE780543C21D, sigsha=df7f018832410fef1da7dfb3c7a369a3fc24be1a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000059787CCDEA0D, sigsha=739a188dbe0be16803fb36972dbe2f1a04db9a5e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00001861E94F84A3, sigsha=09df5268f3e3e647b2b7716755573dc6f6d416ee, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A7780A86C942, sigsha=40b039696ee165ef6b85ec9c2bc9d270031b9079, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013B784C653D68, sigsha=4e5e2654179ff491f71f7bb24e16b08942d5521f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000ED7892A80CCC, sigsha=bbea1e7ec996d077145893c4a43b388f4cc08b4d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DB782F1EF4A5, sigsha=e42acd98925d0e8ddddfe2fae71d09fcf64403fe, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00022C785C9D4E8C, sigsha=39e77da757061f5988fa14d4c9668088057d279a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E378A6F3A4B3, sigsha=7164e068623cb081f8d2b008f15ada6051d05337, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000E27822748EE5, sigsha=b1862b395f73652af786ffe0efdba8597918fc8f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A57870C5DB53, sigsha=515ee09f2651d1998b784344d674c4c478b47c97, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006478A85D5DD0, sigsha=f36ddc955e3caff69272e4382549ac876d8d93e9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013678AEA2151B, sigsha=f0bead5de80001d11fa5a7f16cf937b262c23b91, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D878C5930CD1, sigsha=bfc64f369536b8b6e9e40a57d1f24b4a2006b0bd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007478F0A306A0, sigsha=770d0f5938041c00ad0ee1b8a2e88c3bf2dba368, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000080782F419499, sigsha=c1869b313208a9d7e7b1d31fbdea2c23a86c4fce, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006C7897D0D3CC, sigsha=df8f375654dbaf8d9d3c90bff1debb246fefa455, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008B781BE3E7FD, sigsha=8c6e6dbe62d36c1a3706b4b2a4fff7ebedcb2c8b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008078C5437BE5, sigsha=4dcfd8736a4664472699ac9d94a9ecd6b7c0f682, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D278A91F7BA4, sigsha=1a82b4222b949e2d489fe04d0b9dbbe0424cb9ac, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007F782A784CFE, sigsha=abaf0ab69bafaea43bdc5f5f15ae0230fd095b94, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006578862CA7A5, sigsha=83e08b50b641abf23ea8360baa3f940d31708235, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007B78449B0C9D, sigsha=e04867b8ffbbac310bc98acd73442a7269312ba2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006A78A7E40F60, sigsha=ba564cf5066b48675d099c14a05fb7bc03706a50, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003478EB0D3811, sigsha=3ab09d59387db0bd626cf308d3605c5ad1263365, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007F786EF5CBC9, sigsha=5e49e7ec230826c499132d373b0e5c8b389fbca0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E61F4201CDC, sigsha=3a9c9ee26c9887dce9405091f58a63152d018e49, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000997891BB0490, sigsha=a3c4f141a89d8b017f776bf3338dedbfccacda8a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EE61DFEBBFBB, sigsha=cc1270174d9f68f6189342258994d95457f6084b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000FF78623343D5, sigsha=143cf75a47292c5b7f9ae73afc7a19d8a6f1a9e0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A778FE512EBD, sigsha=5e336842592e5541fd5643b0b866d2920f23eb3b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000447896B2C9FE, sigsha=f82cf48f43a0fc3ac4eddfe7064cf73dc1f913f6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007878C6A94904, sigsha=6bc38df80b30f1318081f9b8fd9937bb7b51124b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005D78234B94B1, sigsha=82faaa032680018dd1349cc668880084c9900a21, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002D7833A498B9, sigsha=39ced22166b31de591abd869107397d8e9a520b3, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000034786C4C88EF, sigsha=353e537c9b195b706ceb77051ca9b1b99c07df5b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002D781CF85FFE, sigsha=48d980487bc8713bfcfc3615bd456cb57c1adeed, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002678DFDB556C, sigsha=465d3222f5d73e30d38458767835272fa46da9a7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002E787F0AD240, sigsha=371da32666d392a5961391ce4d39d1efe26b489a, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003A7801DACE45, sigsha=df5794f3bcd7a6892b76c3aa12a5a7a51a2daa77, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003678413CCC9F, sigsha=51c0be95be70c340de7ac3c03eb06ce453d41045, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B678D5E88875, sigsha=341cb10f2b93aca568adb59cf59a7b2516ce11c7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003178207979D9, sigsha=0b67d726651e43fbe7305adcbb7dd7bf16886758, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003578BB0ED951, sigsha=0eb5c035cd9af26c44af2ec69cd1479e1613a476, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D67841588BEE, sigsha=fba9e9bbd3e353edd736d0032087ebf749e7ba3f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000407898F8A90F, sigsha=bd953f4599f06dcee277d1c2fedb2cbce3cfdbbf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004A7851D78FFA, sigsha=ef3ec304825e27ae6dd0d7c1409bfe8b11eaf407, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004778A4DCCC1C, sigsha=b6c6ad9f1fd33be94eca6dcba959ccb1d32ed2be, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A3788C7AA837, sigsha=35ceebcc1e6a4a73064f7fd3a59de0c1b28cdad9, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003C786B4D12D3, sigsha=033279bb998ce82d61e021de697bcae5ef91e007, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000447828048F46, sigsha=7b60c1a9e5e479f54f9f281d6c3d0bceadc3cb8f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000040781E093745, sigsha=78999a2aaf9a3ac299e6c9bba9472d901ddcc42c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003D7810BBABED, sigsha=fd8760a7ab9fd1b67272b8422775a9958e7bea39, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004E78E26B87B1, sigsha=c16283a6168cc72f3439f2f03af964317b04d203, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003D78340057AA, sigsha=bfab111c1627a627b23b09223944e51eed16cbf4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004478AC083AF7, sigsha=ffa294b32640e480452e652267873f8c78596e69, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000497862B13204, sigsha=8871851378f3831871932e29d69b7e7d82b4f5f5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005B781E19FFAA, sigsha=aeffc91b771467c4eddc107d7321c144d3a8fb7f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007E78F8C7ED5B, sigsha=addcfcf94cfc81ccac34b113fe6e16391b00406d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000EC78A290444B, sigsha=a2b792e64a2f4582ea2730627eb535c9d8aec2aa, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000058783731282B, sigsha=db1f99a07a1405f48ac1d8b119848566002f0cd0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005378FC5002BA, sigsha=69f5cc1b922509bb9e165f50ab9dd212ead2c750, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006578C39E7470, sigsha=77b16ea37bdf657f47d78d6a8fd1d6bf98b3ba2d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006A784CCB0E97, sigsha=c9f3744efbe4900ba1a252fae6831f5a91a95c42, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00007B78365A7A5B, sigsha=eaf7cb4af65a72c790139a06f7544465fbd9a324, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006478568833B5, sigsha=a0977909bb8588b9e00cfefa621dba4bf3ab2ed6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A87872D8069F, sigsha=3f52d8429334687acaf5f2ca282260548fb7978e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AE78F0ED36FA, sigsha=a04f82aa14afa490841b53c7a35ca3bd1299d20d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006F78572001C5, sigsha=54f9801d113c9cfbd622217cd042285e87ca418f, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00006E78C6C5EE81, sigsha=20ed2de6bd94334e6e1680adade2259b4ddd0ccd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000F37881B3796C, sigsha=5e58e02b40f33f65df271e00e54c573a5bdc3ea7, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008F783624A828, sigsha=ccdc66ab7c780eab1bac71e263a53bfb03a1b0b6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CB784A653B8F, sigsha=e77762e961d926ad399bc634eb1c5f5bc2a98445, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013B78820A5003, sigsha=e5a1e7b50182eede2de0708158b31ef8f5746028, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00008578D49C1B39, sigsha=7c9f6637ff3b81c64c3a8e2d590ad6db3b00c34b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000927843DDB67C, sigsha=17f7f08a82a12168773a211a7c38d69f9170f503, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00013578328E4029, sigsha=ec00c0c480e7ba8f7304ec98bdb28a1ac57ddc82, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A17859DA7E2C, sigsha=0019605c33a79890e828055044f6d954a0efb193, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000FF78580C0E66, sigsha=76d736b20a9e05c2e8841d867847f359cdcc6c9c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000A4785B97421D, sigsha=084f9da68ffbade9820b37252f68a948430a27a8, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000024617D0EB055, sigsha=b4c361a7dac40d2a28447d17d87f02bc4b3cca68, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003361B3785145, sigsha=77e791e42a6a5f372c833a5d55b6de4d5c905daf, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00003D61C56CB047, sigsha=c38ce566d0af07b8b12c70d7d226e3b6903fa85e, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000052614D0AA760, sigsha=cb847404d340bfa649345246f95e6285daf89461, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00005C61185D4FF7, sigsha=392d41446bff42acd43328d9947b7d4757647b6c, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004278782CDE25, sigsha=5e021a031123fd3041862746fee4aad73fa609cd, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B561BAA54DC6, sigsha=b9a7b71c1bc492302f808cfe6c8ed080db32f1b0, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B56132FE821E, sigsha=b2f2647b1c4c53b905cc004e17d27128e457e218, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C0785D92564B, sigsha=009fac7f08b5dd53716826925d0e60e46bcfec16, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CF61860B8F0A, sigsha=c3bbd2d5b426308822009fba01621c6abc36f4a2, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000100613BFDB684, sigsha=19ee3446ba601cf10b3cb8f16b63c45b71ad3aab, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00016A613E3000FE, sigsha=394d47b8c7b9e09aedb9ec90f9b20094be0ea68d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000282616CEE44C1, sigsha=1e088b211ced7e5d67c5d2dbb5ab2da6981c6ced, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000AF78E6AC4F5C, sigsha=aa2c69a29af5ff46c899150e0b2d1e68230a09d4, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B478107D721B, sigsha=3d292d7378cf6a5e57e76e2dc599fbe3dc9df54d, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000B8787AC08D1B, sigsha=331f208621256059de9a53dce253776ace8d86ad, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000BE78DDB47D75, sigsha=15cc3b2f5c0b757b7951028297f31e6797df4f81, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000CC78EFAFAFF7, sigsha=07b64a652e0f0d3d7aa069407b94a580c536b361, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C7788F379D78, sigsha=ad8489179e9c998e813736ffaa7d1b522fb91051, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00015B78BE11896F, sigsha=84b381f607dc7b5f54aa40c936f37b4ecc1ff010, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00011978FCF43579, sigsha=e17a1f5f4cd9308868cad8044a4fa17401b79333, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00004D78371425D0, sigsha=2df1579e6e6590ed27827ffa8a95c912ded51f82, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00014E78D02ECB6F, sigsha=bc551436a2fc685d82f17d9d97db05302bda7251, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002278937E628D, sigsha=f203999d20186ae11eb6141cbe72b230a7d31dfe, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002A785F5AED34, sigsha=2a566bd9d1ad332ce0c960f79427b866adff7356, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00002378A0C4ABA2, sigsha=c877810ed930014e689a0f70f771ace4e3ba60c6, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x000025784B126EF9, sigsha=d2e0aec257c4b7c66aaad3c0e842864d8fc66fe1, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00017378B28248FA, sigsha=3d5b94673c39c80eab59411bed2bb8fbbabd9b67, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x00009D7849E7EBEC, sigsha=7b534e7801ed9188a6f4468efad8e282d8d16a09, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C77880A3C717, sigsha=c146a853304d88ecca5d31b7252062ea35021489, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000DE786ED532D5, sigsha=2946695a2caf5f2600aa87e4f6ba8660db655d0b, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000C278F71A8014, sigsha=e715bda19d34a736c8a5bc3704933282bdaf8ef5, cached=false, source=0, resourceid=0x2573ae51 Internal signature match:subtype=Lowfi, sigseq=0x0000D7780B71337B, sigsha=2a17e205de49bc816d802b8c912ce5b53844b1c0, cached=false, source=0, resourceid=0x2573ae51 2026-05-13T12:48:06.889 Engine:SMS threat match: Backdoor:Win32/CobaltStrike.C!dha, sigseq=0x00004861ACAEFEBB, sigsha=7e88c4f6e763bf477b08f542402e6039e036847c, pid=9952 2026-05-13T12:48:06.889 Engine:SMS scan for process: \Device\HarddiskVolume3\Windows\System32\MRT.exe pid: 9952, sigseq: 0x4A6B3613A1967 2026-05-13T12:50:42.871 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-13T12:50:42.996 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T12:51:03.674 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9230, FileId: 0x14d000000001535, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:51:03.752 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9232, FileId: 0x99000000003c95, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:51:26.002 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-13T12:51:26.002 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-13T12:51:26.002 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-13T12:51:26.002 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-13T12:51:26.002 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-13T12:51:26.111 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:4D88EBA0-E63A-4747-836C-F44F87907741, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-13T12:51:26.111 Scheduled scan with Id 4D88EBA0-E63A-4747-836C-F44F87907741 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-13T12:51:26.111 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-13T12:51:26.111 [SFC] System file cache build is not needed (already completed) 2026-05-13T12:51:26.736 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:51:27.564 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-13T12:51:27.783 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-13T12:51:27.799 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-13T12:51:28.127 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:51:28.142 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:51:28.142 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:51:28.220 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-13T12:51:28.283 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-13T12:51:28.424 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-13T12:51:28.439 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-13T12:51:28.611 Bm signature throttled:0x00002db31bed458f 2026-05-13T12:51:28.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-13T12:51:28.736 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-13T12:51:28.736 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10609, FileId: 0x60000000003fd6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T12:51:28.799 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-13T12:51:28.955 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-13T12:51:29.142 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-13T12:51:29.314 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-13T12:51:29.470 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-13T12:51:29.470 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:29.502 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-13T12:51:29.642 Engine:Setting original file name "Annot.api" for "c:\program files\adobe\acrobat dc\acrobat\plug_ins\annots.api", hr=0x800710da 2026-05-13T12:51:29.736 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-13T12:51:29.799 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-13T12:51:30.080 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-13T12:51:30.299 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-13T12:51:30.330 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-13T12:51:30.658 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-13T12:51:30.783 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-13T12:51:31.267 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-13T12:51:31.330 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:31.549 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-13T12:51:31.658 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-13T12:51:31.799 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-13T12:51:32.017 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-13T12:51:32.095 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-13T12:51:32.111 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-13T12:51:32.158 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-13T12:51:32.361 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-13T12:51:32.439 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-13T12:51:32.564 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-13T12:51:32.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-13T12:51:34.401 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-13T12:51:34.417 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-13T12:51:34.651 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-13T12:51:34.714 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-13T12:51:35.276 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-13T12:51:35.308 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-13T12:51:35.308 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-13T12:51:35.323 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-13T12:51:35.386 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-13T12:51:36.105 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-13T12:51:36.261 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-13T12:51:36.589 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ko.dll", hr=0x800710da 2026-05-13T12:51:36.683 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-13T12:51:36.886 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-13T12:51:36.964 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-13T12:51:37.058 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-13T12:51:37.105 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-13T12:51:37.120 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-13T12:51:37.136 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-13T12:51:37.417 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\systemresources\themecpl.dll.mun", hr=0x800710da 2026-05-13T12:51:37.573 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-13T12:51:37.589 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-13T12:51:37.823 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-13T12:51:37.870 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-13T12:51:38.245 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-13T12:51:38.386 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-13T12:51:38.448 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-13T12:51:38.745 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-13T12:51:38.808 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-13T12:51:39.339 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-13T12:51:39.433 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-13T12:51:39.448 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-13T12:51:39.558 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-13T12:51:39.573 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-13T12:51:39.620 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-13T12:51:40.073 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-13T12:51:40.151 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-13T12:51:40.292 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-13T12:51:40.323 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-13T12:51:40.542 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-13T12:51:40.745 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-13T12:51:40.839 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-13T12:51:40.886 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-13T12:51:41.042 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-13T12:51:42.339 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-13T12:51:42.448 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-13T12:51:42.589 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:43.204 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:43.344 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-13T12:51:43.891 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-13T12:51:43.954 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-13T12:51:44.188 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-13T12:51:44.313 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-13T12:51:44.360 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-13T12:51:44.391 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-13T12:51:44.704 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-13T12:51:44.813 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-13T12:51:44.891 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-13T12:51:45.001 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-13T12:51:45.016 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-13T12:51:45.126 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-13T12:51:45.251 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-13T12:51:45.360 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-13T12:51:45.422 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-13T12:51:45.454 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-13T12:51:45.454 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-13T12:51:45.670 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-13T12:51:45.685 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-13T12:51:45.826 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-13T12:51:46.310 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-13T12:51:46.545 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-13T12:51:46.592 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-05-13T12:51:46.920 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-13T12:51:46.982 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-13T12:51:47.014 Bm signature throttled:0x00002db31bed458f 2026-05-13T12:51:47.029 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-13T12:51:47.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-13T12:51:47.185 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-13T12:51:47.185 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-13T12:51:47.342 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-13T12:51:47.514 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-13T12:51:47.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-13T12:51:47.810 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-13T12:51:48.201 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-13T12:51:48.310 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-13T12:51:48.640 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-13T12:51:48.719 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-13T12:51:48.754 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-13T12:51:48.890 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-13T12:51:48.898 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-13T12:51:49.068 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-13T12:51:49.241 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-13T12:51:49.346 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-13T12:51:49.354 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:49.663 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-13T12:51:49.960 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-13T12:51:50.004 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-13T12:51:50.053 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-13T12:51:50.177 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-13T12:51:50.546 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-13T12:51:50.636 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-13T12:51:52.974 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:53.570 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-13T12:51:53.697 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-13T12:51:53.729 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_lt.dll", hr=0x800710da 2026-05-13T12:51:53.807 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-13T12:51:54.197 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-13T12:51:54.244 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-13T12:51:54.260 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-13T12:51:54.588 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-13T12:51:54.854 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-13T12:51:55.025 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-13T12:51:55.197 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-13T12:51:55.213 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-13T12:51:55.463 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-13T12:51:55.619 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-13T12:51:55.650 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-13T12:51:55.760 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-13T12:51:56.291 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-13T12:51:56.369 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-13T12:51:56.369 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-13T12:51:56.479 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-13T12:51:57.057 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-13T12:51:57.166 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ro.dll", hr=0x800710da 2026-05-13T12:51:57.260 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-13T12:51:57.354 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-13T12:51:57.400 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-13T12:51:57.572 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-13T12:51:57.682 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-13T12:51:57.729 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-13T12:51:57.854 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:51:57.979 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-13T12:51:58.150 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-13T12:51:58.260 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_fi.dll", hr=0x800710da 2026-05-13T12:51:58.291 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-13T12:51:58.369 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-13T12:51:58.635 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-13T12:51:58.682 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-13T12:51:58.775 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-13T12:51:59.525 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-13T12:51:59.979 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-13T12:52:00.010 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-13T12:52:00.104 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-13T12:52:03.158 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-13T12:52:03.549 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-13T12:52:03.611 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-13T12:52:03.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-13T12:52:04.002 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-13T12:52:04.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-13T12:52:04.377 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-13T12:52:04.455 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-13T12:52:04.502 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-13T12:52:04.533 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-13T12:52:04.642 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-13T12:52:05.049 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:52:05.330 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-13T12:52:05.377 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-13T12:52:05.908 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-13T12:52:06.158 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-13T12:52:06.283 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-13T12:52:06.486 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-13T12:52:06.814 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-13T12:52:06.877 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-13T12:52:07.049 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-13T12:52:07.095 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-13T12:52:07.174 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-13T12:52:07.283 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-13T12:52:07.314 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-13T12:52:07.314 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-13T12:52:07.361 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-13T12:52:07.377 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-13T12:52:07.627 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-13T12:52:07.627 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-13T12:52:07.658 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-13T12:52:07.736 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-13T12:52:08.585 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-13T12:52:08.788 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-13T12:52:08.804 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_tr.dll", hr=0x800710da 2026-05-13T12:52:09.038 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:52:09.288 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-13T12:52:09.413 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-13T12:52:09.663 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-13T12:52:09.898 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-13T12:52:09.960 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-13T12:52:10.101 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-13T12:52:10.413 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-13T12:52:10.476 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-13T12:52:10.523 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-13T12:52:10.538 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-13T12:52:10.538 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-13T12:52:10.601 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-13T12:52:10.882 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-13T12:52:10.898 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-13T12:52:11.148 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_it.dll", hr=0x800710da 2026-05-13T12:52:11.351 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-13T12:52:11.445 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-13T12:52:12.007 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-13T12:52:12.320 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-13T12:52:12.398 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-13T12:52:12.460 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-13T12:52:12.913 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-13T12:52:13.288 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-13T12:52:13.632 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-13T12:52:13.679 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-13T12:52:13.929 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-13T12:52:14.070 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_da.dll", hr=0x800710da 2026-05-13T12:52:14.148 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-13T12:52:14.210 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-13T12:52:14.304 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-13T12:52:14.648 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-13T12:52:14.663 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-13T12:52:14.804 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-05-13T12:52:15.085 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-13T12:52:15.116 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-13T12:52:15.835 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-13T12:52:16.070 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-13T12:52:16.163 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:52:16.288 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-13T12:52:16.695 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-13T12:52:16.788 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-13T12:52:16.835 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-13T12:52:16.866 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-13T12:52:16.929 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-13T12:52:16.945 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:52:17.070 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-13T12:52:17.132 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-13T12:52:17.429 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-13T12:52:17.491 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-13T12:52:17.538 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:52:17.648 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-13T12:52:18.023 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-13T12:52:18.148 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-13T12:52:18.320 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-13T12:52:19.210 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-13T12:52:19.632 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-13T12:52:19.710 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-13T12:52:20.023 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-13T12:52:20.413 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-13T12:52:20.804 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-13T12:52:21.132 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-05-13T12:52:21.273 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-13T12:52:21.382 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-13T12:52:21.835 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-13T12:52:22.023 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-13T12:52:22.054 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-13T12:52:22.241 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-13T12:52:22.257 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-13T12:52:22.726 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-13T12:52:22.788 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-13T12:52:22.851 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-13T12:52:23.122 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-13T12:52:23.341 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-13T12:52:23.387 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_vi.dll", hr=0x800710da 2026-05-13T12:52:23.466 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-13T12:52:23.512 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-13T12:52:23.544 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-13T12:52:23.700 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-13T12:52:24.247 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-13T12:52:24.481 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-13T12:52:24.528 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-13T12:52:24.731 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-13T12:52:24.825 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-13T12:52:25.106 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-13T12:52:25.106 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-13T12:52:25.122 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-13T12:52:25.403 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-13T12:52:25.528 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-13T12:52:25.825 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-13T12:52:25.903 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-13T12:52:25.981 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-13T12:52:26.012 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-05-13T12:52:26.059 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-13T12:52:26.872 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.22000.2538_none_da66fd59ee613b34\applytrustoffline.exe", hr=0x800710da 2026-05-13T12:52:27.012 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-13T12:52:27.059 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-13T12:52:27.247 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-05-13T12:52:27.294 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-13T12:52:27.387 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-13T12:52:27.450 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:52:27.528 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-13T12:52:27.544 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-05-13T12:52:27.575 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-13T12:52:27.747 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-13T12:52:27.794 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-13T12:52:27.856 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-13T12:52:27.887 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-13T12:52:27.903 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-13T12:52:28.200 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-13T12:52:28.325 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-13T12:52:28.387 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-13T12:52:28.419 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-13T12:52:28.653 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-13T12:52:28.762 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:52:28.794 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:52:28.794 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-13T12:52:29.153 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-13T12:52:29.622 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-05-13T12:52:29.731 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-05-13T12:52:29.841 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-13T12:52:29.919 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-05-13T12:52:30.091 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-05-13T12:52:30.184 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-05-13T12:52:30.278 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-05-13T12:52:30.403 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-05-13T12:52:30.434 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-05-13T12:52:30.466 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-05-13T12:52:30.684 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-05-13T12:52:30.762 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-05-13T12:52:30.778 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-05-13T12:52:30.778 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-13T12:52:31.325 Engine:Setting original file name "uasp.sys" for "c:\windows\system32\driverstore\filerepository\uaspstor.inf_amd64_ead2ec56d8760a84\uaspstor.sys", hr=0x800710da 2026-05-13T12:52:31.591 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-05-13T12:52:31.716 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-05-13T12:52:31.794 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-05-13T12:52:31.934 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-05-13T12:52:32.200 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-05-13T12:52:32.216 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-05-13T12:52:32.591 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-05-13T12:52:32.684 Engine:Setting original file name "msdxm.ocx" for "c:\windows\syswow64\dxmasf.dll", hr=0x800710da 2026-05-13T12:52:32.966 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-05-13T12:52:33.028 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-05-13T12:52:33.138 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-05-13T12:52:33.142 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-05-13T12:52:33.236 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_flac_plugin.dll", hr=0x800710da 2026-05-13T12:52:33.329 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\de-de\wsepno.dll.mui", hr=0x800710da 2026-05-13T12:52:33.579 Engine:Setting original file name "iscsiexe.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a56629be7473c8fd73a9fa129c67ea10\iscsiexe.dll.mui", hr=0x800710da 2026-05-13T12:52:33.673 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\11a533a2a1579c078648dff16787f54d\winnlsres.dll.mui", hr=0x800710da 2026-05-13T12:52:33.704 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sr.dll", hr=0x800710da 2026-05-13T12:52:33.861 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_udp_plugin.dll", hr=0x800710da 2026-05-13T12:52:33.861 Engine:Setting original file name "hgclientservice.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\3bbe55bd039ee800ee6a295dceb66af6\hgclientservice.dll.mui", hr=0x800710da 2026-05-13T12:52:33.923 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\bcf69d5438188e70293457b0ada7ebac\aeevts.dll.mui", hr=0x800710da 2026-05-13T12:52:33.954 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\system32\devobj.dll", hr=0x800710da 2026-05-13T12:52:34.517 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\websockify\melt command websocket.vshost.exe", hr=0x800710da 2026-05-13T12:52:34.548 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libudp_plugin.dll", hr=0x800710da 2026-05-13T12:52:34.673 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\libmarq_plugin.dll", hr=0x800710da 2026-05-13T12:52:34.829 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libasf_plugin.dll", hr=0x800710da 2026-05-13T12:52:34.986 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-13T12:52:35.329 OriginalFileName Maintenance::9871 files in Moac, 239 skipped (cached), 1 filename set 2026-05-13T12:52:35.329 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-13T12:52:46.986 Engine:Triggered AR EMS scan 2026-05-13T12:52:47.002 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.017 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.033 Engine:EMS scan for process: svchost pid: 552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.033 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.033 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.048 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.048 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.064 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.064 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.064 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.080 Engine:EMS scan for process: svchost pid: 1496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.080 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.080 Engine:EMS scan for process: svchost pid: 1512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.095 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.095 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.095 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.095 Engine:EMS scan for process: svchost pid: 1988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.111 Engine:EMS scan for process: svchost pid: 2008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.111 Engine:EMS scan for process: svchost pid: 996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.111 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.111 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.127 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.127 Engine:EMS scan for process: svchost pid: 2400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.127 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.127 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.127 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.142 Engine:EMS scan for process: svchost pid: 2648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.142 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.142 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.142 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.142 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.158 Engine:EMS scan for process: svchost pid: 3076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.158 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.173 Engine:EMS scan for process: svchost pid: 3196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.173 Engine:EMS scan for process: svchost pid: 3548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.173 Engine:EMS scan for process: svchost pid: 3848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.173 Engine:EMS scan for process: svchost pid: 3856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.189 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.189 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.189 Engine:EMS scan for process: svchost pid: 4008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.220 Engine:EMS scan for process: svchost pid: 4080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.220 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.220 Engine:EMS scan for process: svchost pid: 4264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.220 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.236 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.236 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.236 Engine:EMS scan for process: svchost pid: 4624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.252 Engine:EMS scan for process: svchost pid: 4760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.252 Engine:EMS scan for process: svchost pid: 4776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.252 Engine:EMS scan for process: svchost pid: 5244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.267 Engine:EMS scan for process: svchost pid: 5624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.267 Engine:EMS scan for process: svchost pid: 5620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.283 Engine:EMS scan for process: svchost pid: 5844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.283 Engine:EMS scan for process: dllhost pid: 4060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.283 Engine:EMS scan for process: svchost pid: 948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.283 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.283 Engine:EMS scan for process: svchost pid: 6228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.298 Engine:EMS scan for process: svchost pid: 1296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.298 Engine:EMS scan for process: svchost pid: 6960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.298 Engine:EMS scan for process: svchost pid: 7040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.314 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.314 Engine:EMS scan for process: svchost pid: 5084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.314 Engine:EMS scan for process: svchost pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.330 Engine:EMS scan for process: svchost pid: 4044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.330 Engine:EMS scan for process: svchost pid: 7496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.330 Engine:EMS scan for process: explorer pid: 8212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.377 Engine:EMS scan for process: svchost pid: 8440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.377 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.392 Engine:EMS scan for process: svchost pid: 8876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.392 Engine:EMS scan for process: svchost pid: 9284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.392 Engine:EMS scan for process: dllhost pid: 9720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.392 Bm signature throttled:0x00002db31bed458f 2026-05-13T12:52:47.392 Engine:EMS scan for process: svchost pid: 10020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.408 Engine:EMS scan for process: svchost pid: 9932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.408 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.408 Bm signature throttled:0x00002db31bed458f 2026-05-13T12:52:47.408 Engine:EMS scan for process: svchost pid: 13032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.423 Engine:EMS scan for process: svchost pid: 12048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.423 Engine:EMS scan for process: svchost pid: 924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.423 Engine:EMS scan for process: svchost pid: 6348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.423 Engine:EMS scan for process: svchost pid: 12740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.439 Engine:EMS scan for process: svchost pid: 5680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.439 Engine:EMS scan for process: svchost pid: 1996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.439 Engine:EMS scan for process: svchost pid: 4848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:52:47.439 Engine:EMS scan for process: svchost pid: 7156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T12:53:16.132 RPC Rundown called on ScanID: 4D88EBA0-E63A-4747-836C-F44F87907741 2026-05-13T12:53:16.132 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:4D88EBA0-E63A-4747-836C-F44F87907741. bRemoveFromList(ClientKilled):1 2026-05-13T12:53:16.132 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:4D88EBA0-E63A-4747-836C-F44F87907741 2026-05-13T12:53:16.158 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:4D88EBA0-E63A-4747-836C-F44F87907741 2026-05-13T12:53:16.158 QuickScan:ScanID:4D88EBA0-E63A-4747-836C-F44F87907741: Scan was stopped 2026-05-13T12:53:16.158 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:4D88EBA0-E63A-4747-836C-F44F87907741 2026-05-13T12:53:16.158 QuickScan:ScanID:4D88EBA0-E63A-4747-836C-F44F87907741: Quick scan aborted by callback after end stage 2026-05-13T12:53:16.158 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:4D88EBA0-E63A-4747-836C-F44F87907741 2026-05-13T12:53:16.164 OnDemandScanWorker: Scan Cancelled! scanId:4D88EBA0-E63A-4747-836C-F44F87907741, hr = 0x80508018 2026-05-13T12:53:18.174 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:53:18.174 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T12:53:18.174 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T12:55:42.986 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-13T12:55:43.002 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-13T12:55:43.017 Job Notification: New process added to job (13268) 2026-05-13T12:55:43.017 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-13T12:55:43.017 Job Notification: New process added to job (10132) 2026-05-13T12:55:43.033 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:13268] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10132]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:55:43.158 Job Notification: New process added to job (8496) 2026-05-13T12:55:43.174 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-13T12:55:43.174 Job Notification: New process added to job (5860) 2026-05-13T12:55:43.174 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8496] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5860]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T12:55:43.220 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 45328572(ms) from now at 03:31 (01:31 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-13T12:56:16.995 Job Notification: Process exited from job (8496) 2026-05-13T12:56:16.995 Job Notification: Process exited from job (5860) 2026-05-13T12:56:17.073 Job Notification: Process exited from job (13268) 2026-05-13T12:56:17.073 Job Notification: Process exited from job (10132) 2026-05-13T13:04:47.611 [RTP] [Mini-filter] OpenWithoutRead notification (3591, 10577, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-13T13:04:48.908 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13503, FileId: 0x145000000000ad7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:05:47.992 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T13:05:52.220 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #13561, FileId: 0x146000000000ad7, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:05:53.595 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-05-13T13:05:53.595 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-13T13:05:53.595 [RTP] Duplicating the current plugin configuration object... 2026-05-13T13:05:53.595 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T13:05:53.595 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-13T13:05:53.595 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-13T13:05:53.595 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-13T13:05:53.720 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-05-13T13:05:53.861 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-05-13T13:05:53.877 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 Internal signature match:subtype=Lowfi, sigseq=0x0002B1BD9E1A2199, sigsha=2d3e5dea97dd42cf08d7b1acc7f7dbc2350c80dd, cached=false, source=12, resourceid=0x6a7ae995 Internal signature match:subtype=Lowfi, sigseq=0x0002C7BD6F0B1013, sigsha=8bb06083c03020ac23ff7c874afe346f250526db, cached=false, source=12, resourceid=0x6a7ae995 2026-05-13T13:05:53.955 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:05:53.955 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:05:53.955 [Cloud] Queued cloud request. 2026-05-13T13:05:53.955 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:05:53.955 [Cloud] Dequeued cloud request. 2026-05-13T13:05:53.955 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:05:54.627 [Cloud] End of cloud request. AMSI Result:LoFi AMSI Originating Process:00001CE8 2026-05-13T13:05:54.658 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 1 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: TRUE 2026-05-13T13:05:54.752 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x3aa602547ffffffe 2026-05-13T13:05:54.752 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x3aa602547ffffffe 2026-05-13T13:05:54.767 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-05-13T13:05:54.767 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:05:54.767 [Cloud] Queued cloud request. 2026-05-13T13:05:54.767 [Cloud] Dequeued cloud request. 2026-05-13T13:05:54.799 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:05:54.861 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-13T13:05:54.861 [Cloud] End of cloud request. 2026-05-13T13:05:55.142 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:06:06.049 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C8C190A9-43DF-4EEC-9314-37312DCFE3BA}{1c2b5994-c5f5-11eb-bacb-000d3a96488e}.TMContainer00000000000000000001.regtrans-ms. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #14365, FileId: 0x107000000003afd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:06:06.049 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{3C0D6EFC-D59B-41F1-9827-242EBE3DBF6A}{11ec803f-4ec8-11f1-a181-d850e63fb470}.TMContainer00000000000000000001.regtrans-ms. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #14369, FileId: 0x13f000000003f52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:06:06.049 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C8C190A9-43DF-4EEC-9314-37312DCFE3BA}{1c2b5994-c5f5-11eb-bacb-000d3a96488e}.TMContainer00000000000000000002.regtrans-ms. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #14366, FileId: 0xb6000000003c48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:06:06.049 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{3C0D6EFC-D59B-41F1-9827-242EBE3DBF6A}{11ec803f-4ec8-11f1-a181-d850e63fb470}.TM.blf. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #14371, FileId: 0xa6000000003eb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:06:06.049 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{3C0D6EFC-D59B-41F1-9827-242EBE3DBF6A}{11ec803f-4ec8-11f1-a181-d850e63fb470}.TMContainer00000000000000000002.regtrans-ms. Process: \Device\HarddiskVolume3\Windows\System32\SrTasks.exe, Status: 0xc0000001, State: 0, ScanRequest #14370, FileId: 0x67000000003fd6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2026, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:06:08.564 [AutoPurge] Verification Routine tasks have started. 2026-05-13T13:06:08.564 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T13:06:08.595 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-13T13:06:08.595 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-13T13:06:08.595 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-13T13:06:08.595 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-13T13:06:08.595 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-13T13:06:08.595 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-13T13:06:08.611 [AutoPurge] Cleanup Routine tasks have started. 2026-05-13T13:06:08.611 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-13T13:06:08.611 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:852E986F-8AD2-4F3C-BC07-61A82C0B9456, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-13T13:06:08.627 Scheduled scan with Id 852E986F-8AD2-4F3C-BC07-61A82C0B9456 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-13T13:06:08.627 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-13T13:06:08.627 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-13T13:06:08.627 [SFC] System file cache build is not needed (already completed) 2026-05-13T13:06:08.627 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-13-2026 13:06:08 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-13-2026 13:06:08 2026-05-13T13:06:08.642 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-13T13:06:08.642 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-13T13:06:08.642 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-13T13:06:08.642 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-13T13:06:08.642 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-13T13:06:08.642 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-13T13:06:08.752 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-13T13:06:08.752 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-13T13:06:08.783 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-13T13:06:08.799 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-13T13:06:08.799 [AutoPurge] Verification Routine tasks have ended. 2026-05-13T13:06:10.627 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:06:10.642 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T13:06:10.642 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:06:13.705 Engine:Triggered AR EMS scan 2026-05-13T13:06:13.720 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.736 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.752 Engine:EMS scan for process: svchost pid: 552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.752 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.767 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.767 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.783 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.783 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.799 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.799 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.799 Engine:EMS scan for process: svchost pid: 1496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.799 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.814 Engine:EMS scan for process: svchost pid: 1512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.814 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.814 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.830 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.830 Engine:EMS scan for process: svchost pid: 1988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.830 Engine:EMS scan for process: svchost pid: 2008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.845 Engine:EMS scan for process: svchost pid: 996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.845 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.845 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.861 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.861 Engine:EMS scan for process: svchost pid: 2400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.861 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.861 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.877 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.877 Engine:EMS scan for process: svchost pid: 2648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.877 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.877 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.892 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.892 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.892 Engine:EMS scan for process: svchost pid: 3076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.908 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.908 Engine:EMS scan for process: svchost pid: 3196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.924 Engine:EMS scan for process: svchost pid: 3548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.924 Engine:EMS scan for process: svchost pid: 3848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.924 Engine:EMS scan for process: svchost pid: 3856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.924 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.939 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.939 Engine:EMS scan for process: svchost pid: 4008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.955 Engine:EMS scan for process: svchost pid: 4080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.970 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.970 Engine:EMS scan for process: svchost pid: 4264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.970 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.986 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:13.986 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.002 Engine:EMS scan for process: svchost pid: 4624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.002 Engine:EMS scan for process: svchost pid: 4760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.017 Engine:EMS scan for process: svchost pid: 4776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.017 Engine:EMS scan for process: svchost pid: 5244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.017 Engine:EMS scan for process: svchost pid: 5624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.033 Engine:EMS scan for process: svchost pid: 5620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.033 Engine:EMS scan for process: svchost pid: 5844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.049 Engine:EMS scan for process: dllhost pid: 4060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.049 Engine:EMS scan for process: svchost pid: 948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.049 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.049 Engine:EMS scan for process: svchost pid: 6228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.049 Engine:EMS scan for process: svchost pid: 1296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.064 Engine:EMS scan for process: svchost pid: 6960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.064 Engine:EMS scan for process: svchost pid: 7040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.064 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.064 Engine:EMS scan for process: svchost pid: 5084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.080 Engine:EMS scan for process: svchost pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.080 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:06:14.080 Engine:EMS scan for process: svchost pid: 4044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.095 Engine:EMS scan for process: svchost pid: 7496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.095 Engine:EMS scan for process: explorer pid: 8212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.158 Engine:EMS scan for process: svchost pid: 8440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.158 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.158 Engine:EMS scan for process: svchost pid: 8876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.158 Engine:EMS scan for process: svchost pid: 9284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.174 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:06:14.174 Engine:EMS scan for process: dllhost pid: 9720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.174 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:06:14.174 Engine:EMS scan for process: svchost pid: 10020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.174 Engine:EMS scan for process: svchost pid: 9932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.189 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.189 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:06:14.205 Engine:EMS scan for process: svchost pid: 13032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.205 Engine:EMS scan for process: svchost pid: 12048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.220 Engine:EMS scan for process: svchost pid: 924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.220 Engine:EMS scan for process: svchost pid: 12740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.220 Engine:EMS scan for process: svchost pid: 5680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.236 Engine:EMS scan for process: svchost pid: 4848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.236 Engine:EMS scan for process: svchost pid: 8468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:06:14.254 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0xf5c96b12 2026-05-13T13:06:52.392 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:06:52.392 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:06:52.392 [Cloud] Queued cloud request. 2026-05-13T13:06:52.392 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:06:52.392 [Cloud] Dequeued cloud request. 2026-05-13T13:06:52.392 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:02.439 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x9df1ce23 2026-05-13T13:07:02.845 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:07:02.845 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:07:02.845 [Cloud] Queued cloud request. 2026-05-13T13:07:02.845 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:07:02.845 [Cloud] Dequeued cloud request. 2026-05-13T13:07:02.845 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:02.970 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T13:07:02.986 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-13T13:07:02.986 [RTP] Duplicating the current plugin configuration object... 2026-05-13T13:07:02.986 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T13:07:02.986 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-13T13:07:02.986 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-13T13:07:02.986 [RTP] No config change detected. Not updating plugin configuration. 2026-05-13T13:07:02.986 [RTP] No config changes found. No configuration switch. 2026-05-13T13:07:02.986 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-13T13:07:02.986 [RTP] Duplicating the current plugin configuration object... 2026-05-13T13:07:02.986 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T13:07:02.986 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-13T13:07:02.986 [RTP] No config change detected. Not updating plugin configuration. 2026-05-13T13:07:02.986 [RTP] No config changes found. No configuration switch. 2026-05-13T13:07:02.986 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-13T13:07:02.986 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-13T13:07:02.986 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:02.986 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T13:07:02.986 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T13:07:02.986 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T13:07:02.986 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T13:07:02.986 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-13T13:07:02.986 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-13T13:07:02.986 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:02.986 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:03.002 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:03.049 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 53379291(ms) from now at 05:56 (03:56 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-13T13:07:05.549 [RTP] Duplicating the current plugin configuration object... 2026-05-13T13:07:05.549 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T13:07:05.549 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-13T13:07:05.549 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T13:07:05.549 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-13T13:07:06.158 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x83c1aa73 2026-05-13T13:07:06.174 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:07:06.174 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:07:06.174 [Cloud] Queued cloud request. 2026-05-13T13:07:06.174 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:07:06.174 [Cloud] Dequeued cloud request. 2026-05-13T13:07:06.174 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:06.564 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 2026-05-13T13:07:06.580 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:07:06.580 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:07:06.580 [Cloud] Queued cloud request. 2026-05-13T13:07:06.580 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:07:06.580 [Cloud] Dequeued cloud request. 2026-05-13T13:07:06.580 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:06.658 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:07.049 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x26b3ba41 2026-05-13T13:07:07.174 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:07:07.174 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:07:07.174 [Cloud] Queued cloud request. 2026-05-13T13:07:07.174 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:07:07.174 [Cloud] Dequeued cloud request. 2026-05-13T13:07:07.174 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:07.564 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:07.658 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-13T13:07:07.689 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:07:07.689 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:07:07.689 [Cloud] Queued cloud request. 2026-05-13T13:07:07.689 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:07:07.689 [Cloud] Dequeued cloud request. 2026-05-13T13:07:07.689 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:07:08.167 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:08.167 [Cloud] End of cloud request. 2026-05-13T13:07:08.674 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:07:20.549 RPC Rundown called on ScanID: 852E986F-8AD2-4F3C-BC07-61A82C0B9456 2026-05-13T13:07:20.549 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:852E986F-8AD2-4F3C-BC07-61A82C0B9456. bRemoveFromList(ClientKilled):1 2026-05-13T13:07:20.549 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:852E986F-8AD2-4F3C-BC07-61A82C0B9456 2026-05-13T13:07:20.549 QuickScan:ScanID:852E986F-8AD2-4F3C-BC07-61A82C0B9456: User scan error=000003e3 2026-05-13T13:07:20.549 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:852E986F-8AD2-4F3C-BC07-61A82C0B9456 2026-05-13T13:07:20.549 QuickScan:ScanID:852E986F-8AD2-4F3C-BC07-61A82C0B9456: Quick scan aborted by callback after end stage 2026-05-13T13:07:20.549 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:852E986F-8AD2-4F3C-BC07-61A82C0B9456 2026-05-13T13:07:20.549 OnDemandScanWorker: Scan Cancelled! scanId:852E986F-8AD2-4F3C-BC07-61A82C0B9456, hr = 0x80508018 2026-05-13T13:07:22.549 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:07:22.549 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T13:07:22.549 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:10:16.816 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:9F8B514D-EE9B-46F3-8A63-B709E1F77719, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-13T13:10:16.816 Scheduled scan with Id 9F8B514D-EE9B-46F3-8A63-B709E1F77719 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-13T13:10:16.818 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-13T13:10:16.818 [SFC] System file cache build is not needed (already completed) Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-13T13:10:18.831 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:10:18.837 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T13:10:18.838 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:10:19.287 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15942, FileId: 0xc2000000001372, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:10:19.918 Engine:Triggered AR EMS scan 2026-05-13T13:10:19.922 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.937 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.954 Engine:EMS scan for process: svchost pid: 552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.957 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.961 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.968 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.975 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.977 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.982 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.983 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.988 Engine:EMS scan for process: svchost pid: 1496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:19.990 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.004 Engine:EMS scan for process: svchost pid: 1512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.010 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.012 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.014 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.017 Engine:EMS scan for process: svchost pid: 1988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.026 Engine:EMS scan for process: svchost pid: 2008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.028 Engine:EMS scan for process: svchost pid: 996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.031 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.034 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.036 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.038 Engine:EMS scan for process: svchost pid: 2400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.041 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.043 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.044 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.047 Engine:EMS scan for process: svchost pid: 2648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.048 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.051 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.054 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.056 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.060 Engine:EMS scan for process: svchost pid: 3076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.066 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.069 Engine:EMS scan for process: svchost pid: 3196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.081 Engine:EMS scan for process: svchost pid: 3548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.086 Engine:EMS scan for process: svchost pid: 3848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.088 Engine:EMS scan for process: svchost pid: 3856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.098 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.103 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.108 Engine:EMS scan for process: svchost pid: 4008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.121 Engine:EMS scan for process: svchost pid: 4080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.124 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.127 Engine:EMS scan for process: svchost pid: 4264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.130 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.139 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.145 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.149 Engine:EMS scan for process: svchost pid: 4624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.163 Engine:EMS scan for process: svchost pid: 4760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.168 Engine:EMS scan for process: svchost pid: 4776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.170 Engine:EMS scan for process: svchost pid: 5244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.180 Engine:EMS scan for process: svchost pid: 5624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.182 Engine:EMS scan for process: svchost pid: 5620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.194 Engine:EMS scan for process: svchost pid: 5844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.208 Engine:EMS scan for process: dllhost pid: 4060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.210 Engine:EMS scan for process: svchost pid: 948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.212 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.214 Engine:EMS scan for process: svchost pid: 6228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.218 Engine:EMS scan for process: svchost pid: 1296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.221 Engine:EMS scan for process: svchost pid: 6960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.227 Engine:EMS scan for process: svchost pid: 7040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.230 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.235 Engine:EMS scan for process: svchost pid: 5084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.242 Engine:EMS scan for process: svchost pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.246 Engine:EMS scan for process: svchost pid: 4044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.249 Engine:EMS scan for process: svchost pid: 7496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.251 Engine:EMS scan for process: explorer pid: 8212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.295 Engine:EMS scan for process: svchost pid: 8440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.298 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.302 Engine:EMS scan for process: svchost pid: 8876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.305 Engine:EMS scan for process: svchost pid: 9284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.315 Engine:EMS scan for process: dllhost pid: 9720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.317 Engine:EMS scan for process: svchost pid: 10020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.319 Engine:EMS scan for process: svchost pid: 9932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.328 Engine:EMS scan for process: svchost pid: 6836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.331 Engine:EMS scan for process: svchost pid: 13032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.350 Engine:EMS scan for process: svchost pid: 12048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.353 Engine:EMS scan for process: svchost pid: 924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.356 Engine:EMS scan for process: svchost pid: 12740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.359 Engine:EMS scan for process: svchost pid: 5680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.365 Engine:EMS scan for process: svchost pid: 4848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.381 Engine:EMS scan for process: svchost pid: 8468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.383 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:10:20.386 Engine:EMS scan for process: dllhost pid: 3900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0xf5c96b12 2026-05-13T13:10:30.375 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:10:30.375 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:10:30.375 [Cloud] Queued cloud request. 2026-05-13T13:10:30.375 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:10:30.375 [Cloud] Dequeued cloud request. 2026-05-13T13:10:30.375 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:10:31.825 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=true, source=0, resourceid=0x9df1ce23 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=true, source=0, resourceid=0x83c1aa73 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=true, source=0, resourceid=0x483b4d60 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=true, source=0, resourceid=0x26b3ba41 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=true, source=0, resourceid=0x431643b7 2026-05-13T13:10:32.343 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:10:55.133 Engine:Process 3644 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-13T13:10:58.504 RPC Rundown called on ScanID: 9F8B514D-EE9B-46F3-8A63-B709E1F77719 2026-05-13T13:10:58.504 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:9F8B514D-EE9B-46F3-8A63-B709E1F77719. bRemoveFromList(ClientKilled):1 2026-05-13T13:10:58.506 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9F8B514D-EE9B-46F3-8A63-B709E1F77719 2026-05-13T13:10:58.506 QuickScan:ScanID:9F8B514D-EE9B-46F3-8A63-B709E1F77719: User scan error=000003e3 2026-05-13T13:10:58.509 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9F8B514D-EE9B-46F3-8A63-B709E1F77719 2026-05-13T13:10:58.509 QuickScan:ScanID:9F8B514D-EE9B-46F3-8A63-B709E1F77719: Quick scan aborted by callback after end stage 2026-05-13T13:10:58.509 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9F8B514D-EE9B-46F3-8A63-B709E1F77719 2026-05-13T13:10:58.510 OnDemandScanWorker: Scan Cancelled! scanId:9F8B514D-EE9B-46F3-8A63-B709E1F77719, hr = 0x80508018 BEGIN BM telemetry GUID:{9EB93F1B-541A-8679-E5A5-0D5814658647} SignatureID:23858905925058 SigSha:bb9deb67e0a930a74a0830b0cf819e8421704cec ThreatLevel:0 ProcessID:588 ProcessCreationTime:134231492757235488 SessionID:0 CreationTime:05-13-2026 13:10:59 ImagePath:C:\Windows\System32\csrss.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-05-13T13:10:59.539 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T13:10:59.539 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T13:10:59.539 [Cloud] Queued cloud request. 2026-05-13T13:10:59.539 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T13:10:59.540 [Cloud] Dequeued cloud request. 2026-05-13T13:10:59.541 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T13:10:59.822 [Cloud] End of cloud request. 2026-05-13T13:11:00.338 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T13:11:00.529 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:11:00.537 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T13:11:00.538 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:20:09.935 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #17051, FileId: 0x4e00000001180f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:20:09.935 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #17050, FileId: 0x5a00000001c025, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:20:09.945 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #17053, FileId: 0x5c00000001c025, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:20:52.997 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T13:23:31.166 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:372C3A19-31ED-45E4-834C-11B105481660, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-13T13:23:31.166 Scheduled scan with Id 372C3A19-31ED-45E4-834C-11B105481660 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-13T13:23:31.168 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-13T13:23:31.168 [SFC] System file cache build is not needed (already completed) 2026-05-13T13:23:32.411 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17593, FileId: 0x1300000001c5a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T13:23:33.179 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:23:33.186 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T13:23:33.187 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T13:23:35.295 Engine:Triggered AR EMS scan 2026-05-13T13:23:35.300 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.316 Engine:EMS scan for process: svchost pid: 976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.332 Engine:EMS scan for process: svchost pid: 552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.335 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.339 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.349 Engine:EMS scan for process: svchost pid: 1252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.354 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.356 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.366 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.369 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.374 Engine:EMS scan for process: svchost pid: 1496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.376 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.386 Engine:EMS scan for process: svchost pid: 1512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.390 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.393 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.399 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.402 Engine:EMS scan for process: svchost pid: 1988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.407 Engine:EMS scan for process: svchost pid: 2008, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.414 Engine:EMS scan for process: svchost pid: 996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.417 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.420 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.427 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.433 Engine:EMS scan for process: svchost pid: 2400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.436 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.438 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.439 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.443 Engine:EMS scan for process: svchost pid: 2648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.445 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.448 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.455 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.458 Engine:EMS scan for process: svchost pid: 3060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.463 Engine:EMS scan for process: svchost pid: 3076, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.469 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.472 Engine:EMS scan for process: svchost pid: 3196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.479 Engine:EMS scan for process: svchost pid: 3548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.485 Engine:EMS scan for process: svchost pid: 3848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.487 Engine:EMS scan for process: svchost pid: 3856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.493 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.499 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.503 Engine:EMS scan for process: svchost pid: 4080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.512 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.515 Engine:EMS scan for process: svchost pid: 4264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.518 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.525 Engine:EMS scan for process: svchost pid: 4400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.531 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.536 Engine:EMS scan for process: svchost pid: 4624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.544 Engine:EMS scan for process: svchost pid: 4760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.549 Engine:EMS scan for process: svchost pid: 4776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.551 Engine:EMS scan for process: svchost pid: 5244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.557 Engine:EMS scan for process: svchost pid: 5624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.564 Engine:EMS scan for process: svchost pid: 5620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.572 Engine:EMS scan for process: svchost pid: 5844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.580 Engine:EMS scan for process: dllhost pid: 4060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.583 Engine:EMS scan for process: svchost pid: 948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.585 Engine:EMS scan for process: svchost pid: 6280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.587 Engine:EMS scan for process: svchost pid: 1296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.591 Engine:EMS scan for process: svchost pid: 7040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.594 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.609 Engine:EMS scan for process: svchost pid: 5084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.628 Engine:EMS scan for process: svchost pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.631 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:23:35.633 Engine:EMS scan for process: svchost pid: 4044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.642 Engine:EMS scan for process: svchost pid: 7496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.648 Engine:EMS scan for process: explorer pid: 8212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.692 Engine:EMS scan for process: svchost pid: 8440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.695 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.704 Engine:EMS scan for process: svchost pid: 8876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.708 Engine:EMS scan for process: svchost pid: 9284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.710 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:23:35.713 Engine:EMS scan for process: dllhost pid: 9720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.715 Bm signature throttled:0x00002db31bed458f 2026-05-13T13:23:35.716 Engine:EMS scan for process: svchost pid: 10020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T13:23:35.718 Engine:EMS scan for process: svchost pid: 9932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-13-2026 14:00:51 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/13/2026 14:00:51.912038400 UTC (14625 ms since boot) 2026-05-13T14:00:51.925 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-13T14:00:51.925 WARNING: the previous service shutdown was not expected. 2026-05-13T14:00:51.929 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T14:00:51.929 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T14:00:51.974 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260513-140051-00000003-fffffffeffffffff.bin ... 2026-05-13T14:00:52.020 [WPP] Trace session started - MpWppTracing-20260513-140051-00000003-fffffffeffffffff.bin 2026-05-13T14:00:52.020 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-13T14:00:52.036 [RbM] Rollback manager succesfully initialized. 2026-05-13T14:00:52.036 [RbM] Rollback manager EnableRollbackManager called. 2026-05-13T14:00:52.036 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-13T14:00:52.036 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-13T14:00:52.036 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-13T14:00:52.036 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-13T14:00:52.036 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-13T14:00:52.036 MdCoreSvc is supported in this platform and OS 2026-05-13T14:00:52.036 MdCoreSvc is supported in this platform and OS 2026-05-13T14:00:52.036 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T14:00:52.036 [PlatUpd] Starting MdCoreSvc service 2026-05-13T14:00:52.099 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-13T14:00:55.942 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-13T14:00:55.942 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-13T14:00:55.942 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-13T14:00:55.942 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-13T14:00:55.942 [PlatUpd] CSP platform update started 2026-05-13T14:00:55.942 [PlatUpd] Defender MDM CSP platform update not required 2026-05-13T14:00:55.942 [PlatUpd] WMI/PS provider platform update started 2026-05-13T14:00:55.942 [PlatUpd] WMI/PS provider platform update not required 2026-05-13T14:00:55.942 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-13T14:00:55.942 MdCoreSvc is supported in this platform and OS 2026-05-13T14:00:55.942 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-13T14:00:55.942 [PlatUpd] Starting MdCoreSvc service 2026-05-13T14:00:55.942 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-13T14:00:55.942 [TS] Troubleshooting mode is not available! 2026-05-13T14:00:55.942 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T14:00:55.942 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-13T14:00:55.958 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-13T14:00:55.958 [Service] Enabling AutoLoggers ... 2026-05-13T14:00:55.958 [Service] Enabling AMSI registration ... 2026-05-13T14:00:55.958 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-13T14:00:55.974 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 41667 Number of invalid entries is 0 Number of inserts issued is 1582611 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6503 Number of lookups is 107967844 Number of lookup misses is 5187565 Number of fast lookup misses is 55013758 Number of false fast lookups is 5187560 Number of invalidations is 734430 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-13T14:00:55.974 Verifying license file... 2026-05-13T14:00:55.974 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll]. File not in cache (0x1) 2026-05-13T14:00:56.005 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] 2026-05-13T14:00:56.020 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-13T14:00:56.020 Loaded module#0 MpComServer. 2026-05-13T14:00:56.020 Loaded module#1 StartupPolicies. 2026-05-13T14:00:56.020 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-13T14:00:56.020 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T14:00:56.020 COM server initialized successfully. 2026-05-13T14:00:56.036 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-13T14:00:56.036 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-13T14:00:56.036 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-13T14:00:56.052 [RTP] [RTP] FilterCommunicator object 0x0000014487707A70 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T14:00:56.067 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-13T14:00:56.067 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T14:00:56.067 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T14:00:56.067 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-13T14:00:56.067 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-13T14:00:56.067 [RTP] [RTP] FilterCommunicator object 0x0000014487707C80 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T14:00:56.067 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-13T14:00:56.067 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-13T14:00:56.067 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-13T14:00:56.067 [RTP] [RTP] StartCommunication 0x0000014487707A70 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-13T14:00:56.067 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-13T14:00:56.067 [init][RTP] RTPPlugin initialization completed 2026-05-13T14:00:56.067 OS boot count = 2 2026-05-13T14:00:56.067 OS Install = 0 2026-05-13T14:00:56.067 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-13T14:00:56.067 [KSL] Entering CKSLEngine::Initialize. 2026-05-13T14:00:56.067 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-13T14:00:56.067 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-13T14:00:56.067 [KSL] MpInstallKslD: hr=0x1 2026-05-13T14:00:56.083 [KSL] MpRegisterKslD: hr=0 2026-05-13T14:00:56.083 [KSL] MpStartKslD: hr=0 2026-05-13T14:00:56.083 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T14:00:56.083 Loading engine... 2026-05-13T14:00:56.099 Verifying engine and signature files (source: 1) ... 2026-05-13T14:00:56.099 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpengine.dll] due to PPL. 2026-05-13T14:00:56.099 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm]. File not in cache (0x1) 2026-05-13T14:00:57.036 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm] 2026-05-13T14:00:57.036 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasdlta.vdm] (file in cache) 2026-05-13T14:00:57.036 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm]. File not in cache (0x1) 2026-05-13T14:00:57.474 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm] 2026-05-13T14:00:57.474 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavdlta.vdm] (file in cache) 2026-05-13T14:00:57.520 [Engine] IsHybridMode: 0 2026-05-13T14:00:57.520 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-13T14:00:57.567 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5966C72D3E93A0018E0270BC315C0CF48C9C8CEB.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-13T14:01:03.815 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-13T14:01:03.815 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_DC_DisableAadDeviceIdQuery new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-13T14:01:03.815 [Engine] New active engine 00007FF98BB15810 (no old engine). Number of active engines: 1 2026-05-13T14:01:03.862 EngineInit:Global ASOC is enabled 2026-05-13T14:01:03.862 EngineInit:ASOO is enabled for developer volumes 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.002 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-13T14:01:04.018 MpWriteUupSignatureVersion 1.449.595.0, hr = 0 2026-05-13T14:01:04.018 [SigStatUpd] CSignatureStatus: back to good 2026-05-13T14:01:04.018 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-13T14:01:04.049 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-13T14:01:04.049 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-13T14:01:04.049 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-13T14:01:04.049 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-13T14:01:04.080 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-13T14:01:04.080 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-13T14:01:04.080 [Plugin] Initializing RTP plugin state... 2026-05-13T14:01:04.080 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-13T14:01:04.080 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2} 2026-05-13T14:01:04.080 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:01:04.080 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:01:04.080 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:01:04.080 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T14:01:04.080 MdCoreSvc is supported in this platform and OS 2026-05-13T14:01:04.080 Engine loaded! 2026-05-13T14:01:04.080 [DLP] Create FeatureControlState instance 2026-05-13T14:01:04.096 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,1,0 Proc:0,1,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:2,2,0 SetEngine:1,1,0 SetState:1,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2494 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2457 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14335 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2789 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-13T14:01:04.096 RegisterSModeChangeListener: hr = 0x1 2026-05-13T14:01:04.096 RegisterHybridModeChangeListener: hr = 0 2026-05-13T14:01:04.096 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-13T14:01:04.096 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-13T14:01:04.127 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-13T14:01:04.143 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-13T14:01:04.143 [SigReleaseHb] Initialized with Stage 0 2026-05-13T14:01:04.143 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-13T14:01:04.143 [SCC][CID=26859_5304] Initializing ... 2026-05-13T14:01:04.143 [SCC][CID=26859_5304] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-13T14:01:04.143 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-13T14:01:04.143 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-13T14:01:04.143 [NRI] Stopping NIS service ... 2026-05-13T14:01:04.143 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-13T14:01:04.143 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.595.0 AV Signature Version: 1.449.595.0 ************************************************************ 2026-05-13T14:01:04.143 Resource usage Monitoring is enabled 2026-05-13T14:01:04.159 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-13T14:01:04.174 Job Notification: New process added to job (4516) 2026-05-13T14:01:04.268 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8508] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8524]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T14:01:04.284 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-13T14:01:04.299 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-13T14:01:04.299 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-13T14:01:04.299 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-13T14:01:04.299 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-13T14:01:04.299 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-13T14:01:04.299 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-13T14:01:04.299 [RTP] Generating the base plugin configuration ... 2026-05-13T14:01:04.299 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-13T14:01:04.299 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T14:01:04.299 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-13T14:01:04.315 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-13T14:01:04.315 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T14:01:04.315 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-13T14:01:04.315 [RTP] [RTP] StartCommunication 0x0000014487707C80 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-13T14:01:04.315 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-13T14:01:04.346 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-13T14:01:04.565 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-13T14:01:04.565 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-13T14:01:04.565 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T14:01:04.580 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-13T14:01:04.955 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:01:04.971 Bm signature throttled:0x00002db31bed458f 2026-05-13T14:01:07.534 [RTP] Duplicating the current plugin configuration object... 2026-05-13T14:01:07.534 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T14:01:07.534 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-13T14:01:07.549 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T14:01:07.549 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-13T14:01:38.167 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3262, FileId: 0x8a000000034a96, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:01:56.356 Process scan (poststartupscan) started. 2026-05-13T14:01:56.397 Process scan (poststartupscan) completed. 2026-05-13T14:01:56.895 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-13T14:01:56.904 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-13T14:01:59.584 [RTP] Duplicating the current plugin configuration object... 2026-05-13T14:01:59.584 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T14:01:59.584 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-13T14:01:59.591 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-13T14:01:59.592 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-13T14:01:59.953 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-13T14:02:00.033 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-13T14:02:00.033 [RTP] Duplicating the current plugin configuration object... 2026-05-13T14:02:00.033 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T14:02:00.033 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-13T14:02:00.033 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-13T14:02:00.064 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-13T14:02:00.117 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-05-13T14:02:23.562 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #4854, FileId: 0x197000000001ea6, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:02:23.565 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #4856, FileId: 0xef000000002424, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:02:23.565 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #4859, FileId: 0x19a000000001ea6, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:02:59.471 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T14:02:59.475 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T14:02:59.476 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T14:06:03.881 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-13T14:06:04.146 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T14:06:06.295 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6269, FileId: 0x4200000000c138, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:11:04.152 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-13T14:11:04.152 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-13T14:11:04.178 Job Notification: New process added to job (12192) 2026-05-13T14:11:04.184 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-13T14:11:04.190 Job Notification: New process added to job (13624) 2026-05-13T14:11:04.205 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:12192] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:13624]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T14:11:04.255 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 37032003(ms) from now at 02:28 (00:28 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-13T14:11:04.330 Job Notification: New process added to job (6776) 2026-05-13T14:11:04.334 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-13T14:11:04.336 Job Notification: New process added to job (14644) 2026-05-13T14:11:04.346 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:6776] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:14644]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-13T14:11:17.152 Job Notification: Process exited from job (6776) 2026-05-13T14:11:17.153 Job Notification: Process exited from job (14644) 2026-05-13T14:11:17.228 Job Notification: Process exited from job (12192) 2026-05-13T14:11:17.230 Job Notification: Process exited from job (13624) 2026-05-13T14:13:05.751 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9A34289C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6820, FileId: 0x5e00000000ebd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:05.894 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE4CC919C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6825, FileId: 0xc600000000ebab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:05.896 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1DDC6C96E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6821, FileId: 0xc200000000ebab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:05.897 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5884A89C8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6826, FileId: 0x6200000000ebd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:05.913 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1CA594987. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6819, FileId: 0xc000000000ebab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:05.978 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0A4D749B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6830, FileId: 0x6300000000ebd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.026 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD87E89955. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6838, FileId: 0xd100000000ebab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.045 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj89C3EB99D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6824, FileId: 0x6000000000ebd8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.870 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD553DA973. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6883, FileId: 0xd300000000ebab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.888 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj287AEA984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6884, FileId: 0x3100000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.938 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC16630948. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6888, FileId: 0x3200000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.971 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD69B4895E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6891, FileId: 0x5b00000000ed59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:06.994 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBC2EDC96E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6892, FileId: 0x5c00000000ed59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:20.300 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7026, FileId: 0x6900000000e758, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:20.408 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7028, FileId: 0x5200000000e78a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:13:20.639 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7034, FileId: 0x5300000000e992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:14:20.743 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7038, FileId: 0x7f00000000dfde, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:16:08.369 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #7090, FileId: 0x19000000083f07, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:21:09.152 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T14:23:20.697 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7179, FileId: 0x9100000000e14a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:23:20.709 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7181, FileId: 0x8a000000010232, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:23:57.355 Bm signature throttled:0x00002db31bed458f 2026-05-13T14:36:14.151 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T14:45:22.546 Bm signature throttled:0x00002db31bed458f IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 2026-05-13T14:50:57.823 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:50:57.838 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-13T14:50:57.841 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-13T14:50:57.841 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-13T14:50:57.843 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:50:57.844 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:50:57.844 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:50:57.844 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-13T14:50:57.844 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-13T14:50:57.845 MdCoreSvc is supported in this platform and OS 2026-05-13T14:50:58.337 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-13T14:50:58.337 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-13T14:50:58.337 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-13T14:51:19.144 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T14:51:40.142 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:16A36058-DBB0-45E1-90EF-48B6F4F44425, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-13T14:51:40.142 Scheduled scan with Id 16A36058-DBB0-45E1-90EF-48B6F4F44425 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-13T14:51:40.145 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-13T14:51:40.145 [SFC] System file cache build is not needed (already completed) 2026-05-13T14:51:42.157 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T14:51:42.165 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T14:51:42.166 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T14:51:42.612 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9411, FileId: 0x32000000011587, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-13T14:52:33.160 Engine:Triggered AR EMS scan 2026-05-13T14:52:33.176 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.192 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.207 Engine:EMS scan for process: svchost pid: 900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.207 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.207 Engine:EMS scan for process: svchost pid: 1188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.207 Engine:EMS scan for process: svchost pid: 1260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.223 Engine:EMS scan for process: svchost pid: 1300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.223 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.223 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.223 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.223 Engine:EMS scan for process: svchost pid: 1452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.238 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.238 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.254 Engine:EMS scan for process: svchost pid: 1636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.254 Engine:EMS scan for process: svchost pid: 1672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.254 Engine:EMS scan for process: svchost pid: 1684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.254 Engine:EMS scan for process: svchost pid: 1988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.254 Engine:EMS scan for process: svchost pid: 676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.270 Engine:EMS scan for process: svchost pid: 2420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.285 Engine:EMS scan for process: svchost pid: 2936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.301 Engine:EMS scan for process: svchost pid: 3028, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.301 Engine:EMS scan for process: svchost pid: 2100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.301 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.317 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.317 Engine:EMS scan for process: svchost pid: 3588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.317 Engine:EMS scan for process: svchost pid: 3732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.317 Engine:EMS scan for process: svchost pid: 3764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.332 Engine:EMS scan for process: svchost pid: 3800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.332 Engine:EMS scan for process: svchost pid: 2844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.332 Engine:EMS scan for process: svchost pid: 3548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.332 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.348 Engine:EMS scan for process: svchost pid: 4180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.348 Engine:EMS scan for process: svchost pid: 4188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.348 Engine:EMS scan for process: svchost pid: 4220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.363 Engine:EMS scan for process: svchost pid: 4420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.363 Engine:EMS scan for process: svchost pid: 4500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.363 Engine:EMS scan for process: svchost pid: 4548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.379 Engine:EMS scan for process: svchost pid: 5140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.379 Engine:EMS scan for process: svchost pid: 5936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.379 Engine:EMS scan for process: dllhost pid: 5084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.379 Engine:EMS scan for process: svchost pid: 6164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.379 Engine:EMS scan for process: svchost pid: 6172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.395 Engine:EMS scan for process: svchost pid: 6244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.395 Engine:EMS scan for process: svchost pid: 6460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.395 Engine:EMS scan for process: svchost pid: 7188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.395 Engine:EMS scan for process: svchost pid: 7228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.410 Engine:EMS scan for process: svchost pid: 7596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.410 Engine:EMS scan for process: svchost pid: 1416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.410 Bm signature throttled:0x00002db31bed458f 2026-05-13T14:52:33.410 Engine:EMS scan for process: svchost pid: 7116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.426 Engine:EMS scan for process: svchost pid: 8352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.426 Engine:EMS scan for process: svchost pid: 8556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.426 Engine:EMS scan for process: svchost pid: 8784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.426 Engine:EMS scan for process: explorer pid: 9060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.473 Engine:EMS scan for process: svchost pid: 9840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.473 Engine:EMS scan for process: svchost pid: 9948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.473 Engine:EMS scan for process: svchost pid: 10564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.488 Engine:EMS scan for process: dllhost pid: 10980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.488 Engine:EMS scan for process: svchost pid: 9556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.488 Engine:EMS scan for process: svchost pid: 7720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.488 Engine:EMS scan for process: svchost pid: 12136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.488 Engine:EMS scan for process: svchost pid: 9860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.504 Engine:EMS scan for process: svchost pid: 12084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.504 Engine:EMS scan for process: svchost pid: 14100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.504 Engine:EMS scan for process: svchost pid: 15196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.520 Engine:EMS scan for process: svchost pid: 5064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.520 Engine:EMS scan for process: svchost pid: 5396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-13T14:52:33.520 Engine:EMS scan for process: svchost pid: 6396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0xf5c96b12 2026-05-13T14:53:33.021 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:33.021 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:33.021 [Cloud] Queued cloud request. 2026-05-13T14:53:33.021 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:33.021 [Cloud] Dequeued cloud request. 2026-05-13T14:53:33.021 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:33.693 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x9df1ce23 2026-05-13T14:53:34.115 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:34.115 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:34.115 [Cloud] Queued cloud request. 2026-05-13T14:53:34.115 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:34.115 [Cloud] Dequeued cloud request. 2026-05-13T14:53:34.115 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:34.193 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:53:34.537 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x83c1aa73 2026-05-13T14:53:34.553 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:34.553 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:34.553 [Cloud] Queued cloud request. 2026-05-13T14:53:34.553 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:34.553 [Cloud] Dequeued cloud request. 2026-05-13T14:53:34.553 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:35.006 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 2026-05-13T14:53:35.021 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:35.021 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:35.021 [Cloud] Queued cloud request. 2026-05-13T14:53:35.021 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:35.021 [Cloud] Dequeued cloud request. 2026-05-13T14:53:35.021 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:35.037 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:53:35.365 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x26b3ba41 2026-05-13T14:53:35.490 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:35.490 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:35.490 [Cloud] Queued cloud request. 2026-05-13T14:53:35.490 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:35.490 [Cloud] Dequeued cloud request. 2026-05-13T14:53:35.490 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:35.881 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:53:35.896 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-13T14:53:35.928 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-13T14:53:35.928 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:53:35.928 [Cloud] Queued cloud request. 2026-05-13T14:53:35.928 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-13T14:53:35.928 [Cloud] Dequeued cloud request. 2026-05-13T14:53:35.928 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:53:36.334 [Cloud] End of cloud request. 2026-05-13T14:53:36.396 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9741, FileId: 0xce000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9742, FileId: 0x92000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9739, FileId: 0xcd000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9745, FileId: 0x93000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.693 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9740, FileId: 0x91000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.708 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9744, FileId: 0xcf000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.708 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9748, FileId: 0xd1000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.724 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9749, FileId: 0x97000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.724 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9746, FileId: 0xd0000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.724 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9750, FileId: 0xd4000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9753, FileId: 0x99000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.740 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9755, FileId: 0x9c000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9751, FileId: 0x98000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:40.755 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9754, FileId: 0xd6000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:41.099 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #9784, FileId: 0x16f000000000df3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:54:41.115 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\131bdcf2-6e15-4aff-af92-9d3cb12cbe59. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #9786, FileId: 0x3700000000f197, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T14:57:03.038 QuickScan:ScanID:16A36058-DBB0-45E1-90EF-48B6F4F44425: Quick scan finished with error 0 2026-05-13T14:57:03.038 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xdac0cf3e7ffffffe 2026-05-13T14:57:03.038 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x2e66e40f7ffffffe 2026-05-13T14:57:03.054 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd1edc1e97ffffffe 2026-05-13T14:57:03.054 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xe7b52c807ffffffe 2026-05-13T14:57:03.054 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9dda20b57ffffffe 2026-05-13T14:57:03.054 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x5a295f8e7ffffffe 2026-05-13T14:57:03.069 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 4 resources, RtpIoavOnly: FALSE 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xdac0cf3e7ffffffe 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x2e66e40f7ffffffe 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xd1edc1e97ffffffe 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xe7b52c807ffffffe 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9dda20b57ffffffe 2026-05-13T14:57:03.069 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x5a295f8e7ffffffe Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x9df1ce23 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x83c1aa73 Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-13T14:57:03.132 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-13T14:57:03.132 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-13T14:57:03.132 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x6fcfab137ffffffe 2026-05-13T14:57:03.132 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xee4a221a7ffffffe 2026-05-13T14:57:03.148 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 2 resources, RtpIoavOnly: FALSE 2026-05-13T14:57:03.148 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-13T14:57:03.148 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-13T14:57:03.148 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x6fcfab137ffffffe Internal signature match:subtype=Lowfi, sigseq=0x00003FE71D145BC8, sigsha=6d6b9489716c899dbcf7ccc44b32a2ea3c244fe6, cached=false, source=0, resourceid=0x483b4d60 2026-05-13T14:57:03.148 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xee4a221a7ffffffe Internal signature match:subtype=Lowfi, sigseq=0x00003FE7DB03AF28, sigsha=cfbb0b393f13e2f091b07b9c7cc04901951c45cb, cached=false, source=0, resourceid=0x431643b7 2026-05-13T14:57:03.179 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-13T14:57:03.179 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-13T14:57:03.179 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7401b89f7ffffffe 2026-05-13T14:57:03.179 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x7f2cb6487ffffffe 2026-05-13T14:57:03.194 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-05-13T14:57:03.194 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:57:03.194 [Cloud] Queued cloud request. 2026-05-13T14:57:03.194 [Cloud] Dequeued cloud request. 2026-05-13T14:57:03.210 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-05-13T14:57:03.210 [Cloud] Start of cloud request. Passive mode: 0 2026-05-13T14:57:03.210 [Cloud] Queued cloud request. 2026-05-13T14:57:03.210 [Cloud] Dequeued cloud request. 2026-05-13T14:57:03.226 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:57:03.382 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-13T14:57:03.382 [Cloud] End of cloud request. 2026-05-13T14:57:03.398 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-13T14:57:03.444 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-13T14:57:03.444 [Cloud] End of cloud request. 2026-05-13T14:57:03.569 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-13T14:57:03.569 [RTP] Duplicating the current plugin configuration object... 2026-05-13T14:57:03.569 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-13T14:57:03.569 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-13T14:57:03.569 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-13T14:57:03.569 [RTP] No config change detected. Not updating plugin configuration. 2026-05-13T14:57:03.569 [RTP] No config changes found. No configuration switch. 2026-05-13T14:57:03.569 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-13T14:57:03.569 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-13T14:57:05.069 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T14:57:05.069 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-13T14:57:05.069 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-13T15:06:24.150 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T15:21:29.151 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T15:28:07.724 Bm signature throttled:0x00002db31bed458f 2026-05-13T15:36:34.144 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T15:51:39.155 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T16:01:03.826 ProcessImageName: explorer.exe, Pid: 9060, TotalTime: 9410, Count: 177, MaxTime: 1687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: AcroCEF.exe, Pid: 5744, TotalTime: 3388, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 27% 2026-05-13T16:01:03.826 ProcessImageName: DipAwayMode.exe, Pid: 7500, TotalTime: 3323, Count: 16, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: AsPowerBar.exe, Pid: 1540, TotalTime: 3132, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 31% 2026-05-13T16:01:03.826 ProcessImageName: crashreporter.exe, Pid: 9852, TotalTime: 2949, Count: 8, MaxTime: 2828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100% 2026-05-13T16:01:03.826 ProcessImageName: MOM.exe, Pid: 15268, TotalTime: 2351, Count: 29, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 78% 2026-05-13T16:01:03.826 ProcessImageName: dllhost.exe, Pid: 10980, TotalTime: 1891, Count: 60, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 43% 2026-05-13T16:01:03.826 ProcessImageName: AISuite3.exe, Pid: 7944, TotalTime: 1618, Count: 22, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 1% 2026-05-13T16:01:03.826 ProcessImageName: websockify.exe, Pid: 14596, TotalTime: 1208, Count: 18, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 38% 2026-05-13T16:01:03.826 ProcessImageName: SDXHelper.exe, Pid: 5776, TotalTime: 634, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 13% 2026-05-13T16:01:03.826 ProcessImageName: WhatsApp.Root.exe, Pid: 14880, TotalTime: 576, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Documents\desktop.ini, EstimatedImpact: 1% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 572, Count: 11, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: firefox.exe, Pid: 8240, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 33% 2026-05-13T16:01:03.826 ProcessImageName: FileCoAuth.exe, Pid: 6204, TotalTime: 380, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 4% 2026-05-13T16:01:03.826 ProcessImageName: TeamViewer.exe, Pid: 7304, TotalTime: 229, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 7% 2026-05-13T16:01:03.826 ProcessImageName: AdobeCollabSync.exe, Pid: 14632, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: RuntimeBroker.exe, Pid: 10440, TotalTime: 218, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 93% 2026-05-13T16:01:03.826 ProcessImageName: firefox.exe, Pid: 3596, TotalTime: 171, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: PhoneExperienceHost.exe, Pid: 10824, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 2420, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: backgroundTaskHost.exe, Pid: 1268, TotalTime: 120, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-05-13T16:01:03.826 ProcessImageName: taskhostw.exe, Pid: 7772, TotalTime: 107, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 98% 2026-05-13T16:01:03.826 ProcessImageName: DesktopOK.exe, Pid: 14140, TotalTime: 92, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini, EstimatedImpact: 1% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 2060, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: OfficeC2RClient.exe, Pid: 4012, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D7D1216-F9C1-4ED7-85EF-834F61749D04, EstimatedImpact: 4% 2026-05-13T16:01:03.826 ProcessImageName: OpenWith.exe, Pid: 14372, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 7% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 3792, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpClient.dll, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: backgroundTaskHost.exe, Pid: 11256, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\ICU\timezoneTypes.res, EstimatedImpact: 2% 2026-05-13T16:01:03.826 ProcessImageName: AcroCEF.exe, Pid: 8808, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 21% 2026-05-13T16:01:03.826 ProcessImageName: AcroCEF.exe, Pid: 14180, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: RuntimeBroker.exe, Pid: 10532, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 12% 2026-05-13T16:01:03.826 ProcessImageName: OneDriveLauncher.exe, Pid: 5160, TotalTime: 61, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 3% 2026-05-13T16:01:03.826 ProcessImageName: SDXHelper.exe, Pid: 9988, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 3% 2026-05-13T16:01:03.826 ProcessImageName: CLIStart.exe, Pid: 15308, TotalTime: 61, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 45% 2026-05-13T16:01:03.826 ProcessImageName: runonce.exe, Pid: 3448, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1% 2026-05-13T16:01:03.826 ProcessImageName: GameBar.exe, Pid: 11284, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.326.5041.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 1% 2026-05-13T16:01:03.826 ProcessImageName: Acrobat.exe, Pid: 10888, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 4% 2026-05-13T16:01:03.826 ProcessImageName: Acrobat.exe, Pid: 9612, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-05-13T16:01:03.826 ProcessImageName: OfficeC2RClient.exe, Pid: 10108, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-1651.log, EstimatedImpact: 2% 2026-05-13T16:01:03.826 ProcessImageName: AggregatorHost.exe, Pid: 5624, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdBoot.sys, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: dllhost.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 42% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 7228, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8\ActivitiesCache.db-shm, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: dasHost.exe, Pid: 5336, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 3% 2026-05-13T16:01:03.826 ProcessImageName: backgroundTaskHost.exe, Pid: 11348, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 12% 2026-05-13T16:01:03.826 ProcessImageName: pingsender.exe, Pid: 4448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\bfac9b20-4555-41bf-a18a-4f98b9713161, EstimatedImpact: 9% 2026-05-13T16:01:03.826 ProcessImageName: svchost.exe, Pid: 12084, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-13T16:01:03.826 ProcessImageName: brynhildr.exe, Pid: 4148, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-13T16:06:44.143 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T16:21:49.154 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T16:36:54.154 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T16:39:04.843 [RTP] [Mini-filter] OpenWithoutRead notification (1084, 10009, ) sent successfully. 2026-05-13T16:49:04.963 Bm signature throttled:0x000045b3435c1067 2026-05-13T16:49:04.978 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10777, FileId: 0xdc000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.978 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10776, FileId: 0xa1000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.978 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10780, FileId: 0xa4000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.978 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10779, FileId: 0xa2000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.978 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10781, FileId: 0xe0000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.994 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10786, FileId: 0xe2000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.994 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10783, FileId: 0xe1000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:04.994 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10787, FileId: 0xe4000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:05.010 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10791, FileId: 0xaa000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:05.010 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10788, FileId: 0xa8000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:05.010 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10792, FileId: 0xe8000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:05.447 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10826, FileId: 0xea000000000e6a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:49:05.447 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\30fc0322-0ccc-4ba0-a92e-f23b52c19884. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #10828, FileId: 0x23000000036226, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T16:51:59.158 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T17:07:04.144 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T17:22:09.155 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T17:37:14.142 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T17:52:19.143 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T18:01:03.840 ProcessImageName: explorer.exe, Pid: 9060, TotalTime: 9410, Count: 177, MaxTime: 1687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: AcroCEF.exe, Pid: 5744, TotalTime: 3388, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 27% 2026-05-13T18:01:03.840 ProcessImageName: DipAwayMode.exe, Pid: 7500, TotalTime: 3323, Count: 16, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: AsPowerBar.exe, Pid: 1540, TotalTime: 3132, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 31% 2026-05-13T18:01:03.840 ProcessImageName: crashreporter.exe, Pid: 9852, TotalTime: 2949, Count: 8, MaxTime: 2828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100% 2026-05-13T18:01:03.840 ProcessImageName: MOM.exe, Pid: 15268, TotalTime: 2351, Count: 29, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 78% 2026-05-13T18:01:03.840 ProcessImageName: dllhost.exe, Pid: 10980, TotalTime: 1891, Count: 60, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 43% 2026-05-13T18:01:03.840 ProcessImageName: AISuite3.exe, Pid: 7944, TotalTime: 1618, Count: 22, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 1% 2026-05-13T18:01:03.840 ProcessImageName: websockify.exe, Pid: 14596, TotalTime: 1208, Count: 18, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 38% 2026-05-13T18:01:03.840 ProcessImageName: SDXHelper.exe, Pid: 5776, TotalTime: 634, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 13% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 587, Count: 13, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: WhatsApp.Root.exe, Pid: 14880, TotalTime: 576, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Documents\desktop.ini, EstimatedImpact: 1% 2026-05-13T18:01:03.840 ProcessImageName: firefox.exe, Pid: 13784, TotalTime: 480, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10284, EstimatedImpact: 62% 2026-05-13T18:01:03.840 ProcessImageName: firefox.exe, Pid: 8240, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 33% 2026-05-13T18:01:03.840 ProcessImageName: FileCoAuth.exe, Pid: 6204, TotalTime: 380, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 4% 2026-05-13T18:01:03.840 ProcessImageName: TeamViewer.exe, Pid: 7304, TotalTime: 229, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 7% 2026-05-13T18:01:03.840 ProcessImageName: AdobeCollabSync.exe, Pid: 14632, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: RuntimeBroker.exe, Pid: 10440, TotalTime: 218, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 93% 2026-05-13T18:01:03.840 ProcessImageName: firefox.exe, Pid: 3596, TotalTime: 171, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: PhoneExperienceHost.exe, Pid: 10824, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 2420, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: backgroundTaskHost.exe, Pid: 1268, TotalTime: 120, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-05-13T18:01:03.840 ProcessImageName: taskhostw.exe, Pid: 7772, TotalTime: 107, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 98% 2026-05-13T18:01:03.840 ProcessImageName: DesktopOK.exe, Pid: 14140, TotalTime: 92, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini, EstimatedImpact: 1% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 2060, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: OfficeC2RClient.exe, Pid: 4012, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D7D1216-F9C1-4ED7-85EF-834F61749D04, EstimatedImpact: 4% 2026-05-13T18:01:03.840 ProcessImageName: OpenWith.exe, Pid: 14372, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 7% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 3792, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpClient.dll, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: backgroundTaskHost.exe, Pid: 11256, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\ICU\timezoneTypes.res, EstimatedImpact: 2% 2026-05-13T18:01:03.840 ProcessImageName: AcroCEF.exe, Pid: 8808, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 21% 2026-05-13T18:01:03.840 ProcessImageName: AcroCEF.exe, Pid: 14180, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: RuntimeBroker.exe, Pid: 10532, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 12% 2026-05-13T18:01:03.840 ProcessImageName: OneDriveLauncher.exe, Pid: 5160, TotalTime: 61, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 3% 2026-05-13T18:01:03.840 ProcessImageName: SDXHelper.exe, Pid: 9988, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 3% 2026-05-13T18:01:03.840 ProcessImageName: CLIStart.exe, Pid: 15308, TotalTime: 61, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 45% 2026-05-13T18:01:03.840 ProcessImageName: runonce.exe, Pid: 3448, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1% 2026-05-13T18:01:03.840 ProcessImageName: GameBar.exe, Pid: 11284, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.326.5041.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 1% 2026-05-13T18:01:03.840 ProcessImageName: Acrobat.exe, Pid: 10888, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 4% 2026-05-13T18:01:03.840 ProcessImageName: Acrobat.exe, Pid: 9612, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-05-13T18:01:03.840 ProcessImageName: AggregatorHost.exe, Pid: 5624, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdBoot.sys, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: OfficeC2RClient.exe, Pid: 10108, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-1651.log, EstimatedImpact: 2% 2026-05-13T18:01:03.840 ProcessImageName: dllhost.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 42% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 7228, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8\ActivitiesCache.db-shm, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: dasHost.exe, Pid: 5336, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 3% 2026-05-13T18:01:03.840 ProcessImageName: backgroundTaskHost.exe, Pid: 11348, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 12% 2026-05-13T18:01:03.840 ProcessImageName: pingsender.exe, Pid: 4448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\bfac9b20-4555-41bf-a18a-4f98b9713161, EstimatedImpact: 9% 2026-05-13T18:01:03.840 ProcessImageName: svchost.exe, Pid: 12084, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: dllhost.exe, Pid: 5084, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-13T18:01:03.840 ProcessImageName: brynhildr.exe, Pid: 4148, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-13T18:07:24.144 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T18:22:29.149 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T18:37:34.150 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T18:52:39.149 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T19:00:12.736 Bm signature throttled:0x00002db31bed458f 2026-05-13T19:00:12.938 Engine:Process 7768 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-13T19:00:30.903 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12384, FileId: 0x20000000000aae2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T19:07:44.147 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T19:13:39.093 Bm signature throttled:0x00002db31bed458f 2026-05-13T19:13:39.093 Bm signature throttled:0x00002db31bed458f 2026-05-13T19:17:57.370 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12852, FileId: 0xbc00000000bcad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T19:22:49.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T19:28:21.637 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12882, FileId: 0xc100000000bcad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T19:37:54.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T19:52:59.147 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T20:01:03.849 ProcessImageName: explorer.exe, Pid: 9060, TotalTime: 9425, Count: 179, MaxTime: 1687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: AcroCEF.exe, Pid: 5744, TotalTime: 3388, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 27% 2026-05-13T20:01:03.849 ProcessImageName: DipAwayMode.exe, Pid: 7500, TotalTime: 3323, Count: 16, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: AsPowerBar.exe, Pid: 1540, TotalTime: 3132, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 31% 2026-05-13T20:01:03.849 ProcessImageName: crashreporter.exe, Pid: 9852, TotalTime: 2949, Count: 8, MaxTime: 2828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100% 2026-05-13T20:01:03.849 ProcessImageName: MOM.exe, Pid: 15268, TotalTime: 2351, Count: 29, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 78% 2026-05-13T20:01:03.849 ProcessImageName: dllhost.exe, Pid: 10980, TotalTime: 1891, Count: 60, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 43% 2026-05-13T20:01:03.849 ProcessImageName: AISuite3.exe, Pid: 7944, TotalTime: 1618, Count: 22, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: websockify.exe, Pid: 14596, TotalTime: 1208, Count: 18, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 38% 2026-05-13T20:01:03.849 ProcessImageName: SDXHelper.exe, Pid: 5776, TotalTime: 634, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 13% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 617, Count: 15, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: WhatsApp.Root.exe, Pid: 14880, TotalTime: 576, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Documents\desktop.ini, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: firefox.exe, Pid: 13784, TotalTime: 480, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10284, EstimatedImpact: 62% 2026-05-13T20:01:03.849 ProcessImageName: firefox.exe, Pid: 8240, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 33% 2026-05-13T20:01:03.849 ProcessImageName: FileCoAuth.exe, Pid: 6204, TotalTime: 380, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 4% 2026-05-13T20:01:03.849 ProcessImageName: TeamViewer.exe, Pid: 7304, TotalTime: 244, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: AdobeCollabSync.exe, Pid: 14632, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: RuntimeBroker.exe, Pid: 10440, TotalTime: 218, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 93% 2026-05-13T20:01:03.849 ProcessImageName: firefox.exe, Pid: 3596, TotalTime: 171, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: PhoneExperienceHost.exe, Pid: 10824, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: TabTip.exe, Pid: 15176, TotalTime: 155, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 87% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 2420, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: backgroundTaskHost.exe, Pid: 1268, TotalTime: 120, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-05-13T20:01:03.849 ProcessImageName: taskhostw.exe, Pid: 7772, TotalTime: 107, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 98% 2026-05-13T20:01:03.849 ProcessImageName: DesktopOK.exe, Pid: 14140, TotalTime: 92, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 2060, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: OfficeC2RClient.exe, Pid: 4012, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\4D7D1216-F9C1-4ED7-85EF-834F61749D04, EstimatedImpact: 4% 2026-05-13T20:01:03.849 ProcessImageName: OpenWith.exe, Pid: 14372, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 7% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 3792, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpClient.dll, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: backgroundTaskHost.exe, Pid: 11256, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\ICU\timezoneTypes.res, EstimatedImpact: 2% 2026-05-13T20:01:03.849 ProcessImageName: AcroCEF.exe, Pid: 8808, TotalTime: 76, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 21% 2026-05-13T20:01:03.849 ProcessImageName: AcroCEF.exe, Pid: 14180, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: RuntimeBroker.exe, Pid: 10532, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks.json, EstimatedImpact: 12% 2026-05-13T20:01:03.849 ProcessImageName: OneDriveLauncher.exe, Pid: 5160, TotalTime: 61, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 3% 2026-05-13T20:01:03.849 ProcessImageName: AggregatorHost.exe, Pid: 5624, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdBoot.sys, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: SDXHelper.exe, Pid: 9988, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 3% 2026-05-13T20:01:03.849 ProcessImageName: CLIStart.exe, Pid: 15308, TotalTime: 61, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 45% 2026-05-13T20:01:03.849 ProcessImageName: runonce.exe, Pid: 3448, TotalTime: 60, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: GameBar.exe, Pid: 11284, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_7.326.5041.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: Acrobat.exe, Pid: 10888, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll, EstimatedImpact: 4% 2026-05-13T20:01:03.849 ProcessImageName: dasHost.exe, Pid: 5336, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: Acrobat.exe, Pid: 9612, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 5% 2026-05-13T20:01:03.849 ProcessImageName: OfficeC2RClient.exe, Pid: 10108, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-1651.log, EstimatedImpact: 2% 2026-05-13T20:01:03.849 ProcessImageName: SDXHelper.exe, Pid: 12924, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 15% 2026-05-13T20:01:03.849 ProcessImageName: OfficeC2RClient.exe, Pid: 1116, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-2100.log, EstimatedImpact: 2% 2026-05-13T20:01:03.849 ProcessImageName: dllhost.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 42% 2026-05-13T20:01:03.849 ProcessImageName: svchost.exe, Pid: 7228, TotalTime: 30, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8\ActivitiesCache.db-shm, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: dllhost.exe, Pid: 5084, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-13T20:01:03.849 ProcessImageName: backgroundTaskHost.exe, Pid: 11348, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 12% 2026-05-13T20:01:03.849 ProcessImageName: OfficeC2RClient.exe, Pid: 11708, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-2128.log, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: OfficeC2RClient.exe, Pid: 944, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260513-2117.log, EstimatedImpact: 1% 2026-05-13T20:01:03.849 ProcessImageName: pingsender.exe, Pid: 4448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\p1j6n8y0.default-release\saved-telemetry-pings\bfac9b20-4555-41bf-a18a-4f98b9713161, EstimatedImpact: 9% 2026-05-13T20:01:03.850 ProcessImageName: svchost.exe, Pid: 12084, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-13T20:01:03.850 ProcessImageName: brynhildr.exe, Pid: 4148, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-13T20:01:35.309 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #13005, FileId: 0x7a00000000df17, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T20:08:04.147 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T20:23:09.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T20:38:14.147 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T20:53:19.146 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T21:08:24.145 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T21:23:29.155 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T21:38:34.147 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T21:53:39.151 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-13T21:54:40.081 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13727, FileId: 0xb0000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.081 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13726, FileId: 0x14c000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.081 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13728, FileId: 0xb1000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.081 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13732, FileId: 0x14f000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.081 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13733, FileId: 0x150000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.097 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13730, FileId: 0xb3000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.097 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13735, FileId: 0x153000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.112 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13738, FileId: 0x156000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.112 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13741, FileId: 0xbb000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.112 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13742, FileId: 0xbc000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.128 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13743, FileId: 0x158000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.128 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13739, FileId: 0xba000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.550 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #13777, FileId: 0xbe000000000ea2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T21:54:40.550 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\51b1892d-84a3-49f2-9777-f42c12feb766. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #13779, FileId: 0x4b000000028a61, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-13T22:01:03.862 ProcessImageName: explorer.exe, Pid: 9060, TotalTime: 9425, Count: 179, MaxTime: 1687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: AcroCEF.exe, Pid: 5744, TotalTime: 3388, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 27% 2026-05-13T22:01:03.862 ProcessImageName: DipAwayMode.exe, Pid: 7500, TotalTime: 3323, Count: 16, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: AsPowerBar.exe, Pid: 1540, TotalTime: 3132, Count: 18, MaxTime: 1187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 31% 2026-05-13T22:01:03.862 ProcessImageName: crashreporter.exe, Pid: 9852, TotalTime: 2949, Count: 8, MaxTime: 2828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 100% 2026-05-13T22:01:03.862 ProcessImageName: MOM.exe, Pid: 15268, TotalTime: 2351, Count: 29, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 78% 2026-05-13T22:01:03.862 ProcessImageName: dllhost.exe, Pid: 10980, TotalTime: 1891, Count: 60, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 43% 2026-05-13T22:01:03.862 ProcessImageName: AISuite3.exe, Pid: 7944, TotalTime: 1618, Count: 22, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 1% 2026-05-13T22:01:03.862 ProcessImageName: websockify.exe, Pid: 14596, TotalTime: 1208, Count: 18, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 38% 2026-05-13T22:01:03.862 ProcessImageName: svchost.exe, Pid: 1452, TotalTime: 647, Count: 17, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveLauncher.exe, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: SDXHelper.exe, Pid: 5776, TotalTime: 634, Count: 21, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 13% 2026-05-13T22:01:03.862 ProcessImageName: WhatsApp.Root.exe, Pid: 14880, TotalTime: 576, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Documents\desktop.ini, EstimatedImpact: 1% 2026-05-13T22:01:03.862 ProcessImageName: firefox.exe, Pid: 960, TotalTime: 496, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa08736, EstimatedImpact: 64% 2026-05-13T22:01:03.862 ProcessImageName: firefox.exe, Pid: 13784, TotalTime: 480, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10284, EstimatedImpact: 62% 2026-05-13T22:01:03.862 ProcessImageName: firefox.exe, Pid: 8240, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 33% 2026-05-13T22:01:03.862 ProcessImageName: FileCoAuth.exe, Pid: 6204, TotalTime: 380, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 4% 2026-05-13T22:01:03.862 ProcessImageName: TeamViewer.exe, Pid: 7304, TotalTime: 244, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: AdobeCollabSync.exe, Pid: 14632, TotalTime: 226, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: RuntimeBroker.exe, Pid: 10440, TotalTime: 218, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 93% 2026-05-13T22:01:03.862 ProcessImageName: firefox.exe, Pid: 3596, TotalTime: 171, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: PhoneExperienceHost.exe, Pid: 10824, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: TabTip.exe, Pid: 15176, TotalTime: 155, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 87% 2026-05-13T22:01:03.862 ProcessImageName: svchost.exe, Pid: 2420, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: svchost.exe, Pid: 2700, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 0% 2026-05-13T22:01:03.862 ProcessImageName: backgroundTaskHost.exe, Pid: 1268, TotalTime: 120, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-05-13T22:01:03.862 ProcessImageName: taskhostw.exe, Pid: 7772, TotalTime: 107, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 98% 2026-05-13T22:01:03.862 ProcessImageName: DesktopOK.exe, Pid: 14140, TotalTime: 92, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini, EstimatedImpact: 1% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-14-2026 11:03:04 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/14/2026 11:03:04.760771900 UTC (13484 ms since boot) 2026-05-14T11:03:04.773 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-14T11:03:04.778 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:03:04.778 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:03:04.916 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260514-110304-00000003-fffffffeffffffff.bin ... 2026-05-14T11:03:04.988 [WPP] Trace session started - MpWppTracing-20260514-110304-00000003-fffffffeffffffff.bin 2026-05-14T11:03:04.994 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-14T11:03:04.998 [RbM] Rollback manager succesfully initialized. 2026-05-14T11:03:04.998 [RbM] Rollback manager EnableRollbackManager called. 2026-05-14T11:03:05.008 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-14T11:03:05.010 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-14T11:03:05.010 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-14T11:03:05.010 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-14T11:03:05.018 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-14T11:03:05.018 MdCoreSvc is supported in this platform and OS 2026-05-14T11:03:05.018 MdCoreSvc is supported in this platform and OS 2026-05-14T11:03:05.018 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-14T11:03:05.018 [PlatUpd] Starting MdCoreSvc service 2026-05-14T11:03:05.053 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-14T11:03:08.366 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-14T11:03:08.366 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-14T11:03:08.366 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-14T11:03:08.366 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-14T11:03:08.366 [PlatUpd] CSP platform update started 2026-05-14T11:03:08.366 [PlatUpd] Defender MDM CSP platform update not required 2026-05-14T11:03:08.366 [PlatUpd] WMI/PS provider platform update started 2026-05-14T11:03:08.366 [PlatUpd] WMI/PS provider platform update not required 2026-05-14T11:03:08.366 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-14T11:03:08.366 MdCoreSvc is supported in this platform and OS 2026-05-14T11:03:08.366 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-14T11:03:08.366 [PlatUpd] Starting MdCoreSvc service 2026-05-14T11:03:08.366 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-14T11:03:08.382 [TS] Troubleshooting mode is not available! 2026-05-14T11:03:08.382 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-14T11:03:08.382 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-14T11:03:08.398 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-14T11:03:08.398 [Service] Enabling AutoLoggers ... 2026-05-14T11:03:08.413 [Service] Enabling AMSI registration ... 2026-05-14T11:03:08.413 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-14T11:03:08.429 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 42385 Number of invalid entries is 0 Number of inserts issued is 1583356 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6503 Number of lookups is 108048082 Number of lookup misses is 5190349 Number of fast lookup misses is 55057702 Number of false fast lookups is 5190344 Number of invalidations is 734457 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-14T11:03:08.429 Verifying license file... 2026-05-14T11:03:08.429 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-14T11:03:08.445 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-14T11:03:08.445 Loaded module#0 MpComServer. 2026-05-14T11:03:08.445 Loaded module#1 StartupPolicies. 2026-05-14T11:03:08.445 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-14T11:03:08.445 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-14T11:03:08.445 COM server initialized successfully. 2026-05-14T11:03:08.460 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-14T11:03:08.476 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-14T11:03:08.476 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-14T11:03:08.491 [RTP] [RTP] FilterCommunicator object 0x0000018F3669F450 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-14T11:03:08.491 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-14T11:03:08.491 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T11:03:08.491 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T11:03:08.491 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-14T11:03:08.491 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-14T11:03:08.491 [RTP] [RTP] FilterCommunicator object 0x0000018F3669F660 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-14T11:03:08.491 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-14T11:03:08.491 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-14T11:03:08.491 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-14T11:03:08.491 [RTP] [RTP] StartCommunication 0x0000018F3669F450 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-14T11:03:08.491 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-14T11:03:08.491 [init][RTP] RTPPlugin initialization completed 2026-05-14T11:03:08.491 OS boot count = 2 2026-05-14T11:03:08.491 OS Install = 0 2026-05-14T11:03:08.507 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-14T11:03:08.507 [KSL] Entering CKSLEngine::Initialize. 2026-05-14T11:03:08.507 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-14T11:03:08.507 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-14T11:03:08.507 [KSL] MpInstallKslD: hr=0x1 2026-05-14T11:03:08.507 [KSL] MpRegisterKslD: hr=0 2026-05-14T11:03:08.523 [KSL] MpStartKslD: hr=0 2026-05-14T11:03:08.523 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T11:03:08.523 Loading engine... 2026-05-14T11:03:08.538 Verifying engine and signature files (source: 1) ... 2026-05-14T11:03:08.538 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpengine.dll] due to PPL. 2026-05-14T11:03:08.538 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm]. File not in cache (0x1) 2026-05-14T11:03:09.507 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm] 2026-05-14T11:03:09.507 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasdlta.vdm] (file in cache) 2026-05-14T11:03:09.507 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm]. File not in cache (0x1) 2026-05-14T11:03:09.976 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavbase.vdm] 2026-05-14T11:03:09.976 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpavdlta.vdm] (file in cache) 2026-05-14T11:03:10.007 [Engine] IsHybridMode: 0 2026-05-14T11:03:10.007 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-14T11:03:10.038 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-5966C72D3E93A0018E0270BC315C0CF48C9C8CEB.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-14T11:03:13.945 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-14T11:03:13.945 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-14T11:03:13.960 [Engine] New active engine 00007FFDA9525810 (no old engine). Number of active engines: 1 2026-05-14T11:03:13.960 EngineInit:Global ASOC is enabled 2026-05-14T11:03:13.960 EngineInit:ASOO is enabled for developer volumes 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.038 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:03:14.054 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eac64b1f59783f7a5d855d52a0cacc6526897729 Dynamic Signature Compilation Timestamp:04-13-2026 19:14:58 Persistence Type:Duration Time remaining:150196224 2026-05-14T11:03:14.054 MpWriteUupSignatureVersion 1.449.595.0, hr = 0 2026-05-14T11:03:14.054 [SigStatUpd] CSignatureStatus: back to good 2026-05-14T11:03:14.054 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-14T11:03:14.070 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-14T11:03:14.070 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:03:14.070 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-14T11:03:14.070 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-14T11:03:14.070 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-14T11:03:14.085 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-14T11:03:14.085 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2075 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11470 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2282 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-14T11:03:14.085 [Plugin] Initializing RTP plugin state... 2026-05-14T11:03:14.085 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-14T11:03:14.085 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2} 2026-05-14T11:03:14.085 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:03:14.085 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:03:14.085 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:03:14.085 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T11:03:14.085 MdCoreSvc is supported in this platform and OS 2026-05-14T11:03:14.085 Engine loaded! 2026-05-14T11:03:14.085 [DLP] Create FeatureControlState instance 2026-05-14T11:03:14.101 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-14T11:03:14.101 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-14T11:03:14.101 RegisterSModeChangeListener: hr = 0x1 2026-05-14T11:03:14.101 RegisterHybridModeChangeListener: hr = 0 2026-05-14T11:03:14.116 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-14T11:03:14.116 [SigReleaseHb] Initialized with Stage 0 2026-05-14T11:03:14.116 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-14T11:03:14.116 [SCC][CID=22843_5380] Initializing ... 2026-05-14T11:03:14.116 [SCC][CID=22843_5380] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-14T11:03:14.116 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-14T11:03:14.116 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-14T11:03:14.116 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-14T11:03:14.116 [NRI] Stopping NIS service ... 2026-05-14T11:03:14.116 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-14T11:03:14.116 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.595.0 AV Signature Version: 1.449.595.0 ************************************************************ 2026-05-14T11:03:14.116 Resource usage Monitoring is enabled 2026-05-14T11:03:14.116 Job Notification: New process added to job (4464) 2026-05-14T11:03:14.116 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-14T11:03:14.163 Job Notification: New process added to job (6724) 2026-05-14T11:03:14.163 Job Notification: New process added to job (6680) 2026-05-14T11:03:14.163 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:6724] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6680]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-14T11:03:14.195 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-14T11:03:14.195 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-14T11:03:14.195 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-14T11:03:14.195 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-14T11:03:14.195 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-14T11:03:14.195 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T11:03:14.195 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T11:03:14.195 [RTP] Generating the base plugin configuration ... 2026-05-14T11:03:14.195 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-14T11:03:14.195 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:03:14.195 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-14T11:03:14.195 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-14T11:03:14.195 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:03:14.195 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-14T11:03:14.210 [RTP] [RTP] StartCommunication 0x0000018F3669F660 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-14T11:03:14.210 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-14T11:03:14.210 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-14T11:03:14.257 Job Notification: Process exited from job (6724) 2026-05-14T11:03:14.257 Job Notification: Process exited from job (6680) 2026-05-14T11:03:14.257 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-14T11:03:14.523 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T11:03:14.570 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-14T11:03:14.570 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-14T11:03:14.570 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T11:03:17.101 [RTP] Duplicating the current plugin configuration object... 2026-05-14T11:03:17.101 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T11:03:17.101 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-14T11:03:17.101 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-14T11:03:17.101 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-14T11:04:08.429 Process scan (poststartupscan) started. 2026-05-14T11:04:08.429 Process scan (poststartupscan) completed. 2026-05-14T11:04:08.929 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-14T11:04:08.929 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-14T11:04:11.507 [RTP] Duplicating the current plugin configuration object... 2026-05-14T11:04:11.507 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T11:04:11.507 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-14T11:04:11.507 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-14T11:04:11.507 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-14T11:05:08.351 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T11:05:08.366 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-14T11:05:08.366 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T11:06:06.851 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\2D7B44AE-FFFE-4BD8-8985-22B4520A1FC713e8.1dce391a84154e2 2026-05-14T11:06:06.960 Verifying engine and signature files (source: 0) ... 2026-05-14T11:06:06.960 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpengine.dll] due to PPL. 2026-05-14T11:06:06.960 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasbase.vdm]. File not in cache (0x1) 2026-05-14T11:06:07.726 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasbase.vdm] 2026-05-14T11:06:07.726 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-14T11:06:07.741 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasdlta.vdm] 2026-05-14T11:06:07.741 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavbase.vdm]. File not in cache (0x1) 2026-05-14T11:06:08.085 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavbase.vdm] 2026-05-14T11:06:08.085 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-14T11:06:08.116 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavdlta.vdm] 2026-05-14T11:06:08.273 [Engine] IsHybridMode: 0 2026-05-14T11:06:08.273 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-14T11:06:08.273 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-060D1DCEE02A5E878F42DA5F7260F4CC05A2764C.bin): 0x00000002 2026-05-14T11:06:08.288 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-060D1DCEE02A5E878F42DA5F7260F4CC05A2764C.bin) 2026-05-14T11:06:08.288 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-14T11:06:08.288 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-14T11:06:08.288 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-14T11:06:08.288 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-14T11:06:17.976 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-14T11:06:17.976 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-14T11:06:17.991 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFDA9525810, lRefCount: 5, hr=0 2026-05-14T11:06:17.991 [Engine] New active engine 00007FFDA3F35810 replacing engine 00007FFDA9525810. Number of active engines: 2 2026-05-14T11:06:17.991 EngineInit:Global ASOC is enabled 2026-05-14T11:06:17.991 EngineInit:ASOO is enabled for developer volumes 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:06:18.054 MpWriteUupSignatureVersion 1.449.610.0, hr = 0 2026-05-14T11:06:18.054 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-14T11:06:18.070 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-14T11:06:18.085 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:06:18.085 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-14T11:06:18.085 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-14T11:06:18.085 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-14T11:06:18.085 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-14T11:06:18.085 [Plugin] Initializing RTP plugin state... 2026-05-14T11:06:18.085 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-14T11:06:18.085 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎14‎-‎2026 13:03:14 Last Perf:‎05‎-‎14‎-‎2026 13:03:14 First RTP Scan:‎05‎-‎14‎-‎2026 13:03:14 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:370 Misses:210 BM Queue:0,12,0 Proc:0,12,0 File:0,5,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:613 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:1959106 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2328 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12666 TotalHits:2714 InstanceCacheInserts:19 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2639 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (84/30) Success: 30, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-14T11:06:18.085 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B} 2026-05-14T11:06:18.085 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CE521F0-3B50-438A-B64B-6C795C8F04C2}\mpasbase.vdm in use, hr=0x80070020 2026-05-14T11:06:18.101 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-14T11:06:18.101 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9B87181B-3283-4033-93DE-49A44BD323A0} removed 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-14-2026 11:06:18 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-14-2026 11:06:18 2026-05-14T11:06:18.101 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-14T11:06:18.101 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-14T11:06:18.101 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:06:18.101 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-14T11:06:18.101 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T11:06:18.101 MdCoreSvc is supported in this platform and OS Signature updated on 05-14-2026 11:06:18 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.610.0 AV Signature Version: 1.449.610.0 ************************************************************ 2026-05-14T11:06:18.101 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-14T11:06:18.101 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\2D7B44AE-FFFE-4BD8-8985-22B4520A1FC713e8.1dce391a84154e2 2026-05-14T11:06:18.179 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-14T11:06:18.179 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-14T11:06:18.523 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-14T11:06:18.523 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-14T11:06:18.523 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-14T11:06:18.523 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T11:06:18.523 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T11:06:18.523 [Engine] Engine 00007FFDA9525810 no longer in use. Number of active engines: 1 2026-05-14T11:06:18.523 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:06:18.523 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-14T11:06:18.554 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-14T11:06:18.554 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-14T11:06:18.554 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T11:06:18.616 ProcessImageName: svchost.exe, Pid: 3560, TotalTime: 155, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpClient.dll, EstimatedImpact: 82% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-14-2026 11:09:46 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/14/2026 11:09:46.962694100 UTC (14687 ms since boot) 2026-05-14T11:09:46.974 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-14T11:09:46.984 WARNING: the previous service shutdown was not expected. 2026-05-14T11:09:46.984 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:09:46.989 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:09:47.041 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260514-110947-00000003-fffffffeffffffff.bin ... 2026-05-14T11:09:47.119 [WPP] Trace session started - MpWppTracing-20260514-110947-00000003-fffffffeffffffff.bin 2026-05-14T11:09:47.135 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-14T11:09:47.135 [RbM] Rollback manager succesfully initialized. 2026-05-14T11:09:47.135 [RbM] Rollback manager EnableRollbackManager called. 2026-05-14T11:09:47.135 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-14T11:09:47.135 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-14T11:09:47.135 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-14T11:09:47.135 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-14T11:09:47.135 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-14T11:09:47.135 MdCoreSvc is supported in this platform and OS 2026-05-14T11:09:47.150 MdCoreSvc is supported in this platform and OS 2026-05-14T11:09:47.150 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-14T11:09:47.150 [PlatUpd] Starting MdCoreSvc service 2026-05-14T11:09:47.181 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-14T11:09:50.963 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-14T11:09:50.963 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-14T11:09:50.963 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-14T11:09:50.963 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-14T11:09:50.963 [PlatUpd] CSP platform update started 2026-05-14T11:09:50.963 [PlatUpd] Defender MDM CSP platform update not required 2026-05-14T11:09:50.963 [PlatUpd] WMI/PS provider platform update started 2026-05-14T11:09:50.963 [PlatUpd] WMI/PS provider platform update not required 2026-05-14T11:09:50.963 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-14T11:09:50.963 MdCoreSvc is supported in this platform and OS 2026-05-14T11:09:50.963 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-14T11:09:50.963 [PlatUpd] Starting MdCoreSvc service 2026-05-14T11:09:50.963 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-14T11:09:50.963 [TS] Troubleshooting mode is not available! 2026-05-14T11:09:50.963 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-14T11:09:50.963 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-14T11:09:50.978 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-14T11:09:50.978 [Service] Enabling AutoLoggers ... 2026-05-14T11:09:50.978 [Service] Enabling AMSI registration ... 2026-05-14T11:09:50.978 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-14T11:09:50.994 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 42391 Number of invalid entries is 0 Number of inserts issued is 1583369 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6503 Number of lookups is 108049377 Number of lookup misses is 5190389 Number of fast lookup misses is 55057893 Number of false fast lookups is 5190384 Number of invalidations is 734464 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-14T11:09:50.994 Verifying license file... 2026-05-14T11:09:50.994 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-14T11:09:51.010 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-14T11:09:51.010 Loaded module#0 MpComServer. 2026-05-14T11:09:51.010 Loaded module#1 StartupPolicies. 2026-05-14T11:09:51.010 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-14T11:09:51.010 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-14T11:09:51.010 COM server initialized successfully. 2026-05-14T11:09:51.025 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-14T11:09:51.041 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-14T11:09:51.041 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-14T11:09:51.056 [RTP] [RTP] FilterCommunicator object 0x000002EC68A9F000 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-14T11:09:51.056 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-14T11:09:51.056 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T11:09:51.056 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T11:09:51.056 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-14T11:09:51.056 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-14T11:09:51.056 [RTP] [RTP] FilterCommunicator object 0x000002EC68A9F210 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-14T11:09:51.056 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-14T11:09:51.056 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-14T11:09:51.056 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-14T11:09:51.056 [RTP] [RTP] StartCommunication 0x000002EC68A9F000 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-14T11:09:51.056 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-14T11:09:51.056 [init][RTP] RTPPlugin initialization completed 2026-05-14T11:09:51.056 OS boot count = 2 2026-05-14T11:09:51.056 OS Install = 0 2026-05-14T11:09:51.072 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-14T11:09:51.072 [KSL] Entering CKSLEngine::Initialize. 2026-05-14T11:09:51.072 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-14T11:09:51.072 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-14T11:09:51.072 [KSL] MpInstallKslD: hr=0x1 2026-05-14T11:09:51.072 [KSL] MpRegisterKslD: hr=0 2026-05-14T11:09:51.072 [KSL] MpStartKslD: hr=0 2026-05-14T11:09:51.072 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T11:09:51.072 Loading engine... 2026-05-14T11:09:51.088 Verifying engine and signature files (source: 1) ... 2026-05-14T11:09:51.088 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpengine.dll] due to PPL. 2026-05-14T11:09:51.088 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasbase.vdm]. File not in cache (0x1) 2026-05-14T11:09:52.056 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasbase.vdm] 2026-05-14T11:09:52.056 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasdlta.vdm] (file in cache) 2026-05-14T11:09:52.056 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavbase.vdm]. File not in cache (0x1) 2026-05-14T11:09:52.478 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavbase.vdm] 2026-05-14T11:09:52.478 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpavdlta.vdm] (file in cache) 2026-05-14T11:09:52.510 [Engine] IsHybridMode: 0 2026-05-14T11:09:52.510 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-14T11:09:52.541 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-060D1DCEE02A5E878F42DA5F7260F4CC05A2764C.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-14T11:09:56.416 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-14T11:09:56.431 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-14T11:09:56.431 [Engine] New active engine 00007FFCA5EF5810 (no old engine). Number of active engines: 1 2026-05-14T11:09:56.447 EngineInit:Global ASOC is enabled 2026-05-14T11:09:56.447 EngineInit:ASOO is enabled for developer volumes 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T11:09:56.525 MpWriteUupSignatureVersion 1.449.610.0, hr = 0 2026-05-14T11:09:56.525 [SigStatUpd] CSignatureStatus: back to good 2026-05-14T11:09:56.525 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-14T11:09:56.556 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-14T11:09:56.556 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T11:09:56.556 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-14T11:09:56.556 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-14T11:09:56.556 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-14T11:09:56.556 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-14T11:09:56.556 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2068 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11560 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2361 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-14T11:09:56.572 [Plugin] Initializing RTP plugin state... 2026-05-14T11:09:56.572 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-14T11:09:56.572 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B} 2026-05-14T11:09:56.572 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:09:56.572 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:09:56.572 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T11:09:56.572 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T11:09:56.572 MdCoreSvc is supported in this platform and OS 2026-05-14T11:09:56.572 Engine loaded! 2026-05-14T11:09:56.572 [DLP] Create FeatureControlState instance 2026-05-14T11:09:56.572 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-14T11:09:56.572 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-14T11:09:56.572 RegisterSModeChangeListener: hr = 0x1 2026-05-14T11:09:56.572 RegisterHybridModeChangeListener: hr = 0 2026-05-14T11:09:56.588 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-14T11:09:56.588 [SigReleaseHb] Initialized with Stage 0 2026-05-14T11:09:56.588 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-14T11:09:56.588 [SCC][CID=24312_5200] Initializing ... 2026-05-14T11:09:56.588 [SCC][CID=24312_5200] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-14T11:09:56.588 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-14T11:09:56.588 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-14T11:09:56.588 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-14T11:09:56.588 [NRI] Stopping NIS service ... 2026-05-14T11:09:56.603 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-14T11:09:56.603 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.610.0 AV Signature Version: 1.449.610.0 ************************************************************ 2026-05-14T11:09:56.603 Resource usage Monitoring is enabled 2026-05-14T11:09:56.603 Job Notification: New process added to job (4524) 2026-05-14T11:09:56.603 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-14T11:09:56.619 Job Notification: New process added to job (7148) 2026-05-14T11:09:56.619 Job Notification: New process added to job (7144) 2026-05-14T11:09:56.619 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7148] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7144]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-14T11:09:56.666 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-14T11:09:56.666 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-14T11:09:56.681 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-14T11:09:56.681 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-14T11:09:56.681 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-14T11:09:56.681 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T11:09:56.681 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T11:09:56.681 [RTP] Generating the base plugin configuration ... 2026-05-14T11:09:56.681 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-14T11:09:56.681 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:09:56.681 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-14T11:09:56.681 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-14T11:09:56.681 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T11:09:56.681 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-14T11:09:56.681 [RTP] [RTP] StartCommunication 0x000002EC68A9F210 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-14T11:09:56.681 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-14T11:09:56.697 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-14T11:09:56.697 Job Notification: Process exited from job (7148) 2026-05-14T11:09:56.697 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-14T11:09:56.697 Job Notification: Process exited from job (7144) 2026-05-14T11:09:56.994 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T11:09:57.041 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-14T11:09:57.041 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-14T11:09:57.041 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T11:09:59.572 [RTP] Duplicating the current plugin configuration object... 2026-05-14T11:09:59.572 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T11:09:59.572 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-14T11:09:59.572 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-14T11:09:59.572 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-14T11:10:50.994 Process scan (poststartupscan) started. 2026-05-14T11:10:50.994 Process scan (poststartupscan) completed. 2026-05-14T11:10:51.494 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-14T11:10:51.494 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-14T11:10:54.072 [RTP] Duplicating the current plugin configuration object... 2026-05-14T11:10:54.072 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T11:10:54.072 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-14T11:10:54.072 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-14T11:10:54.072 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-14T11:11:50.666 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T11:11:50.666 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-14T11:11:50.666 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T11:14:56.478 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-14T11:14:56.588 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T11:17:58.190 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #735, FileId: 0x5430000000002df, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:05.086 Engine:Process 2308 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-05-14T11:18:05.086 Engine:Process 3688 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-05-14T11:18:05.086 Engine:Process 3688 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-05-14T11:18:05.087 Engine:Process 2308 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-05-14T11:18:19.224 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2919, FileId: 0x18c000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.240 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2921, FileId: 0x15b000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.240 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2924, FileId: 0x15c000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.240 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2925, FileId: 0x191000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.255 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2929, FileId: 0x195000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.255 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2923, FileId: 0x190000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.271 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2928, FileId: 0x15e000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.271 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2932, FileId: 0x162000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.271 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2931, FileId: 0x196000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.271 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2930, FileId: 0x161000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.271 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2934, FileId: 0x163000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.286 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2935, FileId: 0x198000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.302 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2937, FileId: 0x165000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.302 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2939, FileId: 0x166000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.302 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2936, FileId: 0x164000000000dec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:19.444 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2952, FileId: 0x19d000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:18:29.881 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.070.0414.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3462, FileId: 0x20500000000aae2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:19:12.335 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-05-14T11:19:18.257 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4683, FileId: 0x18000000032fe5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:19:56.595 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-14T11:19:56.595 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-14T11:19:56.610 Job Notification: New process added to job (12776) 2026-05-14T11:19:56.610 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-14T11:19:56.626 Job Notification: New process added to job (12760) 2026-05-14T11:19:56.626 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:12776] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:12760]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-14T11:19:56.673 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 57005193(ms) from now at 05:10 (03:10 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-14T11:19:56.720 Job Notification: New process added to job (10920) 2026-05-14T11:19:56.720 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-14T11:19:56.720 Job Notification: New process added to job (6344) 2026-05-14T11:19:56.735 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:10920] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6344]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-14T11:20:02.803 Job Notification: Process exited from job (10920) 2026-05-14T11:20:02.803 Job Notification: Process exited from job (6344) 2026-05-14T11:20:02.881 Job Notification: Process exited from job (12776) 2026-05-14T11:20:02.881 Job Notification: Process exited from job (12760) 2026-05-14T11:22:38.497 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5866, FileId: 0xe800000001a85e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:23:01.164 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6236, FileId: 0x120000000b66f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:24:15.611 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #6357, FileId: 0x1b100000000316a, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:01.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T11:30:09.420 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0178E8956. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6754, FileId: 0x4c000000028a7d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:09.433 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3025799B1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6756, FileId: 0x4d000000028a7d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:09.463 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8DF14496E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6758, FileId: 0x92000000028a5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:09.480 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj35224197D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6760, FileId: 0x4f000000028a7d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:09.778 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC0AB1E9D6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6763, FileId: 0x5e000000028e0f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:10.218 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE725C690F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6774, FileId: 0xd6000000004bdc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:10.297 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9850A395F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6778, FileId: 0x1d900000000ed25, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:10.389 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA585B499A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6779, FileId: 0xdd000000004bdc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:10.419 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECEA419EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6780, FileId: 0x1da00000000ed25, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:11.430 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj870C8C920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6796, FileId: 0x1a000000032fe5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:23.762 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6925, FileId: 0xe70000000148bc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:23.934 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6929, FileId: 0xac000000024f92, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:24.277 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6933, FileId: 0x3a0000000284c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:56.630 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #7239, FileId: 0x19e000000001ea6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:30:56.630 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #7241, FileId: 0x19f000000001ea6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:31:24.411 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7632, FileId: 0x16b000000009b70, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:33:03.122 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #7753, FileId: 0x2900000000e26d, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:38:08.854 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7931, FileId: 0xf0000000b693e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:40:24.369 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7997, FileId: 0xe0000000b6940, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:40:24.383 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7999, FileId: 0x110000000b6944, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:45:06.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T11:54:39.994 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8404, FileId: 0x1a0000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:39.997 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8402, FileId: 0x19f000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.001 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8405, FileId: 0x85000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.002 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8407, FileId: 0x1a1000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.004 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8406, FileId: 0x87000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.006 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8410, FileId: 0x88000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.018 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8412, FileId: 0x1a4000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.020 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8408, FileId: 0x1a2000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.022 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8415, FileId: 0x8b000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.022 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8413, FileId: 0x1a5000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.024 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8414, FileId: 0x1a6000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.039 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8418, FileId: 0x8d000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.041 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8422, FileId: 0x1aa000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.042 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8420, FileId: 0x8f000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.053 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8424, FileId: 0x91000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.056 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8419, FileId: 0x8e000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.463 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8457, FileId: 0x1ad000000000d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T11:54:40.474 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\1b669f07-6f6f-48e9-bb9c-9f268e6418e2. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #8459, FileId: 0x6600000000345e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:00:11.603 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T12:15:16.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T12:30:21.591 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T12:40:50.800 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7ADE6A960. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8839, FileId: 0xd0000000b695d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:50.814 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj21583893F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8840, FileId: 0xe0000000b695d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:50.823 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj54B1629BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8841, FileId: 0xf0000000b695d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:50.834 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj20A4689B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8842, FileId: 0x100000000b695d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:50.850 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB524869BF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8843, FileId: 0xe0000000b695e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:50.864 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj46A1A3943. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8844, FileId: 0xf0000000b695e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.069 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECAF55970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8845, FileId: 0xd0000000b6962, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.082 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA85E2C9CD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8846, FileId: 0xf0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.095 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8547709C4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8847, FileId: 0x100000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.107 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4514FB94A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8848, FileId: 0x110000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.121 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj69BD1199C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8849, FileId: 0x120000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.133 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA22DEA9F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8850, FileId: 0x130000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.146 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB42E5692A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8851, FileId: 0x140000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.159 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj75DB9399F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8852, FileId: 0x150000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.172 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA18614995. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8853, FileId: 0x160000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.183 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDE35B7940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8854, FileId: 0x170000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.195 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1CFD5B931. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8855, FileId: 0x180000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.225 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5BD7E0965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8856, FileId: 0x190000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.240 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6CBB689D2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8857, FileId: 0x1a0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.481 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj62433E967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8858, FileId: 0x1b0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.495 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj774D07996. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8859, FileId: 0x1c0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.504 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj289AA591A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8860, FileId: 0x1d0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.511 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA2418D9B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8861, FileId: 0x1e0000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.527 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBE608D966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8862, FileId: 0x2a0000000b695e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.533 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjACA6B393A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8863, FileId: 0x2b0000000b695e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.633 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF31FAA990. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8864, FileId: 0x300000000b695e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.646 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj55F1F9920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8865, FileId: 0x200000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.660 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3471D49B5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8866, FileId: 0x210000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.673 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9E8B2C905. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8867, FileId: 0x220000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.686 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC3DDBC90D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8868, FileId: 0x230000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.711 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj64DF9A942. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8869, FileId: 0x240000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.726 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3327DA91A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8870, FileId: 0x250000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:40:51.747 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9CCA1C9EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8871, FileId: 0x260000000b6961, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:41:05.749 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8872, FileId: 0x1f4000000006a59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:41:05.856 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8874, FileId: 0x120000000b695c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:41:19.805 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8876, FileId: 0x130000000b6956, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:41:19.810 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8878, FileId: 0xe0000000b6959, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T12:45:26.596 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T13:00:31.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T13:09:42.776 [AutoPurge] Verification Routine tasks have started. 2026-05-14T13:09:42.776 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-14T13:09:42.783 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-14T13:09:42.783 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-14T13:09:42.783 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-14T13:09:42.783 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-14T13:09:42.783 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-14T13:09:42.795 [AutoPurge] Cleanup Routine tasks have started. 2026-05-14T13:09:42.814 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-14T13:09:42.820 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-14T13:09:42.821 [AutoPurge] Delete C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\759258EA988B8F64A6480E49BEDEE761, fRet=0x1 2026-05-14T13:09:42.821 [AutoPurge] 1 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-14-2026 13:09:42 2026-05-14T13:09:42.831 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:A841F21C-D7D5-4F0D-9F0A-506533188AB3, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-14T13:09:42.831 Scheduled scan with Id A841F21C-D7D5-4F0D-9F0A-506533188AB3 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-14T13:09:42.834 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-14T13:09:42.834 [SFC] System file cache build is not needed (already completed) Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-14-2026 13:09:42 2026-05-14T13:09:42.849 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-14T13:09:42.850 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-14T13:09:42.850 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-14T13:09:42.850 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-14T13:09:42.850 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-14T13:09:42.854 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-14T13:09:43.057 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-14T13:09:43.061 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-14T13:09:43.093 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-14T13:09:43.116 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:43.437 Job Notification: New process added to job (3608) 2026-05-14T13:09:43.442 Task(GetDeviceTicket -AccessKey 5C71A22F-BD27-4E82-1A14-EA6C2497A3EB ) launched as network service 2026-05-14T13:09:43.487 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:09:43.889 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-14T13:09:43.929 Job Notification: Process exited from job (3608) 2026-05-14T13:09:43.999 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-14T13:09:44.018 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-14T13:09:44.187 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-14T13:09:44.187 [Cloud] Start of cloud request. Passive mode: 0 2026-05-14T13:09:44.187 [Cloud] Queued cloud request. 2026-05-14T13:09:44.187 [Cloud] Dequeued cloud request. 2026-05-14T13:09:44.191 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-14T13:09:44.192 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-14T13:09:44.193 [AutoPurge] Verification Routine tasks have ended. 2026-05-14T13:09:44.362 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-14T13:09:44.363 [Cloud] End of cloud request. 2026-05-14T13:09:44.447 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-14T13:09:44.516 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-14T13:09:44.640 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-14T13:09:44.651 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-14T13:09:44.718 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-14T13:09:44.736 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T13:09:44.740 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T13:09:44.740 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-14T13:09:44.741 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-14T13:09:44.741 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-14T13:09:44.741 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-14T13:09:44.741 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-14T13:09:44.742 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-14T13:09:44.742 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-14T13:09:44.742 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-14T13:09:44.742 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-14T13:09:44.742 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-14T13:09:44.742 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-14T13:09:44.742 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-14T13:09:44.742 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-14T13:09:44.742 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-14T13:09:44.745 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T13:09:44.749 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T13:09:44.752 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T13:09:44.814 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-14T13:09:44.816 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 41016409(ms) from now at 02:33 (00:33 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-14T13:09:44.845 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T13:09:44.852 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-14T13:09:44.855 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T13:09:44.858 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-14T13:09:44.908 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-14T13:09:45.040 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-14T13:09:45.198 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-14T13:09:45.335 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-14T13:09:45.475 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-14T13:09:45.483 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:09:45.514 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-14T13:09:45.630 Engine:Setting original file name "Annot.api" for "c:\program files\adobe\acrobat dc\acrobat\plug_ins\annots.api", hr=0x800710da 2026-05-14T13:09:45.717 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-14T13:09:45.773 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-14T13:09:46.070 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-14T13:09:46.283 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-14T13:09:46.319 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-14T13:09:46.622 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-14T13:09:46.778 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-14T13:09:47.223 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:47.246 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-14T13:09:47.275 [RTP] Duplicating the current plugin configuration object... 2026-05-14T13:09:47.275 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T13:09:47.275 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-05-14T13:09:47.275 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T13:09:47.275 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-14T13:09:47.276 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-05-14T13:09:47.305 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:09:47.519 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-14T13:09:47.621 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-14T13:09:47.827 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-14T13:09:48.036 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-14T13:09:48.110 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-14T13:09:48.123 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-14T13:09:48.158 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-14T13:09:48.356 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-14T13:09:48.433 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-14T13:09:48.554 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-14T13:09:48.656 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-14T13:09:49.130 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-14T13:09:49.147 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-14T13:09:49.406 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-14T13:09:49.480 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-14T13:09:50.038 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-14T13:09:50.068 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-14T13:09:50.072 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-14T13:09:50.076 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-14T13:09:50.177 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-14T13:09:50.233 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-14T13:09:50.329 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-14T13:09:50.523 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ko.dll", hr=0x800710da 2026-05-14T13:09:50.606 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-14T13:09:50.778 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-14T13:09:50.797 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:50.823 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-14T13:09:50.875 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-14T13:09:50.976 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-14T13:09:51.033 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-14T13:09:51.050 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-14T13:09:51.059 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-14T13:09:51.267 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-05-14T13:09:51.408 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-14T13:09:51.412 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-14T13:09:51.581 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:51.633 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-14T13:09:51.674 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-14T13:09:52.025 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-14T13:09:52.165 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-14T13:09:52.218 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-14T13:09:52.454 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-14T13:09:52.466 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-14T13:09:52.749 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-14T13:09:52.819 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-14T13:09:52.825 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-14T13:09:52.927 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-14T13:09:52.937 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-14T13:09:52.970 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-14T13:09:53.350 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-14T13:09:53.399 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-14T13:09:53.502 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-14T13:09:53.536 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-14T13:09:53.673 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-14T13:09:53.794 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-14T13:09:53.850 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-14T13:09:53.883 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-14T13:09:54.020 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-14T13:09:54.285 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:54.598 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-14T13:09:54.635 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-14T13:09:54.646 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-14T13:09:54.712 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:09:55.124 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:09:55.213 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:09:55.506 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-14T13:09:55.554 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-14T13:09:55.685 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-14T13:09:55.766 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-14T13:09:55.803 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-14T13:09:55.817 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-14T13:09:56.147 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-14T13:09:56.230 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-14T13:09:56.304 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-14T13:09:56.383 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-14T13:09:56.401 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-14T13:09:56.448 ProcessImageName: explorer.exe, Pid: 3672, TotalTime: 3922, Count: 111, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: AcroCEF.exe, Pid: 9460, TotalTime: 3709, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-14T13:09:56.448 ProcessImageName: AsPowerBar.exe, Pid: 12372, TotalTime: 2693, Count: 18, MaxTime: 1093, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-05-14T13:09:56.448 ProcessImageName: DeviceCensus.exe, Pid: 1332, TotalTime: 2607, Count: 6, MaxTime: 1281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 40% 2026-05-14T13:09:56.448 ProcessImageName: dllhost.exe, Pid: 6512, TotalTime: 2597, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: DipAwayMode.exe, Pid: 6480, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: MOM.exe, Pid: 3188, TotalTime: 1883, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-14T13:09:56.448 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10932, TotalTime: 1702, Count: 3, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 7% 2026-05-14T13:09:56.448 ProcessImageName: AISuite3.exe, Pid: 7280, TotalTime: 1430, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-14T13:09:56.448 ProcessImageName: websockify.exe, Pid: 10836, TotalTime: 833, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-14T13:09:56.448 ProcessImageName: WmiPrvSE.exe, Pid: 10684, TotalTime: 632, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-05-14T13:09:56.448 ProcessImageName: TeamViewer.exe, Pid: 5780, TotalTime: 439, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-14T13:09:56.448 ProcessImageName: firefox.exe, Pid: 4736, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09444, EstimatedImpact: 56% 2026-05-14T13:09:56.448 ProcessImageName: FileCoAuth.exe, Pid: 3012, TotalTime: 276, Count: 16, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-14T13:09:56.448 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 273, Count: 21, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: firefox.exe, Pid: 9536, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09564, EstimatedImpact: 10% 2026-05-14T13:09:56.448 ProcessImageName: svchost.exe, Pid: 8912, TotalTime: 233, Count: 3, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4D02.tmp, EstimatedImpact: 1% 2026-05-14T13:09:56.448 ProcessImageName: TabTip.exe, Pid: 1376, TotalTime: 232, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-14T13:09:56.448 ProcessImageName: FileSyncConfig.exe, Pid: 12332, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 69% 2026-05-14T13:09:56.448 ProcessImageName: RuntimeBroker.exe, Pid: 8888, TotalTime: 187, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: AdobeCollabSync.exe, Pid: 11208, TotalTime: 180, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-14.log, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: FileCoAuth.exe, Pid: 10408, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-14T13:09:56.448 ProcessImageName: WhatsApp.Root.exe, Pid: 8604, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\applog.txt, EstimatedImpact: 0% 2026-05-14T13:09:56.448 ProcessImageName: ngentask.exe, Pid: 9592, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 9% 2026-05-14T13:09:56.449 ProcessImageName: ngentask.exe, Pid: 5548, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 2204, TotalTime: 139, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 968, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 2584, TotalTime: 138, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: backgroundTaskHost.exe, Pid: 10580, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1778676020->(UTF-16LE), EstimatedImpact: 12% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 916, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: backgroundTaskHost.exe, Pid: 4616, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 22% 2026-05-14T13:09:56.449 ProcessImageName: Acrobat.exe, Pid: 8236, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 4% 2026-05-14T13:09:56.449 ProcessImageName: OfficeC2RClient.exe, Pid: 6184, TotalTime: 91, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-14T13:09:56.449 ProcessImageName: OfficeC2RClient.exe, Pid: 3884, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-14T13:09:56.449 ProcessImageName: SecurityHealthHost.exe, Pid: 12820, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 8% 2026-05-14T13:09:56.449 ProcessImageName: firefox.exe, Pid: 1992, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 3% 2026-05-14T13:09:56.449 ProcessImageName: ngentask.exe, Pid: 10180, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 36% 2026-05-14T13:09:56.449 ProcessImageName: ngentask.exe, Pid: 8864, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 33% 2026-05-14T13:09:56.449 ProcessImageName: SDXHelper.exe, Pid: 6892, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-14T13:09:56.449 ProcessImageName: Acrobat.exe, Pid: 6496, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 7% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 2760, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: taskhostw.exe, Pid: 12784, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-14T13:09:56.449 ProcessImageName: PhoneExperienceHost.exe, Pid: 10208, TotalTime: 60, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: SDXHelper.exe, Pid: 2892, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\OutlookCapabilities.json, EstimatedImpact: 1% 2026-05-14T13:09:56.449 ProcessImageName: AcroCEF.exe, Pid: 9988, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 40% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 5636, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: runonce.exe, Pid: 11720, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 1% 2026-05-14T13:09:56.449 ProcessImageName: OneDriveSetup.exe, Pid: 12772, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncConfig.exe, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: OfficeC2RClient.exe, Pid: 12964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322.log, EstimatedImpact: 2% 2026-05-14T13:09:56.449 ProcessImageName: OfficeC2RClient.exe, Pid: 8472, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1338.log, EstimatedImpact: 2% 2026-05-14T13:09:56.449 ProcessImageName: backgroundTaskHost.exe, Pid: 9788, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 28% 2026-05-14T13:09:56.449 ProcessImageName: OpenWith.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 5% 2026-05-14T13:09:56.449 ProcessImageName: TeamViewer_Service.exe, Pid: 4488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: AggregatorHost.exe, Pid: 5396, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: OfficeC2RClient.exe, Pid: 11112, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: svchost.exe, Pid: 11664, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: brynhildr.exe, Pid: 3304, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-14T13:09:56.449 ProcessImageName: DismHost.exe, Pid: 11716, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-05-14T13:09:56.518 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-14T13:09:56.651 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-14T13:09:56.755 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-14T13:09:56.828 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-14T13:09:56.849 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-14T13:09:56.859 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-14T13:09:57.067 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-14T13:09:57.070 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-14T13:09:57.215 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-14T13:09:57.692 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-14T13:09:57.947 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-14T13:09:58.000 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-05-14T13:09:58.350 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-14T13:09:58.405 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-14T13:09:58.463 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-14T13:09:58.522 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-14T13:09:58.622 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-14T13:09:58.628 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-14T13:09:58.780 Engine:Setting original file name "schtasks.exe" for "c:\windows\winsxs\amd64_microsoft-windows-sctasks_31bf3856ad364e35_10.0.22000.653_none_8587430a3a996be3\schtasks.exe", hr=0x800710da 2026-05-14T13:09:58.969 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-14T13:09:59.150 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-14T13:09:59.274 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-14T13:09:59.575 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-14T13:09:59.671 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-14T13:09:59.784 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-14T13:10:00.077 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-14T13:10:00.161 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-14T13:10:00.197 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-14T13:10:00.328 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-14T13:10:00.336 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-14T13:10:00.450 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-14T13:10:00.510 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-14T13:10:00.669 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-14T13:10:00.766 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-14T13:10:00.771 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:01.025 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-14T13:10:01.292 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-14T13:10:01.322 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-14T13:10:01.418 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-14T13:10:01.515 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-14T13:10:01.765 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-14T13:10:01.859 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-14T13:10:01.878 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-14T13:10:01.980 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:02.524 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-14T13:10:02.638 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-14T13:10:02.669 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_lt.dll", hr=0x800710da 2026-05-14T13:10:02.737 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-14T13:10:03.130 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-14T13:10:03.155 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-14T13:10:03.170 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-14T13:10:03.454 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-14T13:10:03.684 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-14T13:10:03.714 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-14T13:10:03.838 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-14T13:10:03.973 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-14T13:10:03.984 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-14T13:10:04.205 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-14T13:10:04.373 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-14T13:10:04.393 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-14T13:10:04.483 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-14T13:10:04.849 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-14T13:10:04.901 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-14T13:10:04.906 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-14T13:10:04.988 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-14T13:10:05.353 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x800710da 2026-05-14T13:10:05.529 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-14T13:10:05.615 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ro.dll", hr=0x800710da 2026-05-14T13:10:05.682 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-14T13:10:05.753 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-14T13:10:05.786 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-14T13:10:05.944 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-14T13:10:06.039 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-14T13:10:06.081 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-14T13:10:06.200 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:06.316 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-14T13:10:06.802 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-14T13:10:06.890 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_fi.dll", hr=0x800710da 2026-05-14T13:10:06.919 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-14T13:10:06.993 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-14T13:10:07.230 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-14T13:10:07.253 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-14T13:10:07.337 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-14T13:10:08.004 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-14T13:10:08.423 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-14T13:10:08.456 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-14T13:10:08.525 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-14T13:10:08.561 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-14T13:10:09.103 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-14T13:10:09.496 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-14T13:10:09.548 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-14T13:10:09.703 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-14T13:10:09.950 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-14T13:10:09.996 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-14T13:10:10.297 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-14T13:10:10.369 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-14T13:10:10.417 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-14T13:10:10.451 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-14T13:10:10.552 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-14T13:10:10.995 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:10:11.280 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-14T13:10:11.335 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-14T13:10:11.344 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-14T13:10:11.927 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-14T13:10:12.184 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-14T13:10:12.314 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-14T13:10:12.524 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-14T13:10:12.629 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-14T13:10:12.871 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-14T13:10:12.876 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-14T13:10:12.942 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-14T13:10:13.094 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-14T13:10:13.143 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-14T13:10:13.207 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-14T13:10:13.303 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-14T13:10:13.323 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-14T13:10:13.333 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-14T13:10:13.374 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-14T13:10:13.383 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-14T13:10:13.629 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-14T13:10:13.635 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-14T13:10:13.675 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-14T13:10:13.754 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-14T13:10:13.868 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-14T13:10:14.060 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-14T13:10:14.086 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_tr.dll", hr=0x800710da 2026-05-14T13:10:14.314 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:10:14.562 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-14T13:10:14.694 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-14T13:10:14.936 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-14T13:10:15.170 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-14T13:10:15.240 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-14T13:10:15.312 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-14T13:10:15.400 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-14T13:10:15.706 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-14T13:10:15.760 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-14T13:10:15.809 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-14T13:10:15.830 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-14T13:10:15.837 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-14T13:10:15.897 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-14T13:10:16.176 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-14T13:10:16.186 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-14T13:10:16.451 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_it.dll", hr=0x800710da 2026-05-14T13:10:16.657 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-14T13:10:16.741 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-14T13:10:17.275 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-14T13:10:17.553 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-14T13:10:17.613 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-14T13:10:17.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-14T13:10:18.082 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-14T13:10:18.435 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-14T13:10:18.800 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-14T13:10:18.846 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-14T13:10:19.068 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-14T13:10:19.276 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_da.dll", hr=0x800710da 2026-05-14T13:10:19.359 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-14T13:10:19.430 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-14T13:10:19.519 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-14T13:10:19.852 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-14T13:10:19.880 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-14T13:10:20.003 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-05-14T13:10:20.090 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-14T13:10:20.422 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-14T13:10:20.452 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-14T13:10:21.171 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-14T13:10:21.406 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-14T13:10:21.515 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:21.642 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-14T13:10:22.062 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-14T13:10:22.158 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-14T13:10:22.207 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-14T13:10:22.249 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-14T13:10:22.318 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-14T13:10:22.336 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:22.477 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-14T13:10:22.536 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-14T13:10:22.831 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-14T13:10:22.894 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-14T13:10:22.991 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:23.100 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-14T13:10:23.406 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-14T13:10:23.476 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-14T13:10:23.629 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-14T13:10:23.857 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-14T13:10:23.960 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-14T13:10:24.349 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-14T13:10:24.428 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-14T13:10:24.710 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-14T13:10:25.094 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-14T13:10:25.489 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-14T13:10:25.806 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-05-14T13:10:25.939 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-14T13:10:26.053 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-14T13:10:26.499 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-14T13:10:26.695 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-14T13:10:26.716 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-14T13:10:26.783 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-14T13:10:26.789 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-14T13:10:26.804 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-14T13:10:27.253 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-14T13:10:27.291 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-14T13:10:27.357 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-14T13:10:27.622 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-14T13:10:27.863 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-14T13:10:27.902 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_vi.dll", hr=0x800710da 2026-05-14T13:10:27.958 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-14T13:10:28.005 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-14T13:10:28.022 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-14T13:10:28.162 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-14T13:10:28.718 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-14T13:10:28.972 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-14T13:10:28.979 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-14T13:10:29.029 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-14T13:10:29.249 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-14T13:10:29.359 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-14T13:10:29.715 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-14T13:10:29.720 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-14T13:10:29.725 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-14T13:10:30.053 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-14T13:10:30.196 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-14T13:10:30.522 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-14T13:10:30.649 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-14T13:10:30.723 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-14T13:10:30.753 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-05-14T13:10:30.801 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-14T13:10:31.596 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-14T13:10:31.718 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-14T13:10:31.763 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-14T13:10:31.955 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-05-14T13:10:32.006 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-14T13:10:32.086 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-14T13:10:32.145 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:10:32.221 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-14T13:10:32.235 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-05-14T13:10:32.257 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-14T13:10:32.402 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-14T13:10:32.441 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-14T13:10:32.609 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-14T13:10:32.640 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-14T13:10:32.645 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-14T13:10:32.915 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-14T13:10:33.037 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-14T13:10:33.090 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-14T13:10:33.114 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-14T13:10:33.397 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-14T13:10:33.494 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:10:33.513 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:33.525 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-14T13:10:33.774 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-14T13:10:34.118 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-14T13:10:34.205 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-05-14T13:10:34.309 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-05-14T13:10:34.417 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-14T13:10:34.486 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-05-14T13:10:34.620 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-05-14T13:10:34.698 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-05-14T13:10:34.783 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-05-14T13:10:34.904 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-05-14T13:10:34.944 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-05-14T13:10:34.974 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-05-14T13:10:35.179 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-05-14T13:10:35.255 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-05-14T13:10:35.267 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-05-14T13:10:35.276 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-14T13:10:36.023 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-05-14T13:10:36.133 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-05-14T13:10:36.202 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-05-14T13:10:36.337 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-05-14T13:10:36.575 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-05-14T13:10:36.593 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-05-14T13:10:36.922 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-05-14T13:10:37.006 Engine:Setting original file name "msdxm.ocx" for "c:\windows\syswow64\dxmasf.dll", hr=0x800710da 2026-05-14T13:10:37.429 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-05-14T13:10:37.477 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-05-14T13:10:37.565 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-05-14T13:10:37.572 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-05-14T13:10:37.664 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_flac_plugin.dll", hr=0x800710da 2026-05-14T13:10:37.758 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\de-de\wsepno.dll.mui", hr=0x800710da 2026-05-14T13:10:38.024 Engine:Setting original file name "iscsiexe.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a56629be7473c8fd73a9fa129c67ea10\iscsiexe.dll.mui", hr=0x800710da 2026-05-14T13:10:38.379 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\11a533a2a1579c078648dff16787f54d\winnlsres.dll.mui", hr=0x800710da 2026-05-14T13:10:38.429 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_sr.dll", hr=0x800710da 2026-05-14T13:10:38.555 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_udp_plugin.dll", hr=0x800710da 2026-05-14T13:10:38.561 Engine:Setting original file name "hgclientservice.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\3bbe55bd039ee800ee6a295dceb66af6\hgclientservice.dll.mui", hr=0x800710da 2026-05-14T13:10:38.617 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\bcf69d5438188e70293457b0ada7ebac\aeevts.dll.mui", hr=0x800710da 2026-05-14T13:10:38.637 Engine:Triggered AR EMS scan 2026-05-14T13:10:38.641 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.647 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\system32\devobj.dll", hr=0x800710da 2026-05-14T13:10:38.658 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.674 Engine:EMS scan for process: svchost pid: 916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.678 Engine:EMS scan for process: svchost pid: 1032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.683 Engine:EMS scan for process: svchost pid: 1172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.694 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.696 Engine:EMS scan for process: svchost pid: 1364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.701 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.704 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.706 Engine:EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.713 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.715 Engine:EMS scan for process: svchost pid: 1540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.720 Engine:EMS scan for process: svchost pid: 1568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.726 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.729 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.731 Engine:EMS scan for process: svchost pid: 1696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.735 Engine:EMS scan for process: svchost pid: 1908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.737 Engine:EMS scan for process: svchost pid: 1104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.740 Engine:EMS scan for process: svchost pid: 1776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.744 Engine:EMS scan for process: svchost pid: 2064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.747 Engine:EMS scan for process: svchost pid: 2156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.750 Engine:EMS scan for process: svchost pid: 2204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.753 Engine:EMS scan for process: svchost pid: 2320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.756 Engine:EMS scan for process: svchost pid: 2488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.759 Engine:EMS scan for process: svchost pid: 2576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.761 Engine:EMS scan for process: svchost pid: 2584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.763 Engine:EMS scan for process: svchost pid: 2596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.765 Engine:EMS scan for process: svchost pid: 2696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.768 Engine:EMS scan for process: svchost pid: 2748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.771 Engine:EMS scan for process: svchost pid: 2760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.775 Engine:EMS scan for process: svchost pid: 2972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.780 Engine:EMS scan for process: svchost pid: 2084, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.787 Engine:EMS scan for process: svchost pid: 2652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.791 Engine:EMS scan for process: svchost pid: 3224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.793 Engine:EMS scan for process: svchost pid: 3580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.797 Engine:EMS scan for process: svchost pid: 3588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.799 Engine:EMS scan for process: svchost pid: 3680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.805 Engine:EMS scan for process: svchost pid: 3752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.811 Engine:EMS scan for process: svchost pid: 3816, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.815 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.820 Engine:EMS scan for process: svchost pid: 3100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.824 Engine:EMS scan for process: svchost pid: 4100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.829 Engine:EMS scan for process: svchost pid: 4148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.835 Engine:EMS scan for process: svchost pid: 4188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.844 Engine:EMS scan for process: svchost pid: 4392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.848 Engine:EMS scan for process: svchost pid: 4448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.851 OriginalFileName Maintenance::9897 files in Moac, 242 skipped (cached), 1 filename set 2026-05-14T13:10:38.851 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-14T13:10:38.853 Engine:EMS scan for process: svchost pid: 4460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.855 Engine:EMS scan for process: svchost pid: 4536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.861 Engine:EMS scan for process: svchost pid: 5104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.863 Engine:EMS scan for process: dllhost pid: 5908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.865 Engine:EMS scan for process: svchost pid: 5916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.869 Engine:EMS scan for process: svchost pid: 4380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.889 Engine:EMS scan for process: svchost pid: 3568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.892 Engine:EMS scan for process: svchost pid: 4652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.895 Engine:EMS scan for process: svchost pid: 6232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.899 Engine:EMS scan for process: svchost pid: 7528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.904 Engine:EMS scan for process: svchost pid: 7708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.909 Engine:EMS scan for process: svchost pid: 7840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.914 Engine:EMS scan for process: svchost pid: 7904, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.917 Engine:EMS scan for process: svchost pid: 6272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.920 Engine:EMS scan for process: svchost pid: 5636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.933 Engine:EMS scan for process: svchost pid: 6124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.955 Engine:EMS scan for process: svchost pid: 6780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.966 Engine:EMS scan for process: svchost pid: 6868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.970 Engine:EMS scan for process: svchost pid: 1400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:38.976 Engine:EMS scan for process: explorer pid: 3672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.018 Engine:EMS scan for process: svchost pid: 712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.028 Engine:EMS scan for process: svchost pid: 8276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.032 Engine:EMS scan for process: svchost pid: 9036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.037 Engine:EMS scan for process: dllhost pid: 6512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.040 Engine:EMS scan for process: svchost pid: 12528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.044 Engine:EMS scan for process: svchost pid: 12880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.049 Engine:EMS scan for process: svchost pid: 11664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.058 Engine:EMS scan for process: svchost pid: 10000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.062 Engine:EMS scan for process: svchost pid: 7508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.069 Engine:EMS scan for process: dllhost pid: 10004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.070 Engine:EMS scan for process: svchost pid: 7620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.073 Engine:EMS scan for process: svchost pid: 10448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.084 Engine:EMS scan for process: svchost pid: 1184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:10:39.088 Engine:EMS scan for process: svchost pid: 12448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-14T13:14:48.983 QuickScan:ScanID:A841F21C-D7D5-4F0D-9F0A-506533188AB3: Quick scan finished with error 0 2026-05-14T13:14:49.506 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-14T13:14:49.506 [RTP] Duplicating the current plugin configuration object... 2026-05-14T13:14:49.506 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T13:14:49.506 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-14T13:14:49.506 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T13:14:49.506 [RTP] No config change detected. Not updating plugin configuration. 2026-05-14T13:14:49.506 [RTP] No config changes found. No configuration switch. 2026-05-14T13:14:49.506 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-14T13:14:51.010 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T13:14:51.016 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-14T13:14:51.017 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-14T13:15:36.603 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T13:30:41.594 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T13:45:46.602 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T13:49:04.980 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10288, FileId: 0x95000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.982 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10290, FileId: 0x96000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.984 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10292, FileId: 0x5600000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.986 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10293, FileId: 0x5700000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.989 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10294, FileId: 0x99000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.991 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10295, FileId: 0x5800000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.995 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10296, FileId: 0x9a000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.997 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10291, FileId: 0x98000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:04.999 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10298, FileId: 0x9b000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.003 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10299, FileId: 0x5a00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.004 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10289, FileId: 0x5400000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.009 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10301, FileId: 0x5b00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.009 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10302, FileId: 0x9d000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.026 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10297, FileId: 0x5900000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.027 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10304, FileId: 0x5e00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.027 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10300, FileId: 0x9c000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.580 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10386, FileId: 0x6200000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.580 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10391, FileId: 0x6400000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.590 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10393, FileId: 0x6500000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.591 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10388, FileId: 0xa3000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.592 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10394, FileId: 0xa6000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.593 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10389, FileId: 0x6300000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.677 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10410, FileId: 0x6900000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.679 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10411, FileId: 0x6a00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.680 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10409, FileId: 0xaa000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.682 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10406, FileId: 0x6800000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.735 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10419, FileId: 0x6d00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.735 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10420, FileId: 0xae000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.739 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10422, FileId: 0xaf000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.753 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10415, FileId: 0x6b00000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.926 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10459, FileId: 0xb2000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:05.928 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10458, FileId: 0x7100000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T13:49:06.928 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10546, FileId: 0x7400000000c736, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T14:00:51.592 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T14:15:56.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T14:21:54.681 [RTP] [Mini-filter] OpenWithoutRead notification (1231, 10011, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-14T14:22:00.186 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11249, FileId: 0xb100000000ad0d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T14:31:01.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T14:46:06.602 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T15:01:11.595 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T15:08:38.622 [RTP] 8 newly mounted volumes accumulated, forcing a config update ... 2026-05-14T15:08:38.622 [RTP] Duplicating the current plugin configuration object... 2026-05-14T15:08:38.622 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-14T15:08:38.622 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-14T15:08:38.622 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-14T15:08:38.622 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-14T15:08:38.622 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-14T15:08:38.985 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-14T15:09:56.451 ProcessImageName: explorer.exe, Pid: 3672, TotalTime: 7549, Count: 170, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: AcroCEF.exe, Pid: 9460, TotalTime: 3709, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-14T15:09:56.451 ProcessImageName: AsPowerBar.exe, Pid: 12372, TotalTime: 2693, Count: 18, MaxTime: 1093, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-05-14T15:09:56.451 ProcessImageName: DeviceCensus.exe, Pid: 1332, TotalTime: 2607, Count: 6, MaxTime: 1281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 40% 2026-05-14T15:09:56.451 ProcessImageName: dllhost.exe, Pid: 6512, TotalTime: 2597, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: DipAwayMode.exe, Pid: 6480, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: firefox.exe, Pid: 1848, TotalTime: 2505, Count: 284, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa12724, EstimatedImpact: 73% 2026-05-14T15:09:56.451 ProcessImageName: MOM.exe, Pid: 3188, TotalTime: 1883, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-14T15:09:56.451 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10932, TotalTime: 1702, Count: 3, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 7% 2026-05-14T15:09:56.451 ProcessImageName: AISuite3.exe, Pid: 7280, TotalTime: 1430, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-14T15:09:56.451 ProcessImageName: websockify.exe, Pid: 10836, TotalTime: 833, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-14T15:09:56.451 ProcessImageName: WmiPrvSE.exe, Pid: 10684, TotalTime: 632, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-05-14T15:09:56.451 ProcessImageName: TeamViewer.exe, Pid: 5780, TotalTime: 439, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-14T15:09:56.451 ProcessImageName: firefox.exe, Pid: 4736, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09444, EstimatedImpact: 56% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 363, Count: 27, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 3692, TotalTime: 345, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\s641031CheckReachable56C9E93A-CEA2-41E8-B61A-EBF7896AE0F4, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: FileCoAuth.exe, Pid: 3012, TotalTime: 276, Count: 16, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-14T15:09:56.451 ProcessImageName: firefox.exe, Pid: 9536, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09564, EstimatedImpact: 10% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 8912, TotalTime: 233, Count: 3, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4D02.tmp, EstimatedImpact: 1% 2026-05-14T15:09:56.451 ProcessImageName: TabTip.exe, Pid: 1376, TotalTime: 232, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-14T15:09:56.451 ProcessImageName: FileSyncConfig.exe, Pid: 12332, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 69% 2026-05-14T15:09:56.451 ProcessImageName: RuntimeBroker.exe, Pid: 8888, TotalTime: 187, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: AdobeCollabSync.exe, Pid: 11208, TotalTime: 180, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-14.log, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: FileCoAuth.exe, Pid: 10408, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-14T15:09:56.451 ProcessImageName: WhatsApp.Root.exe, Pid: 8604, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\applog.txt, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: ngentask.exe, Pid: 9592, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 9% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 2204, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: ngentask.exe, Pid: 5548, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 968, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 2584, TotalTime: 138, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: backgroundTaskHost.exe, Pid: 10580, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1778676020->(UTF-16LE), EstimatedImpact: 12% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 1692, TotalTime: 122, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 3% 2026-05-14T15:09:56.451 ProcessImageName: OfficeClickToRun.exe, Pid: 4112, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 916, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: PhoneExperienceHost.exe, Pid: 10208, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: backgroundTaskHost.exe, Pid: 4616, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 22% 2026-05-14T15:09:56.451 ProcessImageName: Acrobat.exe, Pid: 8236, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 4% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 6184, TotalTime: 91, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 3884, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-14T15:09:56.451 ProcessImageName: SecurityHealthHost.exe, Pid: 12820, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 8% 2026-05-14T15:09:56.451 ProcessImageName: firefox.exe, Pid: 1992, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 3% 2026-05-14T15:09:56.451 ProcessImageName: ngentask.exe, Pid: 8864, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 33% 2026-05-14T15:09:56.451 ProcessImageName: ngentask.exe, Pid: 10180, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 36% 2026-05-14T15:09:56.451 ProcessImageName: SDXHelper.exe, Pid: 6892, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-14T15:09:56.451 ProcessImageName: Acrobat.exe, Pid: 6496, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 7% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 2760, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: taskhostw.exe, Pid: 12784, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-14T15:09:56.451 ProcessImageName: SDXHelper.exe, Pid: 2892, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\OutlookCapabilities.json, EstimatedImpact: 1% 2026-05-14T15:09:56.451 ProcessImageName: AcroCEF.exe, Pid: 9988, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 40% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 5636, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: runonce.exe, Pid: 11720, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 1% 2026-05-14T15:09:56.451 ProcessImageName: OfficeClickToRun.exe, Pid: 4132, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: OneDriveSetup.exe, Pid: 12772, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncConfig.exe, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: dasHost.exe, Pid: 5308, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 8472, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1338.log, EstimatedImpact: 2% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 12964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322.log, EstimatedImpact: 2% 2026-05-14T15:09:56.451 ProcessImageName: AggregatorHost.exe, Pid: 5396, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: backgroundTaskHost.exe, Pid: 9788, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 28% 2026-05-14T15:09:56.451 ProcessImageName: OpenWith.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 5% 2026-05-14T15:09:56.451 ProcessImageName: TeamViewer_Service.exe, Pid: 4488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: dllhost.exe, Pid: 5908, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: OfficeC2RClient.exe, Pid: 11112, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: StoreDesktopExtension.exe, Pid: 6080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 13% 2026-05-14T15:09:56.451 ProcessImageName: svchost.exe, Pid: 11664, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: brynhildr.exe, Pid: 3304, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-14T15:09:56.451 ProcessImageName: DismHost.exe, Pid: 11716, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-05-14T15:16:16.592 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T15:31:21.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T15:46:26.592 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T16:01:31.598 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T16:16:36.603 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T16:31:41.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T16:46:46.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T17:01:51.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T17:09:56.464 ProcessImageName: explorer.exe, Pid: 3672, TotalTime: 7549, Count: 170, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: AcroCEF.exe, Pid: 9460, TotalTime: 3709, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-14T17:09:56.464 ProcessImageName: AsPowerBar.exe, Pid: 12372, TotalTime: 2693, Count: 18, MaxTime: 1093, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-05-14T17:09:56.464 ProcessImageName: DeviceCensus.exe, Pid: 1332, TotalTime: 2607, Count: 6, MaxTime: 1281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 40% 2026-05-14T17:09:56.464 ProcessImageName: dllhost.exe, Pid: 6512, TotalTime: 2597, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: DipAwayMode.exe, Pid: 6480, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: firefox.exe, Pid: 1848, TotalTime: 2505, Count: 284, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa12724, EstimatedImpact: 73% 2026-05-14T17:09:56.464 ProcessImageName: MOM.exe, Pid: 3188, TotalTime: 1883, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-14T17:09:56.464 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10932, TotalTime: 1702, Count: 3, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 7% 2026-05-14T17:09:56.464 ProcessImageName: AISuite3.exe, Pid: 7280, TotalTime: 1430, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-14T17:09:56.464 ProcessImageName: websockify.exe, Pid: 10836, TotalTime: 833, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-14T17:09:56.464 ProcessImageName: WmiPrvSE.exe, Pid: 10684, TotalTime: 632, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-05-14T17:09:56.464 ProcessImageName: WmiPrvSE.exe, Pid: 6288, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\dxgmms2.sys, EstimatedImpact: 95% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 484, Count: 34, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: TeamViewer.exe, Pid: 5780, TotalTime: 439, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-14T17:09:56.464 ProcessImageName: firefox.exe, Pid: 4736, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09444, EstimatedImpact: 56% 2026-05-14T17:09:56.464 ProcessImageName: SDXHelper.exe, Pid: 7264, TotalTime: 388, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 30% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 3692, TotalTime: 345, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\s641031CheckReachable56C9E93A-CEA2-41E8-B61A-EBF7896AE0F4, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: FileCoAuth.exe, Pid: 3012, TotalTime: 276, Count: 16, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-14T17:09:56.464 ProcessImageName: firefox.exe, Pid: 9536, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09564, EstimatedImpact: 10% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 8912, TotalTime: 233, Count: 3, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4D02.tmp, EstimatedImpact: 1% 2026-05-14T17:09:56.464 ProcessImageName: TabTip.exe, Pid: 1376, TotalTime: 232, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 2584, TotalTime: 230, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: FileSyncConfig.exe, Pid: 12332, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 69% 2026-05-14T17:09:56.464 ProcessImageName: RuntimeBroker.exe, Pid: 8888, TotalTime: 187, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: AdobeCollabSync.exe, Pid: 11208, TotalTime: 180, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-14.log, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: FileCoAuth.exe, Pid: 10408, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-14T17:09:56.464 ProcessImageName: WhatsApp.Root.exe, Pid: 8604, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\applog.txt, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: ngentask.exe, Pid: 9592, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 9% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 2204, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: ngentask.exe, Pid: 5548, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 968, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: backgroundTaskHost.exe, Pid: 10580, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1778676020->(UTF-16LE), EstimatedImpact: 12% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 1692, TotalTime: 122, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 3% 2026-05-14T17:09:56.464 ProcessImageName: OfficeClickToRun.exe, Pid: 4112, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 916, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: PhoneExperienceHost.exe, Pid: 10208, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: backgroundTaskHost.exe, Pid: 4616, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 22% 2026-05-14T17:09:56.464 ProcessImageName: Acrobat.exe, Pid: 8236, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 4% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 6184, TotalTime: 91, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 3884, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-14T17:09:56.464 ProcessImageName: SecurityHealthHost.exe, Pid: 12820, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 8% 2026-05-14T17:09:56.464 ProcessImageName: firefox.exe, Pid: 1992, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 3% 2026-05-14T17:09:56.464 ProcessImageName: ngentask.exe, Pid: 8864, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 33% 2026-05-14T17:09:56.464 ProcessImageName: ngentask.exe, Pid: 10180, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 36% 2026-05-14T17:09:56.464 ProcessImageName: SDXHelper.exe, Pid: 6892, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-14T17:09:56.464 ProcessImageName: Acrobat.exe, Pid: 6496, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 7% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 2760, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: taskhostw.exe, Pid: 12784, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-14T17:09:56.464 ProcessImageName: SDXHelper.exe, Pid: 2892, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\OutlookCapabilities.json, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: AcroCEF.exe, Pid: 9988, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 40% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 5636, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: runonce.exe, Pid: 11720, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 1% 2026-05-14T17:09:56.464 ProcessImageName: OfficeClickToRun.exe, Pid: 4132, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: OneDriveSetup.exe, Pid: 12772, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncConfig.exe, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: dasHost.exe, Pid: 5308, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: AggregatorHost.exe, Pid: 5396, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 12964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322.log, EstimatedImpact: 2% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 8472, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1338.log, EstimatedImpact: 2% 2026-05-14T17:09:56.464 ProcessImageName: backgroundTaskHost.exe, Pid: 9788, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 28% 2026-05-14T17:09:56.464 ProcessImageName: backgroundTaskHost.exe, Pid: 10812, TotalTime: 30, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1778676022, EstimatedImpact: 6% 2026-05-14T17:09:56.464 ProcessImageName: dllhost.exe, Pid: 5908, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: OpenWith.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 5% 2026-05-14T17:09:56.464 ProcessImageName: TeamViewer_Service.exe, Pid: 4488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: OfficeC2RClient.exe, Pid: 11112, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: StoreDesktopExtension.exe, Pid: 6080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 13% 2026-05-14T17:09:56.464 ProcessImageName: svchost.exe, Pid: 11664, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: brynhildr.exe, Pid: 3304, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-14T17:09:56.464 ProcessImageName: DismHost.exe, Pid: 11716, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-05-14T17:16:56.592 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T17:19:17.897 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #30791, FileId: 0x19000000013866, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFc_Disruption_ModularPolicyPublish new=1 old0 2026-05-14T17:31:02.418 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T17:31:02.433 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-14T17:31:02.433 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-14T17:31:02.433 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-14T17:31:02.449 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T17:31:02.449 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T17:31:02.449 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T17:31:02.449 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T17:31:02.449 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T17:31:02.449 MdCoreSvc is supported in this platform and OS 2026-05-14T17:31:02.920 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-14T17:31:02.920 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-14T17:31:02.920 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-14T17:32:01.594 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T17:47:06.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T18:02:11.590 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T18:17:16.595 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T18:32:21.596 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T18:47:26.591 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T18:54:40.320 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32142, FileId: 0xbc000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.320 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32141, FileId: 0xb9000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.320 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32143, FileId: 0x3c00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32144, FileId: 0xbd000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32145, FileId: 0x3d00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32146, FileId: 0xbe000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32147, FileId: 0x3e00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32148, FileId: 0xbf000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32149, FileId: 0x3f00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32150, FileId: 0x4000000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.336 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32151, FileId: 0xc0000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32152, FileId: 0x4100000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32155, FileId: 0xc2000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32156, FileId: 0xc3000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32154, FileId: 0x4200000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32153, FileId: 0xc1000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.353 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32157, FileId: 0x4300000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.368 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32158, FileId: 0x4400000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.368 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32159, FileId: 0xc4000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.368 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32160, FileId: 0x4500000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T18:54:40.368 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #32161, FileId: 0xc5000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T19:02:31.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T19:09:56.465 ProcessImageName: explorer.exe, Pid: 3672, TotalTime: 7579, Count: 174, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: AcroCEF.exe, Pid: 9460, TotalTime: 3709, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-14T19:09:56.465 ProcessImageName: AsPowerBar.exe, Pid: 12372, TotalTime: 2693, Count: 18, MaxTime: 1093, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-05-14T19:09:56.465 ProcessImageName: DeviceCensus.exe, Pid: 1332, TotalTime: 2607, Count: 6, MaxTime: 1281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 40% 2026-05-14T19:09:56.465 ProcessImageName: dllhost.exe, Pid: 6512, TotalTime: 2597, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: DipAwayMode.exe, Pid: 6480, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: firefox.exe, Pid: 1848, TotalTime: 2505, Count: 284, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa12724, EstimatedImpact: 73% 2026-05-14T19:09:56.465 ProcessImageName: MOM.exe, Pid: 3188, TotalTime: 1883, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-14T19:09:56.465 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10932, TotalTime: 1702, Count: 3, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 7% 2026-05-14T19:09:56.465 ProcessImageName: AISuite3.exe, Pid: 7280, TotalTime: 1430, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-14T19:09:56.465 ProcessImageName: websockify.exe, Pid: 10836, TotalTime: 833, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-14T19:09:56.465 ProcessImageName: WmiPrvSE.exe, Pid: 10684, TotalTime: 632, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-05-14T19:09:56.465 ProcessImageName: WmiPrvSE.exe, Pid: 6288, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\dxgmms2.sys, EstimatedImpact: 95% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 529, Count: 39, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: WmiPrvSE.exe, Pid: 6208, TotalTime: 465, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 21% 2026-05-14T19:09:56.465 ProcessImageName: TeamViewer.exe, Pid: 5780, TotalTime: 439, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-14T19:09:56.465 ProcessImageName: firefox.exe, Pid: 4736, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09444, EstimatedImpact: 56% 2026-05-14T19:09:56.465 ProcessImageName: SDXHelper.exe, Pid: 7264, TotalTime: 388, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 30% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 3692, TotalTime: 345, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\s641031CheckReachable56C9E93A-CEA2-41E8-B61A-EBF7896AE0F4, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: FileCoAuth.exe, Pid: 3012, TotalTime: 276, Count: 16, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 256, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 33% 2026-05-14T19:09:56.465 ProcessImageName: firefox.exe, Pid: 9536, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09564, EstimatedImpact: 10% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 8912, TotalTime: 233, Count: 3, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4D02.tmp, EstimatedImpact: 1% 2026-05-14T19:09:56.465 ProcessImageName: TabTip.exe, Pid: 1376, TotalTime: 232, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 2584, TotalTime: 230, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: FileCoAuth.exe, Pid: 10324, TotalTime: 226, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WINWORD.EXE, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: FileSyncConfig.exe, Pid: 12332, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 69% 2026-05-14T19:09:56.465 ProcessImageName: RuntimeBroker.exe, Pid: 8888, TotalTime: 187, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: AdobeCollabSync.exe, Pid: 11208, TotalTime: 180, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-14.log, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: FileCoAuth.exe, Pid: 10408, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-14T19:09:56.465 ProcessImageName: WhatsApp.Root.exe, Pid: 8604, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\applog.txt, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: ngentask.exe, Pid: 9592, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 9% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 2204, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: ngentask.exe, Pid: 5548, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 968, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: dasHost.exe, Pid: 5308, TotalTime: 136, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: backgroundTaskHost.exe, Pid: 10580, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1778676020->(UTF-16LE), EstimatedImpact: 12% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 1692, TotalTime: 122, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: OfficeClickToRun.exe, Pid: 4112, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 916, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: PhoneExperienceHost.exe, Pid: 10208, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: backgroundTaskHost.exe, Pid: 4616, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 22% 2026-05-14T19:09:56.465 ProcessImageName: Acrobat.exe, Pid: 8236, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 4% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 6184, TotalTime: 91, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 3884, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: SecurityHealthHost.exe, Pid: 12820, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 8% 2026-05-14T19:09:56.465 ProcessImageName: firefox.exe, Pid: 1992, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: ngentask.exe, Pid: 10180, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 36% 2026-05-14T19:09:56.465 ProcessImageName: ngentask.exe, Pid: 8864, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 33% 2026-05-14T19:09:56.465 ProcessImageName: GameBar.exe, Pid: 10016, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 4% 2026-05-14T19:09:56.465 ProcessImageName: SDXHelper.exe, Pid: 6892, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-14T19:09:56.465 ProcessImageName: Acrobat.exe, Pid: 6496, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 7% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 2760, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: taskhostw.exe, Pid: 12784, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-14T19:09:56.465 ProcessImageName: SDXHelper.exe, Pid: 2892, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\OutlookCapabilities.json, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: AggregatorHost.exe, Pid: 5396, TotalTime: 60, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: AcroCEF.exe, Pid: 9988, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 40% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 5636, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: runonce.exe, Pid: 11720, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 1% 2026-05-14T19:09:56.465 ProcessImageName: OfficeClickToRun.exe, Pid: 4132, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: OneDriveSetup.exe, Pid: 12772, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncConfig.exe, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: dllhost.exe, Pid: 5908, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 12964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322.log, EstimatedImpact: 2% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 8472, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1338.log, EstimatedImpact: 2% 2026-05-14T19:09:56.465 ProcessImageName: backgroundTaskHost.exe, Pid: 9788, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 28% 2026-05-14T19:09:56.465 ProcessImageName: backgroundTaskHost.exe, Pid: 10812, TotalTime: 30, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1778676022, EstimatedImpact: 6% 2026-05-14T19:09:56.465 ProcessImageName: OpenWith.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 5% 2026-05-14T19:09:56.465 ProcessImageName: TeamViewer_Service.exe, Pid: 4488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: OfficeC2RClient.exe, Pid: 11112, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: SDXHelper.exe, Pid: 7568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3, EstimatedImpact: 9% 2026-05-14T19:09:56.465 ProcessImageName: svchost.exe, Pid: 11664, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: StoreDesktopExtension.exe, Pid: 6080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 13% 2026-05-14T19:09:56.465 ProcessImageName: brynhildr.exe, Pid: 3304, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-14T19:09:56.465 ProcessImageName: DismHost.exe, Pid: 11716, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-05-14T19:17:36.593 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T19:32:41.588 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T19:47:46.599 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T20:02:51.600 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T20:17:56.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T20:33:01.598 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T20:48:06.506 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T20:49:04.922 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33340, FileId: 0x4c00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.922 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33339, FileId: 0x4b00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.922 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33341, FileId: 0xcc000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.922 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33342, FileId: 0x4e00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.938 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33343, FileId: 0xcd000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.938 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33344, FileId: 0x4f00000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.938 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33345, FileId: 0xce000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.938 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33346, FileId: 0x5000000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.960 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33350, FileId: 0x5200000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.969 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33351, FileId: 0xd4000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.969 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33347, FileId: 0x5100000003facb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T20:49:04.969 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33348, FileId: 0xcf000000008370, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T21:03:11.403 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T21:09:56.257 ProcessImageName: explorer.exe, Pid: 3672, TotalTime: 7579, Count: 174, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: AcroCEF.exe, Pid: 9460, TotalTime: 3709, Count: 168, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-14T21:09:56.257 ProcessImageName: AsPowerBar.exe, Pid: 12372, TotalTime: 2693, Count: 18, MaxTime: 1093, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-05-14T21:09:56.257 ProcessImageName: DeviceCensus.exe, Pid: 1332, TotalTime: 2607, Count: 6, MaxTime: 1281, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 40% 2026-05-14T21:09:56.257 ProcessImageName: dllhost.exe, Pid: 6512, TotalTime: 2597, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\LGS5PK93DZ_154, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: DipAwayMode.exe, Pid: 6480, TotalTime: 2570, Count: 16, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 1848, TotalTime: 2505, Count: 284, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa12724, EstimatedImpact: 73% 2026-05-14T21:09:56.257 ProcessImageName: MOM.exe, Pid: 3188, TotalTime: 1883, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-14T21:09:56.257 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10932, TotalTime: 1702, Count: 3, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 7% 2026-05-14T21:09:56.257 ProcessImageName: AISuite3.exe, Pid: 7280, TotalTime: 1430, Count: 22, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-14T21:09:56.257 ProcessImageName: websockify.exe, Pid: 10836, TotalTime: 833, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 60% 2026-05-14T21:09:56.257 ProcessImageName: WmiPrvSE.exe, Pid: 10684, TotalTime: 632, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 589, Count: 45, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: WmiPrvSE.exe, Pid: 6288, TotalTime: 587, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\dxgmms2.sys, EstimatedImpact: 95% 2026-05-14T21:09:56.257 ProcessImageName: WmiPrvSE.exe, Pid: 6208, TotalTime: 465, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 21% 2026-05-14T21:09:56.257 ProcessImageName: TeamViewer.exe, Pid: 5780, TotalTime: 439, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 4736, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09444, EstimatedImpact: 56% 2026-05-14T21:09:56.257 ProcessImageName: SDXHelper.exe, Pid: 7264, TotalTime: 388, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 30% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 3692, TotalTime: 345, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\s641031CheckReachable56C9E93A-CEA2-41E8-B61A-EBF7896AE0F4, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: FileCoAuth.exe, Pid: 3012, TotalTime: 276, Count: 16, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 256, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 33% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 9536, TotalTime: 240, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09564, EstimatedImpact: 10% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 8912, TotalTime: 233, Count: 3, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4D02.tmp, EstimatedImpact: 1% 2026-05-14T21:09:56.257 ProcessImageName: TabTip.exe, Pid: 1376, TotalTime: 232, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 2584, TotalTime: 230, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: FileCoAuth.exe, Pid: 10324, TotalTime: 226, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WINWORD.EXE, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: FileSyncConfig.exe, Pid: 12332, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDriveTelemetryStable.dll, EstimatedImpact: 69% 2026-05-14T21:09:56.257 ProcessImageName: RuntimeBroker.exe, Pid: 8888, TotalTime: 187, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: AdobeCollabSync.exe, Pid: 11208, TotalTime: 180, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-14.log, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: FileCoAuth.exe, Pid: 10408, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-14T21:09:56.257 ProcessImageName: WhatsApp.Root.exe, Pid: 8604, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\applog.txt, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: ngentask.exe, Pid: 9592, TotalTime: 165, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 9% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 2204, TotalTime: 154, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: ngentask.exe, Pid: 5548, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 9% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 968, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: dasHost.exe, Pid: 5308, TotalTime: 136, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: backgroundTaskHost.exe, Pid: 10580, TotalTime: 135, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000163\1778676020->(UTF-16LE), EstimatedImpact: 12% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 1692, TotalTime: 122, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: OfficeClickToRun.exe, Pid: 4112, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 916, TotalTime: 109, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: PhoneExperienceHost.exe, Pid: 10208, TotalTime: 105, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\577269e0119effdc06dfd5edb2c0c0d95c897821.tbres, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: backgroundTaskHost.exe, Pid: 4616, TotalTime: 105, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 22% 2026-05-14T21:09:56.257 ProcessImageName: Acrobat.exe, Pid: 8236, TotalTime: 105, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 4% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 6184, TotalTime: 91, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 3884, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_EAF5D55D93603A879FA973006301F24F, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: SecurityHealthHost.exe, Pid: 12820, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 8% 2026-05-14T21:09:56.257 ProcessImageName: AggregatorHost.exe, Pid: 5396, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 9740, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13288, EstimatedImpact: 11% 2026-05-14T21:09:56.257 ProcessImageName: firefox.exe, Pid: 1992, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: ngentask.exe, Pid: 10180, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 36% 2026-05-14T21:09:56.257 ProcessImageName: ngentask.exe, Pid: 8864, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 33% 2026-05-14T21:09:56.257 ProcessImageName: SDXHelper.exe, Pid: 6892, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-14T21:09:56.257 ProcessImageName: GameBar.exe, Pid: 10016, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 4% 2026-05-14T21:09:56.257 ProcessImageName: Acrobat.exe, Pid: 6496, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 7% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 2760, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: taskhostw.exe, Pid: 12784, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-14T21:09:56.257 ProcessImageName: SDXHelper.exe, Pid: 2892, TotalTime: 60, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\OutlookCapabilities.json, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: AcroCEF.exe, Pid: 9988, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 40% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 5636, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: runonce.exe, Pid: 11720, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 1% 2026-05-14T21:09:56.257 ProcessImageName: OfficeClickToRun.exe, Pid: 4132, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: OneDriveSetup.exe, Pid: 12772, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileSyncConfig.exe, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: dllhost.exe, Pid: 5908, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 12964, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322.log, EstimatedImpact: 2% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 8472, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1338.log, EstimatedImpact: 2% 2026-05-14T21:09:56.257 ProcessImageName: backgroundTaskHost.exe, Pid: 9788, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 28% 2026-05-14T21:09:56.257 ProcessImageName: backgroundTaskHost.exe, Pid: 10812, TotalTime: 30, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1778676022, EstimatedImpact: 6% 2026-05-14T21:09:56.257 ProcessImageName: OpenWith.exe, Pid: 6684, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 5% 2026-05-14T21:09:56.257 ProcessImageName: TeamViewer_Service.exe, Pid: 4488, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: OfficeC2RClient.exe, Pid: 11112, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260514-1322a.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: SDXHelper.exe, Pid: 7568, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3, EstimatedImpact: 9% 2026-05-14T21:09:56.257 ProcessImageName: StoreDesktopExtension.exe, Pid: 6080, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 13% 2026-05-14T21:09:56.257 ProcessImageName: svchost.exe, Pid: 11664, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: brynhildr.exe, Pid: 3304, TotalTime: 0, Count: 4, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-14T21:09:56.257 ProcessImageName: DismHost.exe, Pid: 11716, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-05-14T21:18:16.349 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T21:33:21.297 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T21:48:26.260 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T22:03:31.236 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T22:18:36.210 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T22:33:41.187 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T22:42:06.115 Engine:Process 8008 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-14T22:47:21.438 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #34515, FileId: 0x6500000003fb44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T22:48:03.128 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-14T22:48:46.180 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T22:52:31.134 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #34737, FileId: 0x6900000003fb44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T22:53:59.124 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #35029, FileId: 0xca000000003b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T22:59:21.649 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #35473, FileId: 0x300000000352c2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-14T23:03:51.167 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-14T23:07:20.450 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\ADEC04CE-5310-4FAC-8958-4DD368466CAC1f18.1dce3f669219f50 2026-05-14T23:07:20.560 Verifying engine and signature files (source: 0) ... 2026-05-14T23:07:20.560 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpengine.dll] due to PPL. 2026-05-14T23:07:20.560 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasbase.vdm]. File not in cache (0x1) 2026-05-14T23:07:21.317 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasbase.vdm] 2026-05-14T23:07:21.318 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-14T23:07:21.341 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasdlta.vdm] 2026-05-14T23:07:21.341 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavbase.vdm]. File not in cache (0x1) 2026-05-14T23:07:21.693 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavbase.vdm] 2026-05-14T23:07:21.693 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-14T23:07:21.716 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavdlta.vdm] 2026-05-14T23:07:21.876 [Engine] IsHybridMode: 0 2026-05-14T23:07:21.877 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-14T23:07:21.883 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-12AD1E520842328F7E409618A2650988EDE0CD68.bin): 0x00000002 2026-05-14T23:07:21.886 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-12AD1E520842328F7E409618A2650988EDE0CD68.bin) 2026-05-14T23:07:21.886 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-14T23:07:21.886 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-14T23:07:21.886 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-14T23:07:21.886 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-14T23:07:32.415 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-14T23:07:32.416 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFc_Disruption_ModularPolicyPublish new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-14T23:07:32.444 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFCA5EF5810, lRefCount: 5, hr=0 2026-05-14T23:07:32.445 [Engine] New active engine 00007FFC410C5810 replacing engine 00007FFCA5EF5810. Number of active engines: 2 2026-05-14T23:07:32.459 EngineInit:Global ASOC is enabled 2026-05-14T23:07:32.459 EngineInit:ASOO is enabled for developer volumes 2026-05-14T23:07:32.527 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-14T23:07:32.527 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.528 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.529 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.529 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-14T23:07:32.532 MpWriteUupSignatureVersion 1.449.619.0, hr = 0 2026-05-14T23:07:32.533 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-14T23:07:32.552 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-14T23:07:32.554 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-14T23:07:32.554 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-14T23:07:32.554 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-14T23:07:32.554 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-14T23:07:32.576 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-14T23:07:32.576 [Plugin] Initializing RTP plugin state... 2026-05-14T23:07:32.577 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-14T23:07:32.577 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎14‎-‎2026 13:09:56 Last Perf:‎05‎-‎14‎-‎2026 13:09:56 First RTP Scan:‎05‎-‎14‎-‎2026 13:09:56 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:4713 Misses:28116 BM Queue:0,253,0 Proc:0,169,0 File:0,157,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:35656 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:318896066 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:30813 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:112990 TotalHits:438027 InstanceCacheInserts:3528 InstanceCacheUpdates:0 InstanceCacheDeletes:711 InstanceCacheHits:851 InstanceCacheMisses:44357 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (4735/1221) Success: 1221, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-14T23:07:32.577 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6} 2026-05-14T23:07:32.578 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A88F2854-21C3-45B7-ABE0-E637CBB1CBD3} removed 2026-05-14T23:07:32.578 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DB747156-B9D7-4549-8152-3EA5FB436F1B}\mpasbase.vdm in use, hr=0x80070020 2026-05-14T23:07:32.580 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.580 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.580 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.580 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.580 MdCoreSvc is supported in this platform and OS 2026-05-14T23:07:32.581 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-14-2026 23:07:32 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-14-2026 23:07:32 2026-05-14T23:07:32.586 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-14T23:07:32.586 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-14T23:07:32.589 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-14T23:07:32.590 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-14T23:07:32.590 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-14T23:07:32.590 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.590 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-14T23:07:32.590 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.590 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-14T23:07:32.591 MdCoreSvc is supported in this platform and OS Signature updated on 05-14-2026 23:07:32 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.619.0 AV Signature Version: 1.449.619.0 ************************************************************ 2026-05-14T23:07:32.593 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-14T23:07:32.594 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\ADEC04CE-5310-4FAC-8958-4DD368466CAC1f18.1dce3f669219f50 2026-05-14T23:07:32.610 Process scan (postsignatureupdatescan) started. 2026-05-14T23:07:32.689 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-15-2026 12:54:35 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/15/2026 12:54:35.910519400 UTC (14625 ms since boot) 2026-05-15T12:54:35.926 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-15T12:54:35.931 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-15T12:54:35.931 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-15T12:54:35.994 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260515-125435-00000003-fffffffeffffffff.bin ... 2026-05-15T12:54:36.081 [WPP] Trace session started - MpWppTracing-20260515-125435-00000003-fffffffeffffffff.bin 2026-05-15T12:54:36.090 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-15T12:54:36.091 [RbM] Rollback manager succesfully initialized. 2026-05-15T12:54:36.091 [RbM] Rollback manager EnableRollbackManager called. 2026-05-15T12:54:36.101 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-15T12:54:36.101 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-15T12:54:36.101 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-15T12:54:36.101 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-15T12:54:36.101 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-15T12:54:36.106 MdCoreSvc is supported in this platform and OS 2026-05-15T12:54:36.106 MdCoreSvc is supported in this platform and OS 2026-05-15T12:54:36.106 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-15T12:54:36.106 [PlatUpd] Starting MdCoreSvc service 2026-05-15T12:54:36.151 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-15T12:54:40.008 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-15T12:54:40.008 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-15T12:54:40.008 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-15T12:54:40.008 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-15T12:54:40.008 [PlatUpd] CSP platform update started 2026-05-15T12:54:40.008 [PlatUpd] Defender MDM CSP platform update not required 2026-05-15T12:54:40.008 [PlatUpd] WMI/PS provider platform update started 2026-05-15T12:54:40.008 [PlatUpd] WMI/PS provider platform update not required 2026-05-15T12:54:40.008 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-15T12:54:40.024 MdCoreSvc is supported in this platform and OS 2026-05-15T12:54:40.024 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-15T12:54:40.024 [PlatUpd] Starting MdCoreSvc service 2026-05-15T12:54:40.024 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-15T12:54:40.024 [TS] Troubleshooting mode is not available! 2026-05-15T12:54:40.024 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-15T12:54:40.024 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-15T12:54:40.055 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-15T12:54:40.055 [Service] Enabling AutoLoggers ... 2026-05-15T12:54:40.055 [Service] Enabling AMSI registration ... 2026-05-15T12:54:40.055 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-15T12:54:40.070 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43121 Number of invalid entries is 0 Number of inserts issued is 1584326 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6510 Number of lookups is 108159859 Number of lookup misses is 5194815 Number of fast lookup misses is 55117390 Number of false fast lookups is 5194810 Number of invalidations is 734689 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-15T12:54:40.070 Verifying license file... 2026-05-15T12:54:40.070 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-15T12:54:40.086 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-15T12:54:40.086 Loaded module#0 MpComServer. 2026-05-15T12:54:40.086 Loaded module#1 StartupPolicies. 2026-05-15T12:54:40.086 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-15T12:54:40.086 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-15T12:54:40.086 COM server initialized successfully. 2026-05-15T12:54:40.102 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-15T12:54:40.117 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-15T12:54:40.117 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-15T12:54:40.133 [RTP] [RTP] FilterCommunicator object 0x00000128F0099970 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-15T12:54:40.133 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-15T12:54:40.133 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-15T12:54:40.133 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-15T12:54:40.133 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-15T12:54:40.133 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-15T12:54:40.133 [RTP] [RTP] FilterCommunicator object 0x00000128F0099B80 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-15T12:54:40.133 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-15T12:54:40.133 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-15T12:54:40.133 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-15T12:54:40.133 [RTP] [RTP] StartCommunication 0x00000128F0099970 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-15T12:54:40.133 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-15T12:54:40.133 [init][RTP] RTPPlugin initialization completed 2026-05-15T12:54:40.133 OS boot count = 2 2026-05-15T12:54:40.133 OS Install = 0 2026-05-15T12:54:40.149 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-15T12:54:40.149 [KSL] Entering CKSLEngine::Initialize. 2026-05-15T12:54:40.149 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-15T12:54:40.149 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-15T12:54:40.149 [KSL] MpInstallKslD: hr=0x1 2026-05-15T12:54:40.149 [KSL] MpRegisterKslD: hr=0 2026-05-15T12:54:40.164 [KSL] MpStartKslD: hr=0 2026-05-15T12:54:40.164 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-15T12:54:40.164 Loading engine... 2026-05-15T12:54:40.180 Verifying engine and signature files (source: 1) ... 2026-05-15T12:54:40.180 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpengine.dll] due to PPL. 2026-05-15T12:54:40.180 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasbase.vdm] (file in cache) 2026-05-15T12:54:40.180 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasdlta.vdm] (file in cache) 2026-05-15T12:54:40.180 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavbase.vdm] (file in cache) 2026-05-15T12:54:40.180 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpavdlta.vdm] (file in cache) 2026-05-15T12:54:40.211 [Engine] IsHybridMode: 0 2026-05-15T12:54:40.211 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-15T12:54:40.242 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-12AD1E520842328F7E409618A2650988EDE0CD68.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-15T12:54:44.477 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-15T12:54:44.477 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFc_Disruption_ModularPolicyPublish new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-15T12:54:44.492 [Engine] New active engine 00007FFC4D145810 (no old engine). Number of active engines: 1 2026-05-15T12:54:44.492 EngineInit:Global ASOC is enabled 2026-05-15T12:54:44.492 EngineInit:ASOO is enabled for developer volumes 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:54:44.570 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\deec6b0a3a89109430d3ac1ac2781dfa401f58c6 Dynamic Signature Compilation Timestamp:04-15-2026 11:57:08 Persistence Type:Duration Time remaining:150196224 2026-05-15T12:54:44.586 MpWriteUupSignatureVersion 1.449.619.0, hr = 0 2026-05-15T12:54:44.586 [SigStatUpd] CSignatureStatus: back to good 2026-05-15T12:54:44.586 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-15T12:54:44.602 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-15T12:54:44.602 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-15T12:54:44.602 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-15T12:54:44.602 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-15T12:54:44.602 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-15T12:54:44.633 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-15T12:54:44.633 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2177 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12386 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2467 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-15T12:54:44.633 [Plugin] Initializing RTP plugin state... 2026-05-15T12:54:44.633 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-15T12:54:44.633 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6} 2026-05-15T12:54:44.633 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:54:44.633 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:54:44.633 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:54:44.633 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-15T12:54:44.633 MdCoreSvc is supported in this platform and OS 2026-05-15T12:54:44.633 Engine loaded! 2026-05-15T12:54:44.633 [DLP] Create FeatureControlState instance 2026-05-15T12:54:44.633 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-15T12:54:44.633 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-15T12:54:44.633 RegisterSModeChangeListener: hr = 0x1 2026-05-15T12:54:44.633 RegisterHybridModeChangeListener: hr = 0 2026-05-15T12:54:44.649 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-15T12:54:44.649 [SigReleaseHb] Initialized with Stage 0 2026-05-15T12:54:44.649 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-15T12:54:44.649 [SCC][CID=23375_5404] Initializing ... 2026-05-15T12:54:44.649 [SCC][CID=23375_5404] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-15T12:54:44.664 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-15T12:54:44.664 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-15T12:54:44.664 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-15T12:54:44.664 [NRI] Stopping NIS service ... 2026-05-15T12:54:44.664 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-15T12:54:44.664 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.619.0 AV Signature Version: 1.449.619.0 ************************************************************ 2026-05-15T12:54:44.664 Resource usage Monitoring is enabled 2026-05-15T12:54:44.664 Job Notification: New process added to job (4712) 2026-05-15T12:54:44.664 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-15T12:54:44.727 Job Notification: New process added to job (7460) 2026-05-15T12:54:44.727 Job Notification: New process added to job (7468) 2026-05-15T12:54:44.742 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7460] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7468]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-15T12:54:44.742 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-15T12:54:44.742 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-15T12:54:44.758 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-15T12:54:44.758 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-15T12:54:44.758 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-15T12:54:44.758 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-15T12:54:44.758 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-15T12:54:44.758 [RTP] Generating the base plugin configuration ... 2026-05-15T12:54:44.758 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-15T12:54:44.758 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T12:54:44.758 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-15T12:54:44.758 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-15T12:54:44.758 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T12:54:44.758 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-15T12:54:44.758 [RTP] [RTP] StartCommunication 0x00000128F0099B80 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-15T12:54:44.758 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-15T12:54:44.774 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp 2026-05-15T12:54:44.852 Job Notification: Process exited from job (7460) 2026-05-15T12:54:44.852 Job Notification: Process exited from job (7468) 2026-05-15T12:54:44.852 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-15T12:54:45.086 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-15T12:54:45.086 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-15T12:54:45.086 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-15T12:54:45.117 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T12:54:47.695 [RTP] Duplicating the current plugin configuration object... 2026-05-15T12:54:47.695 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T12:54:47.695 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-15T12:54:47.695 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-15T12:54:47.695 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-15T12:54:59.305 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7BB0651D-D740-48D4-BA4A-49FA9140FD2B1f70.1dce46a084ac81c 2026-05-15T12:54:59.414 Verifying engine and signature files (source: 0) ... 2026-05-15T12:54:59.414 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpengine.dll] due to PPL. 2026-05-15T12:54:59.414 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasbase.vdm]. File not in cache (0x1) 2026-05-15T12:55:00.164 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasbase.vdm] 2026-05-15T12:55:00.164 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-15T12:55:00.180 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasdlta.vdm] 2026-05-15T12:55:00.180 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavbase.vdm]. File not in cache (0x1) 2026-05-15T12:55:00.524 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavbase.vdm] 2026-05-15T12:55:00.524 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-15T12:55:00.555 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavdlta.vdm] 2026-05-15T12:55:00.711 [Engine] IsHybridMode: 0 2026-05-15T12:55:00.711 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-15T12:55:00.711 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-607B832ACECC74746205607F6294A3064FC1CA08.bin): 0x00000002 2026-05-15T12:55:00.711 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-607B832ACECC74746205607F6294A3064FC1CA08.bin) 2026-05-15T12:55:00.711 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-15T12:55:00.711 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-15T12:55:00.711 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-15T12:55:00.711 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-15T12:55:10.711 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-15T12:55:10.711 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-15T12:55:10.727 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFC4D145810, lRefCount: 5, hr=0 2026-05-15T12:55:10.727 [Engine] New active engine 00007FFC494E5810 replacing engine 00007FFC4D145810. Number of active engines: 2 2026-05-15T12:55:10.727 EngineInit:Global ASOC is enabled 2026-05-15T12:55:10.727 EngineInit:ASOO is enabled for developer volumes 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-15T12:55:10.789 MpWriteUupSignatureVersion 1.449.629.0, hr = 0 2026-05-15T12:55:10.789 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-15T12:55:10.805 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-15T12:55:10.805 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-15T12:55:10.805 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-15T12:55:10.805 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-15T12:55:10.805 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-15T12:55:10.820 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-15T12:55:10.820 [Plugin] Initializing RTP plugin state... 2026-05-15T12:55:10.820 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-15T12:55:10.820 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎15‎-‎2026 14:54:44 Last Perf:‎05‎-‎15‎-‎2026 14:54:44 First RTP Scan:‎05‎-‎15‎-‎2026 14:54:44 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:233 Misses:104 BM Queue:0,6,0 Proc:0,6,0 File:0,2,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:348 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:379788 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2248 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12881 TotalHits:555 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:15 InstanceCacheHits:0 InstanceCacheMisses:2563 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:8ms (62/7) Success: 7, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-15T12:55:10.820 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77} 2026-05-15T12:55:10.820 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6}\mpasbase.vdm in use, hr=0x80070020 2026-05-15T12:55:10.820 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-15T12:55:10.820 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0F24CADE-6B84-4E44-B32E-8990331C7429} removed 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-15-2026 12:55:10 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-15-2026 12:55:10 2026-05-15T12:55:10.836 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-15T12:55:10.836 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-15T12:55:10.836 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T12:55:10.836 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-15T12:55:10.836 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-15T12:55:10.836 MdCoreSvc is supported in this platform and OS Signature updated on 05-15-2026 12:55:10 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.629.0 AV Signature Version: 1.449.629.0 ************************************************************ 2026-05-15T12:55:10.836 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-15T12:55:10.836 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\7BB0651D-D740-48D4-BA4A-49FA9140FD2B1f70.1dce46a084ac81c 2026-05-15T12:55:10.914 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-15T12:55:10.914 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-15T12:55:11.211 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-15T12:55:11.211 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-15T12:55:11.211 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-15T12:55:11.211 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-15T12:55:11.211 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-15T12:55:11.211 [Engine] Engine 00007FFC4D145810 no longer in use. Number of active engines: 1 2026-05-15T12:55:11.211 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T12:55:11.211 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-15T12:55:11.289 ProcessImageName: taskhostw.exe, Pid: 7268, TotalTime: 921, Count: 2, MaxTime: 875, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-05-15T12:55:11.289 ProcessImageName: brynhildr.exe, Pid: 4196, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-15T12:55:11.305 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-15T12:55:11.305 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-15T12:55:11.305 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-15T12:55:11.320 [Engine] RSIG_UNLOADENGINE, 00007FFC4D145810, err=0x0 2026-05-15T12:55:11.336 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0E0F1DAA-F911-4C64-AB9E-5B0E6F05F7C6} removed 2026-05-15T12:55:40.070 Process scan (postsignatureupdatescan) started. 2026-05-15T12:55:40.570 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-15T12:55:40.570 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-15T12:55:43.149 [RTP] Duplicating the current plugin configuration object... 2026-05-15T12:55:43.149 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T12:55:43.149 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-15T12:55:43.149 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-15T12:55:43.149 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-15T12:55:55.102 Process scan (postsignatureupdatescan) completed. 2026-05-15T12:56:39.102 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T12:56:39.102 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-15T12:56:39.102 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T12:59:44.649 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T13:00:10.774 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-15T13:04:34.352 [AutoPurge] Verification Routine tasks have started. 2026-05-15T13:04:34.367 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-15T13:04:34.399 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-15T13:04:34.399 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-15T13:04:34.399 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-15T13:04:34.399 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-15T13:04:34.399 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-15T13:04:34.399 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-15T13:04:34.399 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:F97A7D2B-6762-495A-99EF-718BA315A099, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-15T13:04:34.399 Scheduled scan with Id F97A7D2B-6762-495A-99EF-718BA315A099 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-15T13:04:34.399 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-15T13:04:34.399 [SFC] System file cache build is not needed (already completed) 2026-05-15T13:04:34.414 [AutoPurge] Cleanup Routine tasks have started. 2026-05-15T13:04:34.430 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-15T13:04:34.430 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-15T13:04:34.430 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-15-2026 13:04:34 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-15-2026 13:04:34 2026-05-15T13:04:34.445 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-15T13:04:34.445 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-15T13:04:34.445 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-15T13:04:34.445 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-15T13:04:34.445 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-15T13:04:34.445 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-15T13:04:34.586 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-15T13:04:34.586 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-15T13:04:34.617 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-15T13:04:34.633 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-15T13:04:34.633 [AutoPurge] Verification Routine tasks have ended. 2026-05-15T13:04:35.633 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #1845, FileId: 0x5500000000c611, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:04:36.399 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T13:04:36.399 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-15T13:04:36.414 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T13:04:44.649 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-15T13:04:44.649 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-15T13:04:44.664 Job Notification: New process added to job (4708) 2026-05-15T13:04:44.664 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-15T13:04:44.664 Aggressive catchup quick scan threshold: 861018421772 / 25920000000000 2026-05-15T13:04:44.680 Job Notification: New process added to job (4756) 2026-05-15T13:04:44.680 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:4708] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4756]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-15T13:04:44.742 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 43121019(ms) from now at 03:03 (01:03 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-15T13:04:44.789 Job Notification: New process added to job (2256) 2026-05-15T13:04:44.789 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-15T13:04:44.789 Job Notification: New process added to job (2584) 2026-05-15T13:04:44.805 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:2256] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2584]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-15T13:04:45.008 Job Notification: New process added to job (2136) 2026-05-15T13:04:45.024 Task(GetDeviceTicket -AccessKey 6E11F305-9E8E-6F78-716A-95159AC1B29A ) launched as network service 2026-05-15T13:04:45.055 Job Notification: Process exited from job (2136) 2026-05-15T13:04:45.195 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-15T13:04:45.211 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-15T13:04:45.211 [RTP] Duplicating the current plugin configuration object... 2026-05-15T13:04:45.211 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T13:04:45.211 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-15T13:04:45.211 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T13:04:45.211 [RTP] No config change detected. Not updating plugin configuration. 2026-05-15T13:04:45.211 [RTP] No config changes found. No configuration switch. 2026-05-15T13:04:45.211 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-15T13:04:45.211 [RTP] Duplicating the current plugin configuration object... 2026-05-15T13:04:45.211 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T13:04:45.211 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-15T13:04:45.211 [RTP] No config change detected. Not updating plugin configuration. 2026-05-15T13:04:45.211 [RTP] No config changes found. No configuration switch. 2026-05-15T13:04:45.211 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-15T13:04:45.211 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-15T13:04:45.211 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:45.211 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-15T13:04:45.211 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-15T13:04:45.211 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-15T13:04:45.211 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-15T13:04:45.211 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-15T13:04:45.211 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-15T13:04:45.227 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:45.227 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:45.227 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:45.289 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-15T13:04:45.289 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T13:04:45.289 [Cloud] Queued cloud request. 2026-05-15T13:04:45.289 [Cloud] Dequeued cloud request. 2026-05-15T13:04:45.289 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T13:04:45.477 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-15T13:04:45.477 [Cloud] End of cloud request. 2026-05-15T13:04:45.789 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T13:04:47.774 [RTP] Duplicating the current plugin configuration object... 2026-05-15T13:04:47.774 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T13:04:47.774 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-15T13:04:47.774 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-15T13:04:47.774 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-15T13:04:49.649 Job Notification: Process exited from job (2256) 2026-05-15T13:04:49.649 Job Notification: Process exited from job (2584) 2026-05-15T13:04:49.727 Job Notification: Process exited from job (4708) 2026-05-15T13:04:49.727 Job Notification: Process exited from job (4756) 2026-05-15T13:05:07.570 Engine:Triggered AR EMS scan 2026-05-15T13:05:07.570 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.586 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 1032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 1192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 1220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.602 Engine:EMS scan for process: svchost pid: 1376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.617 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.617 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.617 Engine:EMS scan for process: svchost pid: 1484, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.617 Engine:EMS scan for process: svchost pid: 1540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.617 Engine:EMS scan for process: svchost pid: 1572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 1624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 1780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 1960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 2060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.633 Engine:EMS scan for process: svchost pid: 2108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.649 Engine:EMS scan for process: svchost pid: 2636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 2676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 3016, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 2348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 2908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.664 Engine:EMS scan for process: svchost pid: 3116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.680 Engine:EMS scan for process: svchost pid: 3608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.680 Engine:EMS scan for process: svchost pid: 3604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.680 Engine:EMS scan for process: svchost pid: 3720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.680 Engine:EMS scan for process: svchost pid: 3744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.695 Engine:EMS scan for process: svchost pid: 3752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.711 Engine:EMS scan for process: svchost pid: 3828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.711 Engine:EMS scan for process: svchost pid: 2992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.711 Engine:EMS scan for process: svchost pid: 3820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.711 Engine:EMS scan for process: svchost pid: 4204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.711 Engine:EMS scan for process: svchost pid: 4236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.727 Engine:EMS scan for process: svchost pid: 4268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.727 Engine:EMS scan for process: svchost pid: 4412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.727 Engine:EMS scan for process: svchost pid: 4500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.742 Engine:EMS scan for process: svchost pid: 4528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.742 Engine:EMS scan for process: svchost pid: 4656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.742 Engine:EMS scan for process: svchost pid: 5164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.742 Engine:EMS scan for process: svchost pid: 5952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.742 Engine:EMS scan for process: dllhost pid: 6096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 6176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 6852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 6868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 6936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 3192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.758 Engine:EMS scan for process: svchost pid: 7284, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.774 Engine:EMS scan for process: svchost pid: 7848, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.774 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.774 Engine:EMS scan for process: svchost pid: 8080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.774 Engine:EMS scan for process: svchost pid: 3340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.774 Engine:EMS scan for process: svchost pid: 4704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.789 Engine:EMS scan for process: svchost pid: 3220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.789 Engine:EMS scan for process: svchost pid: 7752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.789 Engine:EMS scan for process: svchost pid: 7396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.789 Engine:EMS scan for process: svchost pid: 7456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:05:07.789 Engine:EMS scan for process: svchost pid: 5936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-15T13:09:14.289 QuickScan:ScanID:F97A7D2B-6762-495A-99EF-718BA315A099: Quick scan finished with error 0 2026-05-15T13:09:14.789 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-15T13:09:14.789 [RTP] Duplicating the current plugin configuration object... 2026-05-15T13:09:14.789 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T13:09:14.789 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-15T13:09:14.789 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-15T13:09:14.789 [RTP] No config change detected. Not updating plugin configuration. 2026-05-15T13:09:14.789 [RTP] No config changes found. No configuration switch. 2026-05-15T13:09:14.789 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-15T13:09:16.289 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T13:09:16.289 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-15T13:09:16.289 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-15T13:10:46.189 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #2551, FileId: 0x5430000000002df, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:10:56.736 [RTP] 8 newly mounted volumes accumulated, forcing a config update ... 2026-05-15T13:10:56.736 [RTP] Duplicating the current plugin configuration object... 2026-05-15T13:10:56.736 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-15T13:10:56.736 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-15T13:10:56.736 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-15T13:10:56.737 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-15T13:10:56.739 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-15T13:11:19.835 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5413, FileId: 0x6300000003fb32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:11:44.810 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-15T13:11:46.670 [RTP] [Mini-filter] OpenWithoutRead notification (4667, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-15T13:12:34.886 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\Prefetch\SETHC.EXE-1E0D0DA0.pf. Process: \Device\HarddiskVolume3\Windows\System32\sethc.exe, Status: 0xc000004b, State: 0, ScanRequest #14633, FileId: 0x12a00000000b014, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:14:49.663 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T13:15:49.314 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15528, FileId: 0xf3000000004a42, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:18:31.249 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16888, FileId: 0x90000000004ed1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.620 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEB146B96E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17419, FileId: 0x4400000000f119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.635 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB1BCE092B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17425, FileId: 0x4500000000f119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.635 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj08B3E8980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17434, FileId: 0x4e00000000f114, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.720 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0942FC98B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17449, FileId: 0x5100000000f114, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.800 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4CE57C9C4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17459, FileId: 0x8b00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.804 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7D65C594E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17455, FileId: 0x5200000000f114, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.834 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8A5A7934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17460, FileId: 0x8c00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.834 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD917D59E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17461, FileId: 0x5500000000f114, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:48.881 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj50FBD3966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17465, FileId: 0x4700000000ed40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.013 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB2C14D969. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17477, FileId: 0x9700000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.029 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8AF088992. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17478, FileId: 0x210000000102d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.169 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj71F9DA9D4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17486, FileId: 0x9b00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.193 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70FD199C1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17487, FileId: 0x9c00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.216 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF313BB9F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17489, FileId: 0x9e00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.243 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj85A33D984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17490, FileId: 0x9f00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.252 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFBF986912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17491, FileId: 0xa000000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.266 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2F45DE932. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17492, FileId: 0xa100000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.282 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8622839B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17493, FileId: 0xa200000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.296 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E564E9C9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17494, FileId: 0xa300000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.313 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCA3081924. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17495, FileId: 0xa400000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.389 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE493959B2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17496, FileId: 0xa500000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.405 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEB57B299C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17497, FileId: 0xa600000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.431 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8EB220949. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17498, FileId: 0xa700000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.442 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB4CD6C9AA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17499, FileId: 0xa800000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.484 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCAE628919. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17500, FileId: 0x88000000010e43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.492 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFE4A56912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17501, FileId: 0xaa00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.619 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11E43E9CE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17502, FileId: 0xab00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.635 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA7C4BA9B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17503, FileId: 0x3600000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.650 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj992B0696D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17504, FileId: 0x3700000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.666 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj54572D9DD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17505, FileId: 0x3800000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.682 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj359263928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17506, FileId: 0x3900000000ed55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.826 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjADCC4E9C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17515, FileId: 0x89000000010e43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:49.847 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj42840593D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17516, FileId: 0xad00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:50.064 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCFF6C0923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17522, FileId: 0xae00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:50.064 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4F7FDC99D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17523, FileId: 0xaf00000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:22:57.791 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17653, FileId: 0xb000000000f4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:23:03.174 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17660, FileId: 0x5800000000cf0f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:23:03.315 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17664, FileId: 0x127000000006413, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:23:03.408 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17668, FileId: 0x3600000000e7d9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:24:03.591 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17700, FileId: 0x12d000000006413, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:25:51.025 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #17763, FileId: 0x48e00000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:29:54.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T13:33:03.560 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17854, FileId: 0x5400000000d0b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:33:03.575 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #17856, FileId: 0x2c0000000110d8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T13:44:59.650 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T14:00:04.649 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T14:15:09.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T14:29:10.862 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19472, FileId: 0x5b000000012a1d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T14:30:14.650 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T14:45:19.650 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T14:46:04.282 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19800, FileId: 0x880000000075ce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T14:55:10.741 ProcessImageName: explorer.exe, Pid: 2852, TotalTime: 6131, Count: 115, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 6% 2026-05-15T14:55:10.741 ProcessImageName: AggregatorHost.exe, Pid: 5536, TotalTime: 4245, Count: 144, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: AcroCEF.exe, Pid: 5084, TotalTime: 3294, Count: 169, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-15T14:55:10.741 ProcessImageName: DipAwayMode.exe, Pid: 3768, TotalTime: 2743, Count: 16, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: AsPowerBar.exe, Pid: 10700, TotalTime: 2740, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 16% 2026-05-15T14:55:10.741 ProcessImageName: dllhost.exe, Pid: 9308, TotalTime: 2046, Count: 68, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\NULHZZBBSN_153, EstimatedImpact: 51% 2026-05-15T14:55:10.741 ProcessImageName: DeviceCensus.exe, Pid: 4072, TotalTime: 1951, Count: 7, MaxTime: 968, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-15T14:55:10.741 ProcessImageName: MOM.exe, Pid: 12624, TotalTime: 1882, Count: 29, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 85% 2026-05-15T14:55:10.741 ProcessImageName: AISuite3.exe, Pid: 2776, TotalTime: 1336, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-05-15T14:55:10.741 ProcessImageName: websockify.exe, Pid: 12648, TotalTime: 880, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 75% 2026-05-15T14:55:10.741 ProcessImageName: WmiPrvSE.exe, Pid: 3692, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-05-15T14:55:10.741 ProcessImageName: WmiPrvSE.exe, Pid: 3400, TotalTime: 509, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-05-15T14:55:10.741 ProcessImageName: powershell.exe, Pid: 6724, TotalTime: 446, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-05-15T14:55:10.741 ProcessImageName: TeamViewer.exe, Pid: 4156, TotalTime: 363, Count: 31, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 2464, TotalTime: 246, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 39% 2026-05-15T14:55:10.741 ProcessImageName: WhatsApp.Root.exe, Pid: 11780, TotalTime: 166, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{328D6E84-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db, EstimatedImpact: 1% 2026-05-15T14:55:10.741 ProcessImageName: FileCoAuth.exe, Pid: 10292, TotalTime: 166, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: backgroundTaskHost.exe, Pid: 3576, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 12% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 1392, TotalTime: 165, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 150, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-15.log, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 5% 2026-05-15T14:55:10.741 ProcessImageName: PhoneExperienceHost.exe, Pid: 9560, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: Acrobat.exe, Pid: 5032, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_ecc.dll, EstimatedImpact: 5% 2026-05-15T14:55:10.741 ProcessImageName: SecurityHealthHost.exe, Pid: 10616, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-15T14:55:10.741 ProcessImageName: SDXHelper.exe, Pid: 9180, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A66D91F-4141-4DA0-9E28-E37700E8D6CC, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: AcroCEF.exe, Pid: 7104, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 38% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 2144, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: backgroundTaskHost.exe, Pid: 12488, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 16% 2026-05-15T14:55:10.741 ProcessImageName: SDXHelper.exe, Pid: 6140, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: dasHost.exe, Pid: 5340, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 4384, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: taskhostw.exe, Pid: 7136, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\AB473FEC6A5D9774CAF4BF9F95A8CEF3C0D5FEBC, EstimatedImpact: 31% 2026-05-15T14:55:10.741 ProcessImageName: runonce.exe, Pid: 12304, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: OpenWith.exe, Pid: 12080, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 35% 2026-05-15T14:55:10.741 ProcessImageName: TeamViewer_Service.exe, Pid: 4572, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 1% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 10048, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B25435C5-697D-486A-A0E8-A429822004B5, EstimatedImpact: 1% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 10660, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1518.log, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 5876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1646.log, EstimatedImpact: 2% 2026-05-15T14:55:10.741 ProcessImageName: dllhost.exe, Pid: 8664, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 16% 2026-05-15T14:55:10.741 ProcessImageName: backgroundTaskHost.exe, Pid: 9224, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 36% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 5348, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1504.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-15T14:55:10.741 ProcessImageName: Acrobat.exe, Pid: 12084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 3% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 10968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1522.log, EstimatedImpact: 1% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 6012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6474.tmp, EstimatedImpact: 4% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 4236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\DiagTrack\utc.allow.diffbase, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 12984, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: SDXHelper.exe, Pid: 7688, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 3% 2026-05-15T14:55:10.741 ProcessImageName: OfficeC2RClient.exe, Pid: 7504, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1502.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: OneDriveLauncher.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: svchost.exe, Pid: 12708, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: dllhost.exe, Pid: 6096, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-15T14:55:10.741 ProcessImageName: brynhildr.exe, Pid: 4196, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-15T15:00:24.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T15:01:40.758 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20104, FileId: 0x5900000000d0b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:15:29.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T15:30:34.662 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T15:45:39.648 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T15:54:39.996 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20363, FileId: 0xcd000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:39.996 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20364, FileId: 0xed000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:39.996 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20366, FileId: 0xef000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:39.996 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20367, FileId: 0xd0000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.012 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20368, FileId: 0xf0000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.027 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20370, FileId: 0xd4000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.027 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20371, FileId: 0xf4000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.043 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20362, FileId: 0xec000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.043 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20365, FileId: 0xcf000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.074 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20374, FileId: 0xf6000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.637 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20431, FileId: 0xdc000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.637 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20433, FileId: 0xdd000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.637 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20429, FileId: 0xfb000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.652 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20434, FileId: 0xfe000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.652 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20435, FileId: 0xde000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.652 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20436, FileId: 0xff000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.652 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20438, FileId: 0x100000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.652 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20430, FileId: 0xfd000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.668 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20437, FileId: 0xdf000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.684 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20441, FileId: 0x101000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.684 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20444, FileId: 0x102000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.684 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20445, FileId: 0xe2000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.684 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20448, FileId: 0x103000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.699 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20442, FileId: 0xe1000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.730 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20456, FileId: 0xe5000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.730 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20457, FileId: 0x106000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.746 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20458, FileId: 0xe6000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.746 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20459, FileId: 0x107000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.746 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20455, FileId: 0x105000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.762 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20451, FileId: 0x104000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.871 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20482, FileId: 0xe9000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:40.871 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20481, FileId: 0x10a000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:41.730 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20565, FileId: 0x10d000000013a76, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T15:54:42.793 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\c9fa8e57-1f95-43e5-9366-86b6bc257b2c. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #20655, FileId: 0x6a00000002bd02, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:00:44.650 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T16:15:49.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T16:18:38.828 Engine:Process 2472 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-15T16:18:51.434 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21323, FileId: 0x46000000013257, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:22:34.194 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21604, FileId: 0x8900000000c0c9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:24:11.386 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22002, FileId: 0x7e00000000eef1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:30:54.649 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T16:43:39.227 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22631, FileId: 0x8000000000eef1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:45:59.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T16:46:23.451 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23054, FileId: 0x1b5000000013baf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:49:16.214 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #23438, FileId: 0x79000000010753, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T16:55:10.750 ProcessImageName: explorer.exe, Pid: 2852, TotalTime: 6176, Count: 118, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: AggregatorHost.exe, Pid: 5536, TotalTime: 4245, Count: 146, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: AcroCEF.exe, Pid: 5084, TotalTime: 3294, Count: 169, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-15T16:55:10.750 ProcessImageName: DipAwayMode.exe, Pid: 3768, TotalTime: 2743, Count: 16, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: AsPowerBar.exe, Pid: 10700, TotalTime: 2740, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 16% 2026-05-15T16:55:10.750 ProcessImageName: firefox.exe, Pid: 13156, TotalTime: 2505, Count: 239, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 68% 2026-05-15T16:55:10.750 ProcessImageName: dllhost.exe, Pid: 9308, TotalTime: 2046, Count: 68, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\NULHZZBBSN_153, EstimatedImpact: 51% 2026-05-15T16:55:10.750 ProcessImageName: DeviceCensus.exe, Pid: 4072, TotalTime: 1951, Count: 7, MaxTime: 968, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-15T16:55:10.750 ProcessImageName: MOM.exe, Pid: 12624, TotalTime: 1882, Count: 29, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 85% 2026-05-15T16:55:10.750 ProcessImageName: AISuite3.exe, Pid: 2776, TotalTime: 1336, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-05-15T16:55:10.750 ProcessImageName: websockify.exe, Pid: 12648, TotalTime: 880, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 75% 2026-05-15T16:55:10.750 ProcessImageName: WmiPrvSE.exe, Pid: 3692, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-05-15T16:55:10.750 ProcessImageName: WmiPrvSE.exe, Pid: 3400, TotalTime: 509, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-05-15T16:55:10.750 ProcessImageName: powershell.exe, Pid: 6724, TotalTime: 446, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-05-15T16:55:10.750 ProcessImageName: TeamViewer.exe, Pid: 4156, TotalTime: 409, Count: 34, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 2464, TotalTime: 246, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 1392, TotalTime: 225, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 39% 2026-05-15T16:55:10.750 ProcessImageName: WhatsApp.Root.exe, Pid: 11780, TotalTime: 166, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{328D6E84-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: FileCoAuth.exe, Pid: 10292, TotalTime: 166, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: backgroundTaskHost.exe, Pid: 3576, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 12% 2026-05-15T16:55:10.750 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 150, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-15.log, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 5% 2026-05-15T16:55:10.750 ProcessImageName: PhoneExperienceHost.exe, Pid: 9560, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: Acrobat.exe, Pid: 5032, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_ecc.dll, EstimatedImpact: 5% 2026-05-15T16:55:10.750 ProcessImageName: SecurityHealthHost.exe, Pid: 10616, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-15T16:55:10.750 ProcessImageName: SDXHelper.exe, Pid: 9180, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A66D91F-4141-4DA0-9E28-E37700E8D6CC, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: AcroCEF.exe, Pid: 7104, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 38% 2026-05-15T16:55:10.750 ProcessImageName: dasHost.exe, Pid: 5340, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 2144, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: backgroundTaskHost.exe, Pid: 12488, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 16% 2026-05-15T16:55:10.750 ProcessImageName: SDXHelper.exe, Pid: 6140, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: taskhostw.exe, Pid: 7136, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\AB473FEC6A5D9774CAF4BF9F95A8CEF3C0D5FEBC, EstimatedImpact: 31% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 4384, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: runonce.exe, Pid: 12304, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: TeamViewer_Service.exe, Pid: 4572, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: OpenWith.exe, Pid: 12080, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 35% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 10048, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B25435C5-697D-486A-A0E8-A429822004B5, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 9996, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1843.log, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 5876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1646.log, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 10660, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1518.log, EstimatedImpact: 2% 2026-05-15T16:55:10.750 ProcessImageName: dllhost.exe, Pid: 8664, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 16% 2026-05-15T16:55:10.750 ProcessImageName: backgroundTaskHost.exe, Pid: 9224, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 36% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 5348, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1504.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: SDXHelper.exe, Pid: 9192, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 13% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 6640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1822.log, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: Acrobat.exe, Pid: 12084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 3% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 6012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6474.tmp, EstimatedImpact: 4% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 4116, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1824.log, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 10968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1522.log, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 6980, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1818.log, EstimatedImpact: 1% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 4236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\DiagTrack\utc.allow.diffbase, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 12984, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: SDXHelper.exe, Pid: 7688, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 3% 2026-05-15T16:55:10.750 ProcessImageName: dllhost.exe, Pid: 6096, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 7504, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1502.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OneDriveLauncher.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1701.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 10588, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1849.log, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1846.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: svchost.exe, Pid: 12708, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-15T16:55:10.750 ProcessImageName: brynhildr.exe, Pid: 4196, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-15T17:01:04.657 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T17:11:05.394 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24194, FileId: 0x23d0000000137fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:16:09.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T17:21:02.786 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25255, FileId: 0x9700000000540f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:25:21.585 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #25720, FileId: 0x9b00000000540f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:31:14.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T17:38:38.153 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26231, FileId: 0x97000000013d49, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:40:16.789 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26650, FileId: 0x36000000013ddd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:45:51.966 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26992, FileId: 0x3d000000013bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:46:19.661 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T17:47:38.796 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #27391, FileId: 0x3800000001b0b9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:49:04.356 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #27731, FileId: 0x43000000013bad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T17:49:04.867 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27744, FileId: 0xf1000000013a7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T18:01:24.651 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T18:16:29.656 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T18:17:25.325 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #30708, FileId: 0x2200000001b6e9, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T18:31:34.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T18:46:39.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T18:55:10.759 ProcessImageName: explorer.exe, Pid: 2852, TotalTime: 6386, Count: 133, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: AggregatorHost.exe, Pid: 5536, TotalTime: 4260, Count: 148, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: AcroCEF.exe, Pid: 5084, TotalTime: 3294, Count: 169, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-15T18:55:10.759 ProcessImageName: DipAwayMode.exe, Pid: 3768, TotalTime: 2743, Count: 16, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: AsPowerBar.exe, Pid: 10700, TotalTime: 2740, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 16% 2026-05-15T18:55:10.759 ProcessImageName: firefox.exe, Pid: 13156, TotalTime: 2505, Count: 239, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 68% 2026-05-15T18:55:10.759 ProcessImageName: dllhost.exe, Pid: 9308, TotalTime: 2046, Count: 68, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\NULHZZBBSN_153, EstimatedImpact: 51% 2026-05-15T18:55:10.759 ProcessImageName: DeviceCensus.exe, Pid: 4072, TotalTime: 1951, Count: 7, MaxTime: 968, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-15T18:55:10.759 ProcessImageName: MOM.exe, Pid: 12624, TotalTime: 1882, Count: 29, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 85% 2026-05-15T18:55:10.759 ProcessImageName: AISuite3.exe, Pid: 2776, TotalTime: 1336, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-05-15T18:55:10.759 ProcessImageName: websockify.exe, Pid: 12648, TotalTime: 880, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 75% 2026-05-15T18:55:10.759 ProcessImageName: WmiPrvSE.exe, Pid: 3692, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-05-15T18:55:10.759 ProcessImageName: TeamViewer.exe, Pid: 4156, TotalTime: 608, Count: 43, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: WmiPrvSE.exe, Pid: 3400, TotalTime: 509, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-05-15T18:55:10.759 ProcessImageName: powershell.exe, Pid: 6724, TotalTime: 446, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 1392, TotalTime: 300, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 2464, TotalTime: 246, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: firefox.exe, Pid: 5744, TotalTime: 227, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\d58b6bc3-7399-4052-89f4-e56dbe33eff8, EstimatedImpact: 27% 2026-05-15T18:55:10.759 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 39% 2026-05-15T18:55:10.759 ProcessImageName: WhatsApp.Root.exe, Pid: 11780, TotalTime: 166, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{328D6E84-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: FileCoAuth.exe, Pid: 10292, TotalTime: 166, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: backgroundTaskHost.exe, Pid: 3576, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 12% 2026-05-15T18:55:10.759 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 150, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-15.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 5% 2026-05-15T18:55:10.759 ProcessImageName: PhoneExperienceHost.exe, Pid: 9560, TotalTime: 106, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: Acrobat.exe, Pid: 5032, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_ecc.dll, EstimatedImpact: 5% 2026-05-15T18:55:10.759 ProcessImageName: SecurityHealthHost.exe, Pid: 10616, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-15T18:55:10.759 ProcessImageName: SDXHelper.exe, Pid: 9180, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A66D91F-4141-4DA0-9E28-E37700E8D6CC, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: AcroCEF.exe, Pid: 7104, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 38% 2026-05-15T18:55:10.759 ProcessImageName: dasHost.exe, Pid: 5340, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 2144, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: backgroundTaskHost.exe, Pid: 12488, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 16% 2026-05-15T18:55:10.759 ProcessImageName: SDXHelper.exe, Pid: 6140, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 6372, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2003.log->(UTF-16LE), EstimatedImpact: 3% 2026-05-15T18:55:10.759 ProcessImageName: dllhost.exe, Pid: 6096, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 4384, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: taskhostw.exe, Pid: 7136, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\AB473FEC6A5D9774CAF4BF9F95A8CEF3C0D5FEBC, EstimatedImpact: 31% 2026-05-15T18:55:10.759 ProcessImageName: runonce.exe, Pid: 12304, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OpenWith.exe, Pid: 12080, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 35% 2026-05-15T18:55:10.759 ProcessImageName: TeamViewer_Service.exe, Pid: 4572, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10048, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B25435C5-697D-486A-A0E8-A429822004B5, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 7492, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1949.log, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 9996, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1843.log, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 9396, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1954.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10660, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1518.log, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 5876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1646.log, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: dllhost.exe, Pid: 8664, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 16% 2026-05-15T18:55:10.759 ProcessImageName: backgroundTaskHost.exe, Pid: 9224, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 36% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 8496, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1921.log, EstimatedImpact: 2% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 5348, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1504.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: SDXHelper.exe, Pid: 9192, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 13% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 6640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1822.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: Acrobat.exe, Pid: 12084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 3% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 5712, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 6012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6474.tmp, EstimatedImpact: 4% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 6980, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1818.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 4116, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1824.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1938.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 13092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1940.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 12668, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1945.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 13252, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2034.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 11360, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1911.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 11252, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1949a.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1522.log, EstimatedImpact: 1% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 9204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2015.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 4236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\DiagTrack\utc.allow.diffbase, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 12984, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: SDXHelper.exe, Pid: 7688, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 3% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 7504, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1502.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1701.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: SDXHelper.exe, Pid: 4848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 10% 2026-05-15T18:55:10.759 ProcessImageName: OneDriveLauncher.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 9908, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2032.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1846.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1956.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 11456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1925.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10588, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1849.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: svchost.exe, Pid: 12708, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 7336, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1947.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: OfficeC2RClient.exe, Pid: 10372, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2035.log, EstimatedImpact: 0% 2026-05-15T18:55:10.759 ProcessImageName: brynhildr.exe, Pid: 4196, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-15T19:01:44.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T19:16:49.660 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T19:31:54.654 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T19:46:59.659 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T20:02:04.663 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T20:06:05.326 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #34544, FileId: 0x27000000032e2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T20:17:09.660 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T20:32:14.655 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T20:47:19.647 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T20:55:10.766 ProcessImageName: explorer.exe, Pid: 2852, TotalTime: 6386, Count: 134, MaxTime: 1296, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: AggregatorHost.exe, Pid: 5536, TotalTime: 4260, Count: 150, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: AcroCEF.exe, Pid: 5084, TotalTime: 3294, Count: 169, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-15T20:55:10.766 ProcessImageName: DipAwayMode.exe, Pid: 3768, TotalTime: 2743, Count: 16, MaxTime: 500, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: AsPowerBar.exe, Pid: 10700, TotalTime: 2740, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 16% 2026-05-15T20:55:10.766 ProcessImageName: firefox.exe, Pid: 13156, TotalTime: 2505, Count: 239, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 68% 2026-05-15T20:55:10.766 ProcessImageName: dllhost.exe, Pid: 9308, TotalTime: 2046, Count: 68, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\RE1RYM1A_471\Q4AO7QU9_473\NULHZZBBSN_153, EstimatedImpact: 51% 2026-05-15T20:55:10.766 ProcessImageName: DeviceCensus.exe, Pid: 4072, TotalTime: 1951, Count: 7, MaxTime: 968, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 44% 2026-05-15T20:55:10.766 ProcessImageName: MOM.exe, Pid: 12624, TotalTime: 1882, Count: 29, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 85% 2026-05-15T20:55:10.766 ProcessImageName: AISuite3.exe, Pid: 2776, TotalTime: 1336, Count: 21, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 5% 2026-05-15T20:55:10.766 ProcessImageName: websockify.exe, Pid: 12648, TotalTime: 880, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 75% 2026-05-15T20:55:10.766 ProcessImageName: TeamViewer.exe, Pid: 4156, TotalTime: 684, Count: 48, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: WmiPrvSE.exe, Pid: 3692, TotalTime: 632, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 96% 2026-05-15T20:55:10.766 ProcessImageName: WmiPrvSE.exe, Pid: 3400, TotalTime: 509, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 88% 2026-05-15T20:55:10.766 ProcessImageName: powershell.exe, Pid: 6724, TotalTime: 446, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 29% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 1392, TotalTime: 315, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 2464, TotalTime: 246, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: firefox.exe, Pid: 5744, TotalTime: 227, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\d58b6bc3-7399-4052-89f4-e56dbe33eff8, EstimatedImpact: 27% 2026-05-15T20:55:10.766 ProcessImageName: TabTip.exe, Pid: 6280, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 39% 2026-05-15T20:55:10.766 ProcessImageName: WhatsApp.Root.exe, Pid: 11780, TotalTime: 166, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\{328D6E84-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: FileCoAuth.exe, Pid: 10292, TotalTime: 166, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: backgroundTaskHost.exe, Pid: 3576, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 12% 2026-05-15T20:55:10.766 ProcessImageName: AdobeCollabSync.exe, Pid: 11384, TotalTime: 150, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-15.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 5% 2026-05-15T20:55:10.766 ProcessImageName: PhoneExperienceHost.exe, Pid: 9560, TotalTime: 106, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: Acrobat.exe, Pid: 5032, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_ecc.dll, EstimatedImpact: 5% 2026-05-15T20:55:10.766 ProcessImageName: SecurityHealthHost.exe, Pid: 10616, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 9180, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\6A66D91F-4141-4DA0-9E28-E37700E8D6CC, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: AcroCEF.exe, Pid: 7104, TotalTime: 91, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 38% 2026-05-15T20:55:10.766 ProcessImageName: dasHost.exe, Pid: 5340, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: dllhost.exe, Pid: 6096, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 2144, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: backgroundTaskHost.exe, Pid: 12488, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 16% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 6140, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8A11338F-DE53-4362-B4D0-A3021CDD3808, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 6372, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2003.log->(UTF-16LE), EstimatedImpact: 3% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 4384, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: FileCoAuth.exe, Pid: 11528, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-15.1911.11528.1.aodl, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: taskhostw.exe, Pid: 7136, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\AB473FEC6A5D9774CAF4BF9F95A8CEF3C0D5FEBC, EstimatedImpact: 31% 2026-05-15T20:55:10.766 ProcessImageName: runonce.exe, Pid: 12304, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OpenWith.exe, Pid: 12080, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26093.415.4620.1935_x64__8wekyb3d8bbwe\resources.pri, EstimatedImpact: 35% 2026-05-15T20:55:10.766 ProcessImageName: TeamViewer_Service.exe, Pid: 4572, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10048, TotalTime: 46, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B25435C5-697D-486A-A0E8-A429822004B5, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 7492, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1949.log, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 9996, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1843.log, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 9396, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1954.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10660, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1518.log, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 5876, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1646.log, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: dllhost.exe, Pid: 8664, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 16% 2026-05-15T20:55:10.766 ProcessImageName: backgroundTaskHost.exe, Pid: 9224, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 36% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 8496, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1921.log, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 5348, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1504.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 9192, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 13% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 6640, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1822.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 5712, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: Acrobat.exe, Pid: 12084, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 3% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 6800, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2232.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10952, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2203.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 4116, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1824.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 6980, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1818.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 9468, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2120.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 9204, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2015.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1522.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 7364, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2207.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 3692, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2145.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 12556, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2226.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 6012, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT6474.tmp, EstimatedImpact: 4% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 7240, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2206.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 13252, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2034.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 11252, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1949a.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 11360, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1911.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 11880, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2228.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 12668, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1945.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 13092, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1940.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 4000, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1938.log, EstimatedImpact: 1% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 4236, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\DiagTrack\utc.allow.diffbase, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 12984, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7F549931-0D0E-44FC-9039-7BF60B18E7D4, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 7688, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_879AFEB08DCB012707582D902977FF92, EstimatedImpact: 3% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 7504, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1502.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 9908, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2032.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OneDriveLauncher.exe, Pid: 9716, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10964, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1846.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 11120, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1701.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10588, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1849.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 5772, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2128.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 11456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1925.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 4848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 10% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 12484, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2147.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1956.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: svchost.exe, Pid: 12708, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: SDXHelper.exe, Pid: 7352, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 2% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 7336, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-1947.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: OfficeC2RClient.exe, Pid: 10372, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260515-2035.log, EstimatedImpact: 0% 2026-05-15T20:55:10.766 ProcessImageName: brynhildr.exe, Pid: 4196, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-15T21:02:24.653 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T21:17:29.648 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T21:32:34.658 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-15T21:36:16.385 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #39466, FileId: 0x40000000040012, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-15T21:47:39.652 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x211f41cf 2026-05-15T21:51:11.455 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:11.455 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:11.455 [Cloud] Queued cloud request. 2026-05-15T21:51:11.455 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:11.455 [Cloud] Dequeued cloud request. 2026-05-15T21:51:11.455 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:11.830 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2170ee8b7db76e95bd0683b685c93a19f4b7a787 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:11 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:11.830 [Cloud] End of cloud request. 2026-05-15T21:51:11.830 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7133769a 2026-05-15T21:51:12.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:12.096 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:12.096 [Cloud] Queued cloud request. 2026-05-15T21:51:12.096 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:12.096 [Cloud] Dequeued cloud request. 2026-05-15T21:51:12.096 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:12.299 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9df28069c54f06cc967ef127f236c8a1611d6933 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:12.299 [Cloud] End of cloud request. 2026-05-15T21:51:12.299 RTSD:RTSD recieved, rescanning impacted resources 2026-05-15T21:51:12.346 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a883020 2026-05-15T21:51:12.522 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:12.522 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:12.522 [Cloud] Queued cloud request. 2026-05-15T21:51:12.522 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:12.522 [Cloud] Dequeued cloud request. 2026-05-15T21:51:12.522 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:12.694 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\674d5b2b98a544ac9597110bad1887dc30b5aa79 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:12.694 [Cloud] End of cloud request. 2026-05-15T21:51:12.694 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ccbb36f 2026-05-15T21:51:12.788 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:12.788 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:12.788 [Cloud] Queued cloud request. 2026-05-15T21:51:12.788 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:12.788 [Cloud] Dequeued cloud request. 2026-05-15T21:51:12.788 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:12.979 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cba30f8b11b5cb2837316244dae1a21e942b1bfc Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:12.979 [Cloud] End of cloud request. 2026-05-15T21:51:12.979 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3dc12e4b 2026-05-15T21:51:13.201 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T21:51:13.405 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:13.405 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:13.405 [Cloud] Queued cloud request. 2026-05-15T21:51:13.405 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:13.405 [Cloud] Dequeued cloud request. 2026-05-15T21:51:13.405 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:13.609 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e72bb33d32ab21d1c69a07f7a19b1cbe628e4ee2 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:13 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:13.609 [Cloud] End of cloud request. 2026-05-15T21:51:13.609 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-15T21:51:13.843 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:13.843 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:13.843 [Cloud] Queued cloud request. 2026-05-15T21:51:13.843 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:13.843 [Cloud] Dequeued cloud request. 2026-05-15T21:51:13.843 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:14.109 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-15T21:51:14.202 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\107eb01a0bf73838cb49bfa61ebe37b4c3799392 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:13 Persistence Type:Duration Time remaining:288000000 2026-05-15T21:51:14.202 [Cloud] End of cloud request. 2026-05-15T21:51:14.202 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c25bb8 2026-05-15T21:51:14.283 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-15T21:51:14.283 [Cloud] Start of cloud request. Passive mode: 0 2026-05-15T21:51:14.283 [Cloud] Queued cloud request. 2026-05-15T21:51:14.283 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-15T21:51:14.297 [Cloud] Dequeued cloud request. 2026-05-15T21:51:14.297 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-15T21:51:14.502 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\47a558d44b924447c7cfb687a3f682597cf7981c Dynamic Signature Compilation Timestamp:05-15-2026 21:51:14 Persistence Type:Duration Time remaining:50065408 2026-05-15T21:51:14.502 [Cloud] End of cloud request. 2026-05-15T21:51:14.502 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6ab8889 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-16-2026 06:12:11 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/16/2026 06:12:11.99698000 UTC (13812 ms since boot) 2026-05-16T06:12:11.113 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-16T06:12:11.122 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:12:11.122 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:12:11.207 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260516-061211-00000003-fffffffeffffffff.bin ... 2026-05-16T06:12:11.277 [WPP] Trace session started - MpWppTracing-20260516-061211-00000003-fffffffeffffffff.bin 2026-05-16T06:12:11.282 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-16T06:12:11.282 [RbM] Rollback manager succesfully initialized. 2026-05-16T06:12:11.282 [RbM] Rollback manager EnableRollbackManager called. 2026-05-16T06:12:11.292 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-16T06:12:11.292 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-16T06:12:11.292 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-16T06:12:11.292 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-16T06:12:11.292 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-16T06:12:11.292 MdCoreSvc is supported in this platform and OS 2026-05-16T06:12:11.292 MdCoreSvc is supported in this platform and OS 2026-05-16T06:12:11.292 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T06:12:11.297 [PlatUpd] Starting MdCoreSvc service 2026-05-16T06:12:11.336 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-16T06:12:14.985 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-16T06:12:14.985 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-16T06:12:14.985 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-16T06:12:14.985 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-16T06:12:14.985 [PlatUpd] CSP platform update started 2026-05-16T06:12:14.985 [PlatUpd] Defender MDM CSP platform update not required 2026-05-16T06:12:14.985 [PlatUpd] WMI/PS provider platform update started 2026-05-16T06:12:14.985 [PlatUpd] WMI/PS provider platform update not required 2026-05-16T06:12:14.985 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-16T06:12:14.985 MdCoreSvc is supported in this platform and OS 2026-05-16T06:12:14.985 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T06:12:14.985 [PlatUpd] Starting MdCoreSvc service 2026-05-16T06:12:14.985 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-16T06:12:14.985 [TS] Troubleshooting mode is not available! 2026-05-16T06:12:14.985 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T06:12:14.985 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-16T06:12:15.016 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-16T06:12:15.016 [Service] Enabling AutoLoggers ... 2026-05-16T06:12:15.016 [Service] Enabling AMSI registration ... 2026-05-16T06:12:15.016 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-16T06:12:15.032 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43201 Number of invalid entries is 0 Number of inserts issued is 1584645 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6517 Number of lookups is 108285810 Number of lookup misses is 5198308 Number of fast lookup misses is 55181994 Number of false fast lookups is 5198303 Number of invalidations is 734928 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-16T06:12:15.032 Verifying license file... 2026-05-16T06:12:15.032 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-16T06:12:15.047 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-16T06:12:15.047 Loaded module#0 MpComServer. 2026-05-16T06:12:15.047 Loaded module#1 StartupPolicies. 2026-05-16T06:12:15.047 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T06:12:15.047 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T06:12:15.047 COM server initialized successfully. 2026-05-16T06:12:15.063 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-16T06:12:15.079 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-16T06:12:15.079 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-16T06:12:15.094 [RTP] [RTP] FilterCommunicator object 0x000001219929C740 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T06:12:15.094 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-16T06:12:15.094 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T06:12:15.094 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T06:12:15.094 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-16T06:12:15.094 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-16T06:12:15.094 [RTP] [RTP] FilterCommunicator object 0x000001219929C950 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T06:12:15.094 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-16T06:12:15.094 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-16T06:12:15.094 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-16T06:12:15.094 [RTP] [RTP] StartCommunication 0x000001219929C740 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T06:12:15.094 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-16T06:12:15.094 [init][RTP] RTPPlugin initialization completed 2026-05-16T06:12:15.094 OS boot count = 2 2026-05-16T06:12:15.094 OS Install = 0 2026-05-16T06:12:15.110 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-16T06:12:15.110 [KSL] Entering CKSLEngine::Initialize. 2026-05-16T06:12:15.110 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-16T06:12:15.110 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-16T06:12:15.110 [KSL] MpInstallKslD: hr=0x1 2026-05-16T06:12:15.110 [KSL] MpRegisterKslD: hr=0 2026-05-16T06:12:15.110 [KSL] MpStartKslD: hr=0 2026-05-16T06:12:15.110 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T06:12:15.110 Loading engine... 2026-05-16T06:12:15.126 Verifying engine and signature files (source: 1) ... 2026-05-16T06:12:15.126 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpengine.dll] due to PPL. 2026-05-16T06:12:15.126 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasbase.vdm]. File not in cache (0x1) 2026-05-16T06:12:16.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasbase.vdm] 2026-05-16T06:12:16.079 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasdlta.vdm] (file in cache) 2026-05-16T06:12:16.079 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavbase.vdm]. File not in cache (0x1) 2026-05-16T06:12:16.516 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavbase.vdm] 2026-05-16T06:12:16.516 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpavdlta.vdm] (file in cache) 2026-05-16T06:12:16.547 [Engine] IsHybridMode: 0 2026-05-16T06:12:16.547 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-16T06:12:16.579 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-607B832ACECC74746205607F6294A3064FC1CA08.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-16T06:12:20.438 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-16T06:12:20.438 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-16T06:12:20.438 [Engine] New active engine 00007FF81A7C5810 (no old engine). Number of active engines: 1 2026-05-16T06:12:20.469 EngineInit:Global ASOC is enabled 2026-05-16T06:12:20.485 EngineInit:ASOO is enabled for developer volumes 2026-05-16T06:12:20.594 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-16T06:12:20.594 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.594 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-16T06:12:20.594 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-16T06:12:20.594 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:12:20.610 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\313716707a9894c4508a80fbff657b283739b922 Dynamic Signature Compilation Timestamp:04-15-2026 13:32:05 Persistence Type:Duration Time remaining:150196224 2026-05-16T06:12:20.610 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ca527195a5ff0fcdbfd37e0f8ea3b91de6e64bc8 Dynamic Signature Compilation Timestamp:04-15-2026 13:32:05 Persistence Type:Duration Time remaining:150196224 2026-05-16T06:12:20.610 Dynamic signature dropped 2026-05-16T06:12:20.626 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\107eb01a0bf73838cb49bfa61ebe37b4c3799392 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:13 Persistence Type:Duration Time remaining:288000000 2026-05-16T06:12:20.626 MpWriteUupSignatureVersion 1.449.629.0, hr = 0 2026-05-16T06:12:20.626 [SigStatUpd] CSignatureStatus: back to good 2026-05-16T06:12:20.641 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-16T06:12:20.657 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-16T06:12:20.657 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:12:20.657 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-16T06:12:20.657 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-16T06:12:20.657 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T06:12:20.672 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-16T06:12:20.672 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2062 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11472 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:1 InstanceCacheMisses:2284 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-16T06:12:20.672 [Plugin] Initializing RTP plugin state... 2026-05-16T06:12:20.672 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-16T06:12:20.672 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77} 2026-05-16T06:12:20.672 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:12:20.672 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:12:20.672 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:12:20.672 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T06:12:20.672 MdCoreSvc is supported in this platform and OS 2026-05-16T06:12:20.688 Engine loaded! 2026-05-16T06:12:20.688 [DLP] Create FeatureControlState instance 2026-05-16T06:12:20.688 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-16T06:12:20.688 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-16T06:12:20.688 RegisterSModeChangeListener: hr = 0x1 2026-05-16T06:12:20.688 RegisterHybridModeChangeListener: hr = 0 2026-05-16T06:12:20.704 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T06:12:20.719 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-16T06:12:20.719 [SigReleaseHb] Initialized with Stage 0 2026-05-16T06:12:20.719 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-16T06:12:20.719 [SCC][CID=23437_5472] Initializing ... 2026-05-16T06:12:20.719 [SCC][CID=23437_5472] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-16T06:12:20.719 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-16T06:12:20.719 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-16T06:12:20.719 [NRI] Stopping NIS service ... 2026-05-16T06:12:20.719 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-16T06:12:20.719 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.629.0 AV Signature Version: 1.449.629.0 ************************************************************ 2026-05-16T06:12:20.735 Resource usage Monitoring is enabled 2026-05-16T06:12:20.735 Job Notification: New process added to job (4512) 2026-05-16T06:12:20.735 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-16T06:12:20.782 Job Notification: New process added to job (6804) 2026-05-16T06:12:20.782 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-16T06:12:20.782 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T06:12:20.797 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T06:12:20.797 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T06:12:20.797 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T06:12:20.797 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T06:12:20.797 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T06:12:20.797 [RTP] Generating the base plugin configuration ... 2026-05-16T06:12:20.797 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-16T06:12:20.797 Job Notification: New process added to job (3440) 2026-05-16T06:12:20.797 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:12:20.797 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-16T06:12:20.797 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-16T06:12:20.797 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:12:20.797 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-16T06:12:20.797 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:6804] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3440]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:12:20.797 [RTP] [RTP] StartCommunication 0x000001219929C950 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T06:12:20.797 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-16T06:12:20.813 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-16T06:12:20.907 Job Notification: Process exited from job (6804) 2026-05-16T06:12:20.907 Job Notification: Process exited from job (3440) 2026-05-16T06:12:20.907 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-16T06:12:21.141 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:12:21.141 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-16T06:12:21.141 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-16T06:12:21.141 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T06:12:23.719 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:12:23.719 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:12:23.719 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-16T06:12:23.719 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-16T06:12:23.719 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-16T06:12:41.758 [RTP] 1 newly mounted volumes accumulated, forcing a config update ... 2026-05-16T06:12:41.758 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-16T06:12:41.758 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:12:41.758 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:12:41.758 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-16T06:12:41.758 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-16T06:12:41.758 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-16T06:13:06.576 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2814, FileId: 0x19000000096d1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:13:15.221 Process scan (poststartupscan) started. 2026-05-16T06:13:15.237 Process scan (poststartupscan) completed. 2026-05-16T06:13:15.753 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-16T06:13:15.768 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-16T06:13:18.406 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:13:18.406 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:13:18.406 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-16T06:13:18.406 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-16T06:13:18.406 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-16T06:14:14.268 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:14:14.268 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T06:14:14.284 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:14:28.550 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\22D6ADE0-880C-4FD2-BD25-53BEB23C7D51c24.1dce4fb3f42835f 2026-05-16T06:14:28.675 Verifying engine and signature files (source: 0) ... 2026-05-16T06:14:28.675 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpengine.dll] due to PPL. 2026-05-16T06:14:28.675 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm]. File not in cache (0x1) 2026-05-16T06:14:29.425 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm] 2026-05-16T06:14:29.425 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-16T06:14:29.440 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasdlta.vdm] 2026-05-16T06:14:29.440 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm]. File not in cache (0x1) 2026-05-16T06:14:29.784 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm] 2026-05-16T06:14:29.784 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-16T06:14:29.815 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavdlta.vdm] 2026-05-16T06:14:29.971 [Engine] IsHybridMode: 0 2026-05-16T06:14:29.971 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-16T06:14:29.987 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-BD6F815C8D130F9E9724667CC5D868F55032F114.bin): 0x00000002 2026-05-16T06:14:29.987 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-BD6F815C8D130F9E9724667CC5D868F55032F114.bin) 2026-05-16T06:14:29.987 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-16T06:14:29.987 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-16T06:14:29.987 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-16T06:14:29.987 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-16T06:14:40.471 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-16T06:14:40.471 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-16T06:14:40.487 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF81A7C5810, lRefCount: 5, hr=0 2026-05-16T06:14:40.487 [Engine] New active engine 00007FFFBE305810 replacing engine 00007FF81A7C5810. Number of active engines: 2 2026-05-16T06:14:40.487 EngineInit:Global ASOC is enabled 2026-05-16T06:14:40.487 EngineInit:ASOO is enabled for developer volumes 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.550 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:14:40.565 MpWriteUupSignatureVersion 1.449.642.0, hr = 0 2026-05-16T06:14:40.565 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-16T06:14:40.581 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-16T06:14:40.581 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:14:40.581 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-16T06:14:40.581 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-16T06:14:40.581 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T06:14:40.596 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-16T06:14:40.596 [Plugin] Initializing RTP plugin state... 2026-05-16T06:14:40.596 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-16T06:14:40.596 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎16‎-‎2026 08:12:20 Last Perf:‎05‎-‎16‎-‎2026 08:12:20 First RTP Scan:‎05‎-‎16‎-‎2026 08:12:20 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2073 Misses:2956 BM Queue:0,729,0 Proc:0,378,0 File:0,351,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5187 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:7909964 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:5994 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:22285 TotalHits:13793 InstanceCacheInserts:266 InstanceCacheUpdates:0 InstanceCacheDeletes:168 InstanceCacheHits:1 InstanceCacheMisses:6819 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (764/164) Success: 164, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-16T06:14:40.596 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8} 2026-05-16T06:14:40.596 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T06:14:40.596 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0F838EF7-8EE7-4EA1-9C28-51E19E9BCA8A} removed 2026-05-16T06:14:40.596 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77}\mpasbase.vdm in use, hr=0x80070020 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-16-2026 06:14:40 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-16-2026 06:14:40 2026-05-16T06:14:40.612 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-16T06:14:40.612 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-16T06:14:40.612 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:14:40.612 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-16T06:14:40.612 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T06:14:40.612 MdCoreSvc is supported in this platform and OS Signature updated on 05-16-2026 06:14:40 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.642.0 AV Signature Version: 1.449.642.0 ************************************************************ 2026-05-16T06:14:40.612 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-16T06:14:40.612 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\22D6ADE0-880C-4FD2-BD25-53BEB23C7D51c24.1dce4fb3f42835f 2026-05-16T06:14:40.690 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-16T06:14:40.690 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T06:14:41.065 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T06:14:41.065 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T06:14:41.065 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T06:14:41.065 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T06:14:41.065 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T06:14:41.065 [Engine] Engine 00007FF81A7C5810 no longer in use. Number of active engines: 1 2026-05-16T06:14:41.065 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:14:41.065 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-16T06:14:41.081 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-16T06:14:41.081 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-16T06:14:41.081 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T06:14:41.159 ProcessImageName: explorer.exe, Pid: 8540, TotalTime: 6266, Count: 110, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 15% 2026-05-16T06:14:41.159 ProcessImageName: DipAwayMode.exe, Pid: 8096, TotalTime: 2852, Count: 15, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 16% 2026-05-16T06:14:41.159 ProcessImageName: AsPowerBar.exe, Pid: 12124, TotalTime: 2758, Count: 18, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 13% 2026-05-16T06:14:41.159 ProcessImageName: MOM.exe, Pid: 10656, TotalTime: 2149, Count: 29, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll, EstimatedImpact: 72% 2026-05-16T06:14:41.159 ProcessImageName: AISuite3.exe, Pid: 8088, TotalTime: 1476, Count: 22, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 12% 2026-05-16T06:14:41.159 ProcessImageName: websockify.exe, Pid: 7096, TotalTime: 927, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 69% 2026-05-16T06:14:41.159 ProcessImageName: WmiPrvSE.exe, Pid: 3900, TotalTime: 480, Count: 60, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf->(UTF-16LE), EstimatedImpact: 13% 2026-05-16T06:14:41.159 ProcessImageName: TeamViewer.exe, Pid: 7820, TotalTime: 363, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 3% 2026-05-16T06:14:41.159 ProcessImageName: TabTip.exe, Pid: 8284, TotalTime: 277, Count: 12, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 40% 2026-05-16T06:14:41.159 ProcessImageName: FileCoAuth.exe, Pid: 11848, TotalTime: 196, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-16T06:14:41.159 ProcessImageName: backgroundTaskHost.exe, Pid: 2280, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 19% 2026-05-16T06:14:41.159 ProcessImageName: WhatsApp.Root.exe, Pid: 11836, TotalTime: 165, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-05-16T06:14:41.159 ProcessImageName: dllhost.exe, Pid: 10936, TotalTime: 165, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Internet Explorer\CacheStorage\edb.chk, EstimatedImpact: 3% 2026-05-16T06:14:41.159 ProcessImageName: PhoneExperienceHost.exe, Pid: 11540, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-05-16T06:14:41.159 ProcessImageName: CLIStart.exe, Pid: 12052, TotalTime: 91, Count: 13, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 61% 2026-05-16T06:14:41.190 [Engine] RSIG_UNLOADENGINE, 00007FF81A7C5810, err=0x0 2026-05-16T06:14:41.206 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D093566F-0532-4268-934E-7D6C7FC59B77} removed 2026-05-16T06:14:42.612 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:14:42.612 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T06:14:42.612 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:16:47.378 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5729, FileId: 0x2d000000013168, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.425 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5734, FileId: 0x1c000000013659, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.425 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5736, FileId: 0x2f000000013168, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.440 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5738, FileId: 0x4f3000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.440 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5733, FileId: 0x2e000000013168, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.440 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5741, FileId: 0x26000000013659, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.456 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5735, FileId: 0x1d000000013659, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.456 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5739, FileId: 0x4f4000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.722 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0530e1f1-bb38-4412-83a0-0b64c88c51ad. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #5756, FileId: 0xc800000000a075, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.769 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5759, FileId: 0x46000000013168, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:16:47.769 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5758, FileId: 0xc400000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:17:20.721 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T06:17:34.909 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6404, FileId: 0x25000000036a3a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:18:43.169 [RTP] 8 newly mounted volumes accumulated, forcing a config update ... 2026-05-16T06:18:43.169 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:18:43.169 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:18:43.169 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-16T06:18:43.169 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-16T06:18:43.169 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-16T06:18:43.312 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-16T06:19:40.534 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-16T06:22:16.737 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8754, FileId: 0x6000000000cfc6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:22:20.721 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-16T06:22:20.721 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-16T06:22:20.737 Job Notification: New process added to job (4728) 2026-05-16T06:22:20.753 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-16T06:22:20.753 Job Notification: New process added to job (3824) 2026-05-16T06:22:20.768 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:4728] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3824]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:22:20.815 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 68773858(ms) from now at 03:28 (01:28 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-16T06:22:20.878 Job Notification: New process added to job (1660) 2026-05-16T06:22:20.878 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-16T06:22:20.878 Job Notification: New process added to job (5884) 2026-05-16T06:22:20.893 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:1660] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5884]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:22:25.659 Job Notification: Process exited from job (1660) 2026-05-16T06:22:25.675 Job Notification: Process exited from job (5884) 2026-05-16T06:22:25.753 Job Notification: Process exited from job (4728) 2026-05-16T06:22:25.753 Job Notification: Process exited from job (3824) 2026-05-16T06:22:33.623 Engine:Process 4704 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-05-16T06:23:15.237 Process scan (postsignatureupdatescan) started. 2026-05-16T06:23:33.333 Process scan (postsignatureupdatescan) completed. -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-16-2026 06:26:39 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/16/2026 06:26:39.865847200 UTC (14578 ms since boot) 2026-05-16T06:26:39.872 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-16T06:26:39.872 WARNING: the previous service shutdown was not expected. 2026-05-16T06:26:39.872 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:26:39.872 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:26:39.981 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260516-062639-00000003-fffffffeffffffff.bin ... 2026-05-16T06:26:40.059 [WPP] Trace session started - MpWppTracing-20260516-062639-00000003-fffffffeffffffff.bin 2026-05-16T06:26:40.059 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-16T06:26:40.059 [RbM] Rollback manager succesfully initialized. 2026-05-16T06:26:40.059 [RbM] Rollback manager EnableRollbackManager called. 2026-05-16T06:26:40.075 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-16T06:26:40.090 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-16T06:26:40.090 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-16T06:26:40.090 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-16T06:26:40.090 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-16T06:26:40.090 MdCoreSvc is supported in this platform and OS 2026-05-16T06:26:40.090 MdCoreSvc is supported in this platform and OS 2026-05-16T06:26:40.090 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T06:26:40.090 [PlatUpd] Starting MdCoreSvc service 2026-05-16T06:26:40.122 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-16T06:26:44.096 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-16T06:26:44.096 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-16T06:26:44.096 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-16T06:26:44.096 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-16T06:26:44.096 [PlatUpd] CSP platform update started 2026-05-16T06:26:44.096 [PlatUpd] Defender MDM CSP platform update not required 2026-05-16T06:26:44.096 [PlatUpd] WMI/PS provider platform update started 2026-05-16T06:26:44.096 [PlatUpd] WMI/PS provider platform update not required 2026-05-16T06:26:44.096 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-16T06:26:44.096 MdCoreSvc is supported in this platform and OS 2026-05-16T06:26:44.096 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T06:26:44.096 [PlatUpd] Starting MdCoreSvc service 2026-05-16T06:26:44.096 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-16T06:26:44.096 [TS] Troubleshooting mode is not available! 2026-05-16T06:26:44.096 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T06:26:44.096 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-16T06:26:44.112 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-16T06:26:44.112 [Service] Enabling AutoLoggers ... 2026-05-16T06:26:44.112 [Service] Enabling AMSI registration ... 2026-05-16T06:26:44.112 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-16T06:26:44.128 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43218 Number of invalid entries is 0 Number of inserts issued is 1584673 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6517 Number of lookups is 108295388 Number of lookup misses is 5198479 Number of fast lookup misses is 55185315 Number of false fast lookups is 5198474 Number of invalidations is 734939 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-16T06:26:44.128 Verifying license file... 2026-05-16T06:26:44.128 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-16T06:26:44.143 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-16T06:26:44.143 Loaded module#0 MpComServer. 2026-05-16T06:26:44.143 Loaded module#1 StartupPolicies. 2026-05-16T06:26:44.143 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T06:26:44.159 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T06:26:44.159 COM server initialized successfully. 2026-05-16T06:26:44.159 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-16T06:26:44.175 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-16T06:26:44.175 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-16T06:26:44.190 [RTP] [RTP] FilterCommunicator object 0x0000019D32E9F450 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T06:26:44.206 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-16T06:26:44.206 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T06:26:44.206 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T06:26:44.206 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-16T06:26:44.206 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-16T06:26:44.206 [RTP] [RTP] FilterCommunicator object 0x0000019D32E9F660 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T06:26:44.206 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-16T06:26:44.206 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-16T06:26:44.206 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-16T06:26:44.206 [RTP] [RTP] StartCommunication 0x0000019D32E9F450 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T06:26:44.206 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-16T06:26:44.206 [init][RTP] RTPPlugin initialization completed 2026-05-16T06:26:44.206 OS boot count = 2 2026-05-16T06:26:44.206 OS Install = 0 2026-05-16T06:26:44.221 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-16T06:26:44.221 [KSL] Entering CKSLEngine::Initialize. 2026-05-16T06:26:44.221 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-16T06:26:44.221 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-16T06:26:44.221 [KSL] MpInstallKslD: hr=0x1 2026-05-16T06:26:44.221 [KSL] MpRegisterKslD: hr=0 2026-05-16T06:26:44.237 [KSL] MpStartKslD: hr=0 2026-05-16T06:26:44.237 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T06:26:44.237 Loading engine... 2026-05-16T06:26:44.253 Verifying engine and signature files (source: 1) ... 2026-05-16T06:26:44.253 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpengine.dll] due to PPL. 2026-05-16T06:26:44.253 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm]. File not in cache (0x1) 2026-05-16T06:26:45.206 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm] 2026-05-16T06:26:45.206 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasdlta.vdm] (file in cache) 2026-05-16T06:26:45.206 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm]. File not in cache (0x1) 2026-05-16T06:26:45.628 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm] 2026-05-16T06:26:45.628 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavdlta.vdm] (file in cache) 2026-05-16T06:26:45.675 [Engine] IsHybridMode: 0 2026-05-16T06:26:45.675 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-16T06:26:45.690 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-BD6F815C8D130F9E9724667CC5D868F55032F114.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-16T06:26:49.503 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-16T06:26:49.503 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-16T06:26:49.503 [Engine] New active engine 00007FFB49E75810 (no old engine). Number of active engines: 1 2026-05-16T06:26:49.518 EngineInit:Global ASOC is enabled 2026-05-16T06:26:49.518 EngineInit:ASOO is enabled for developer volumes 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.596 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T06:26:49.612 MpWriteUupSignatureVersion 1.449.642.0, hr = 0 2026-05-16T06:26:49.612 [SigStatUpd] CSignatureStatus: back to good 2026-05-16T06:26:49.612 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-16T06:26:49.628 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-16T06:26:49.628 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T06:26:49.628 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-16T06:26:49.628 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-16T06:26:49.628 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T06:26:49.643 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-16T06:26:49.643 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2182 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12483 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2468 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-16T06:26:49.643 [Plugin] Initializing RTP plugin state... 2026-05-16T06:26:49.643 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-16T06:26:49.643 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8} 2026-05-16T06:26:49.643 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:26:49.643 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:26:49.643 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T06:26:49.643 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T06:26:49.643 MdCoreSvc is supported in this platform and OS 2026-05-16T06:26:49.643 Engine loaded! 2026-05-16T06:26:49.643 [DLP] Create FeatureControlState instance 2026-05-16T06:26:49.659 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-16T06:26:49.659 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-16T06:26:49.659 RegisterSModeChangeListener: hr = 0x1 2026-05-16T06:26:49.659 RegisterHybridModeChangeListener: hr = 0 2026-05-16T06:26:49.675 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-16T06:26:49.675 [SigReleaseHb] Initialized with Stage 0 2026-05-16T06:26:49.675 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-16T06:26:49.675 [SCC][CID=24390_5608] Initializing ... 2026-05-16T06:26:49.675 [SCC][CID=24390_5608] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-16T06:26:49.675 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-16T06:26:49.675 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-16T06:26:49.675 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T06:26:49.675 [NRI] Stopping NIS service ... 2026-05-16T06:26:49.675 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-16T06:26:49.675 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.642.0 AV Signature Version: 1.449.642.0 ************************************************************ 2026-05-16T06:26:49.675 Resource usage Monitoring is enabled 2026-05-16T06:26:49.675 Job Notification: New process added to job (4532) 2026-05-16T06:26:49.675 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-16T06:26:49.721 Job Notification: New process added to job (8136) 2026-05-16T06:26:49.721 Job Notification: New process added to job (8144) 2026-05-16T06:26:49.721 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8136] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8144]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:26:49.753 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-16T06:26:49.753 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T06:26:49.753 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T06:26:49.753 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T06:26:49.753 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T06:26:49.753 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T06:26:49.753 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T06:26:49.753 [RTP] Generating the base plugin configuration ... 2026-05-16T06:26:49.753 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-16T06:26:49.753 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:26:49.768 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-16T06:26:49.768 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-16T06:26:49.768 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T06:26:49.768 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-16T06:26:49.768 [RTP] [RTP] StartCommunication 0x0000019D32E9F660 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T06:26:49.768 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-16T06:26:49.784 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-16T06:26:49.815 Job Notification: Process exited from job (8136) 2026-05-16T06:26:49.831 Job Notification: Process exited from job (8144) 2026-05-16T06:26:49.831 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-16T06:26:50.096 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:26:50.112 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-16T06:26:50.112 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-16T06:26:50.112 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T06:26:52.659 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:26:52.659 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:26:52.659 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-16T06:26:52.659 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-16T06:26:52.659 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-16T06:27:33.003 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2808, FileId: 0x1a0000000a7d7f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:27:44.175 Process scan (poststartupscan) started. 2026-05-16T06:27:44.175 Process scan (poststartupscan) completed. 2026-05-16T06:27:44.659 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-16T06:27:44.675 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-16T06:27:47.248 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:27:47.248 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:27:47.248 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-16T06:27:47.249 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-16T06:27:47.249 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-16T06:28:42.893 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:28:42.893 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T06:28:42.893 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T06:31:49.538 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-16T06:31:49.680 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T06:32:01.784 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4339, FileId: 0x67000000013039, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:36:44.034 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5147, FileId: 0x2a0000000a7aa7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:36:49.680 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-16T06:36:49.680 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-16T06:36:49.696 Job Notification: New process added to job (2848) 2026-05-16T06:36:49.696 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-16T06:36:49.711 Job Notification: New process added to job (2552) 2026-05-16T06:36:49.722 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:2848] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:2552]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:36:49.759 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 74646103(ms) from now at 05:20 (03:20 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-16T06:36:49.806 Job Notification: New process added to job (12648) 2026-05-16T06:36:49.806 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-16T06:36:49.815 Job Notification: New process added to job (3084) 2026-05-16T06:36:49.822 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:12648] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3084]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T06:36:55.315 Job Notification: Process exited from job (12648) 2026-05-16T06:36:55.315 Job Notification: Process exited from job (3084) 2026-05-16T06:36:55.393 Job Notification: Process exited from job (2848) 2026-05-16T06:36:55.393 Job Notification: Process exited from job (2552) 2026-05-16T06:39:00.956 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjADB6E0965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5580, FileId: 0x1f0000000a7b00, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:00.971 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE065699F3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5582, FileId: 0x200000000a7b00, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.003 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFB96AD9CD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5585, FileId: 0xbe0000000131e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.050 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26D02E9C9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5589, FileId: 0x2c0000000a7b0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.081 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj13288F9EF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5593, FileId: 0x1f0000000a7d7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.283 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEC4EAD907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5609, FileId: 0xc90000000131e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.381 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1E1D2F97D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5613, FileId: 0x300000000a7b0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.391 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5A6953995. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5623, FileId: 0x390000000ab5c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.409 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD3B8B0971. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5625, FileId: 0x3a0000000ab5c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:01.438 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEF26139AD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5650, FileId: 0x36000000010aab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:02.065 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7D18849C1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5683, FileId: 0x3b0000000ab5c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:15.628 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5828, FileId: 0x830000000033d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:15.706 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5830, FileId: 0x210000000a7ace, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:39:15.784 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5836, FileId: 0x160000000a7af0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:40:15.893 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #5840, FileId: 0x890000000033d2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:42:03.612 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #5903, FileId: 0x48f00000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:42:57.682 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-05-16T06:42:57.682 [RTP] Duplicating the current plugin configuration object... 2026-05-16T06:42:57.682 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T06:42:57.682 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-16T06:42:57.682 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-16T06:42:57.682 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-16T06:42:57.682 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-16T06:42:57.920 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #5960, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b 2026-05-16T06:43:00.940 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:00.940 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:00.940 [Cloud] Queued cloud request. 2026-05-16T06:43:00.940 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:00.940 [Cloud] Dequeued cloud request. 2026-05-16T06:43:00.940 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.315 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd91e5fe4299ba54a9432f2e69927aa846fea511 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:00 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:01.315 [Cloud] End of cloud request. 2026-05-16T06:43:01.315 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a 2026-05-16T06:43:01.503 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:01.503 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:01.503 [Cloud] Queued cloud request. 2026-05-16T06:43:01.503 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:01.503 [Cloud] Dequeued cloud request. 2026-05-16T06:43:01.503 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.503 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:01.503 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:01.503 [Cloud] Queued cloud request. 2026-05-16T06:43:01.503 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:01.503 [Cloud] Dequeued cloud request. 2026-05-16T06:43:01.503 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.518 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:01.518 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:01.518 [Cloud] Queued cloud request. 2026-05-16T06:43:01.518 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:01.518 [Cloud] Dequeued cloud request. 2026-05-16T06:43:01.518 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.659 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\00017441-AC50-27C2-2060-FC2582E80200-0.bin loaded. 2026-05-16T06:43:01.800 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\baf17a4aede642cb6dd2256c8b0657e5845d56d1 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:01.800 [Cloud] End of cloud request. 2026-05-16T06:43:01.800 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 2026-05-16T06:43:01.831 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:01.846 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:01.846 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:01.846 [Cloud] Queued cloud request. 2026-05-16T06:43:01.846 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:01.846 [Cloud] Dequeued cloud request. 2026-05-16T06:43:01.846 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.846 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f2c1fc2a1073e0bf26a61faa87b5d7181f5def8c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:01.846 [Cloud] End of cloud request. 2026-05-16T06:43:01.846 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 2026-05-16T06:43:01.909 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:01.909 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:01.909 [Cloud] Queued cloud request. 2026-05-16T06:43:01.909 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:01.909 [Cloud] Dequeued cloud request. 2026-05-16T06:43:01.909 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:01.909 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\439178085b624c5e54867bde062bbc3e3ce8cd0e Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:01.909 [Cloud] End of cloud request. 2026-05-16T06:43:01.909 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:02.050 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\233d6ba43f2cb8bef94f3a41a0d977d472d094ee Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:02.050 [Cloud] End of cloud request. 2026-05-16T06:43:02.050 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:02.096 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3859d201b1c1e0d6bfbc197804e605f65296fd29 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:02.096 [Cloud] End of cloud request. 2026-05-16T06:43:02.096 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:02.346 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e 2026-05-16T06:43:02.925 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:02.925 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:02.925 [Cloud] Queued cloud request. 2026-05-16T06:43:02.925 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:02.925 [Cloud] Dequeued cloud request. 2026-05-16T06:43:02.925 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:03.206 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ae8acacca1d3993cd1ad462fe4f53996047b412 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:02 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:03.206 [Cloud] End of cloud request. 2026-05-16T06:43:03.206 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc 2026-05-16T06:43:03.237 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:03.237 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:03.237 [Cloud] Queued cloud request. 2026-05-16T06:43:03.237 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:03.237 [Cloud] Dequeued cloud request. 2026-05-16T06:43:03.237 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\de7ed5cf55070c6d5038783333e6c20b9b597a00 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:03.456 [Cloud] End of cloud request. 2026-05-16T06:43:03.456 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf 2026-05-16T06:43:03.518 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:03.518 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:03.518 [Cloud] Queued cloud request. 2026-05-16T06:43:03.518 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:03.518 [Cloud] Dequeued cloud request. 2026-05-16T06:43:03.518 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:03.706 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7f7ae3dc73490b5e25874d40c3d18bd081f17b8b Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:03.862 [Cloud] End of cloud request. 2026-05-16T06:43:03.862 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a 2026-05-16T06:43:03.909 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:03.909 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:03.909 [Cloud] Queued cloud request. 2026-05-16T06:43:03.909 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:03.909 [Cloud] Dequeued cloud request. 2026-05-16T06:43:03.909 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f252b0ec7a55a3e634c5f961897edda727f584b8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:04.112 [Cloud] End of cloud request. 2026-05-16T06:43:04.112 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab 2026-05-16T06:43:04.159 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:04.159 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:04.159 [Cloud] Queued cloud request. 2026-05-16T06:43:04.159 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:04.159 [Cloud] Dequeued cloud request. 2026-05-16T06:43:04.159 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4e97ae12a8c229dafebb1b7dfe48d53ee5fa165c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:04.331 [Cloud] End of cloud request. 2026-05-16T06:43:04.331 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc 2026-05-16T06:43:04.362 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:04.393 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:04.393 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:04.393 [Cloud] Queued cloud request. 2026-05-16T06:43:04.393 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:04.393 [Cloud] Dequeued cloud request. 2026-05-16T06:43:04.393 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\887ebddc08fde48f75ccd18c5f2a1e2bd6f0e3ab Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:04.628 [Cloud] End of cloud request. 2026-05-16T06:43:04.628 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 2026-05-16T06:43:04.675 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:04.675 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:04.675 [Cloud] Queued cloud request. 2026-05-16T06:43:04.675 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:04.675 [Cloud] Dequeued cloud request. 2026-05-16T06:43:04.675 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:04.800 Dynamic signature received 2026-05-16T06:43:04.862 Dynamic signature received 2026-05-16T06:43:04.862 Dynamic signature received 2026-05-16T06:43:04.862 Dynamic signature received 2026-05-16T06:43:04.862 Dynamic signature received 2026-05-16T06:43:04.893 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9c9c3c2df6ff2d9a1b369cc2f1eece8f8b6c5536 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:04.893 [Cloud] End of cloud request. 2026-05-16T06:43:04.893 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 2026-05-16T06:43:04.940 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:04.940 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:04.940 [Cloud] Queued cloud request. 2026-05-16T06:43:04.940 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:04.940 [Cloud] Dequeued cloud request. 2026-05-16T06:43:04.940 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:05.128 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:05.284 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b39ac7205431bf28c87dacdbe0bdf7077c17623 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:05.284 [Cloud] End of cloud request. 2026-05-16T06:43:05.284 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 2026-05-16T06:43:05.315 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:05.315 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:05.315 [Cloud] Queued cloud request. 2026-05-16T06:43:05.315 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:05.315 [Cloud] Dequeued cloud request. 2026-05-16T06:43:05.331 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\648c5f30d105dafad4dcaf54a386f45d0aa86930 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:05.581 Dynamic signature received 2026-05-16T06:43:05.581 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:05.581 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a 2026-05-16T06:43:05.612 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:05.612 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:05.612 [Cloud] Queued cloud request. 2026-05-16T06:43:05.612 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:05.612 [Cloud] Dequeued cloud request. 2026-05-16T06:43:05.612 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:05.800 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:05.815 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3dd10c3991096904f91d93ed4d6bca278a19e869 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:05.815 [Cloud] End of cloud request. 2026-05-16T06:43:05.815 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f 2026-05-16T06:43:05.847 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:05.847 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:05.847 [Cloud] Queued cloud request. 2026-05-16T06:43:05.847 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:05.847 [Cloud] Dequeued cloud request. 2026-05-16T06:43:05.847 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d7bd50ef2215dbd71aaf1ab6b688c1c04ad061c3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:06.097 Dynamic signature received 2026-05-16T06:43:06.097 [Cloud] End of cloud request. 2026-05-16T06:43:06.097 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed 2026-05-16T06:43:06.128 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:06.128 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:06.128 [Cloud] Queued cloud request. 2026-05-16T06:43:06.128 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:06.128 [Cloud] Dequeued cloud request. 2026-05-16T06:43:06.128 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:06.315 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:06.347 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\19618574d921a1a092498426de2bb62104333c01 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:06.347 [Cloud] End of cloud request. 2026-05-16T06:43:06.347 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c 2026-05-16T06:43:06.394 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:06.394 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:06.394 [Cloud] Queued cloud request. 2026-05-16T06:43:06.394 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:06.394 [Cloud] Dequeued cloud request. 2026-05-16T06:43:06.394 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:06.597 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\42f43cf8819518049f1cc853cbebac650a6b9f5d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:06.597 [Cloud] End of cloud request. 2026-05-16T06:43:06.597 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 2026-05-16T06:43:06.644 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:06.644 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:06.644 [Cloud] Queued cloud request. 2026-05-16T06:43:06.644 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:06.644 [Cloud] Dequeued cloud request. 2026-05-16T06:43:06.644 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:06.847 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:06.862 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d4fd0c988d115c82dbacfa3af3c1704719c53956 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:06.862 [Cloud] End of cloud request. 2026-05-16T06:43:06.862 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 2026-05-16T06:43:06.909 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:06.909 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:06.909 [Cloud] Queued cloud request. 2026-05-16T06:43:06.909 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:06.909 [Cloud] Dequeued cloud request. 2026-05-16T06:43:06.909 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:07.097 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7a58e9532447b8c4a745e4dd6e05a3b009756db7 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:07.097 [Cloud] End of cloud request. 2026-05-16T06:43:07.097 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce 2026-05-16T06:43:07.144 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:07.144 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:07.144 [Cloud] Queued cloud request. 2026-05-16T06:43:07.144 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:07.144 [Cloud] Dequeued cloud request. 2026-05-16T06:43:07.144 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\332421f2f0d8ad9450954ab9bd4eaeae373eb3e3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:07.378 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:07.425 Dynamic signature received 2026-05-16T06:43:07.425 [Cloud] End of cloud request. 2026-05-16T06:43:07.425 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 2026-05-16T06:43:07.472 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:07.472 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:07.472 [Cloud] Queued cloud request. 2026-05-16T06:43:07.472 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:07.472 [Cloud] Dequeued cloud request. 2026-05-16T06:43:07.503 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:07.706 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a0854df48684365aff7c663aba86adf2ea2e6975 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:07.706 [Cloud] End of cloud request. 2026-05-16T06:43:07.706 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c 2026-05-16T06:43:07.753 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:07.753 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:07.753 [Cloud] Queued cloud request. 2026-05-16T06:43:07.753 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:07.753 [Cloud] Dequeued cloud request. 2026-05-16T06:43:07.753 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:07.972 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\01e3c74539adc811914eff0546db4605527c5e52 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:07.972 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:07.972 [Cloud] End of cloud request. 2026-05-16T06:43:07.972 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 2026-05-16T06:43:08.019 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:08.019 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:08.019 [Cloud] Queued cloud request. 2026-05-16T06:43:08.019 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:08.019 [Cloud] Dequeued cloud request. 2026-05-16T06:43:08.019 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:08.206 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdc5670e00bbb44bb00785362421ce84dc2e6110 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:08.206 [Cloud] End of cloud request. 2026-05-16T06:43:08.206 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb 2026-05-16T06:43:08.253 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:08.253 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:08.253 [Cloud] Queued cloud request. 2026-05-16T06:43:08.253 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:08.253 [Cloud] Dequeued cloud request. 2026-05-16T06:43:08.253 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:08.425 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3e1dd65c7eedbcf2b5e9b1800333b080b4743bd9 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:08.425 [Cloud] End of cloud request. 2026-05-16T06:43:08.425 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 2026-05-16T06:43:08.472 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:08.472 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:08.472 [Cloud] Queued cloud request. 2026-05-16T06:43:08.472 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:08.472 [Cloud] Dequeued cloud request. 2026-05-16T06:43:08.472 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:08.487 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:08.659 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3272a0284544e020eaa214f605f1272bc6a29a5d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:08.659 [Cloud] End of cloud request. 2026-05-16T06:43:08.659 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 2026-05-16T06:43:08.706 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:08.706 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:08.706 [Cloud] Queued cloud request. 2026-05-16T06:43:08.706 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:08.706 [Cloud] Dequeued cloud request. 2026-05-16T06:43:08.706 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:08.878 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a643dcdd5a2e5c0e1c530e11c6ef7cf9761c19d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:08.878 [Cloud] End of cloud request. 2026-05-16T06:43:08.878 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 2026-05-16T06:43:08.925 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:08.925 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:08.925 [Cloud] Queued cloud request. 2026-05-16T06:43:08.925 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:08.925 [Cloud] Dequeued cloud request. 2026-05-16T06:43:08.925 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:09.128 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82c57a44716437dc610d58aaeeee696a632a8810 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:09.128 [Cloud] End of cloud request. 2026-05-16T06:43:09.128 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 2026-05-16T06:43:09.175 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:09.175 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:09.175 [Cloud] Queued cloud request. 2026-05-16T06:43:09.175 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:09.175 [Cloud] Dequeued cloud request. 2026-05-16T06:43:09.175 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:09.175 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:09.394 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ebba7d5912dcb78ae35ea9734ee49632d3178b56 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:09.394 [Cloud] End of cloud request. 2026-05-16T06:43:09.394 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 2026-05-16T06:43:09.440 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:09.440 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:09.440 [Cloud] Queued cloud request. 2026-05-16T06:43:09.440 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:09.440 [Cloud] Dequeued cloud request. 2026-05-16T06:43:09.440 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:09.737 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3b89f06cd8ec26c460e54922387a1b2f44388f43 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:09.737 [Cloud] End of cloud request. 2026-05-16T06:43:09.737 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd 2026-05-16T06:43:09.784 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:09.784 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:09.784 [Cloud] Queued cloud request. 2026-05-16T06:43:09.784 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:09.784 [Cloud] Dequeued cloud request. 2026-05-16T06:43:09.784 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:09.909 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:09.971 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3ddf4f2caecc51af05071d2946169b0c33625670 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:150196224 2026-05-16T06:43:09.971 [Cloud] End of cloud request. 2026-05-16T06:43:09.971 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b 2026-05-16T06:43:10.018 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:10.018 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:10.018 [Cloud] Queued cloud request. 2026-05-16T06:43:10.018 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:10.018 [Cloud] Dequeued cloud request. 2026-05-16T06:43:10.018 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:10.315 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\923314b132dd3e515ce3e86f72cf5bfadfe5e210 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:10.315 [Cloud] End of cloud request. 2026-05-16T06:43:10.315 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 2026-05-16T06:43:10.362 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:10.362 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:10.362 [Cloud] Queued cloud request. 2026-05-16T06:43:10.362 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:10.362 [Cloud] Dequeued cloud request. 2026-05-16T06:43:10.362 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:10.471 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:10.550 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87a9c1781effb536e60c1e5f736f3cb673486119 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:10.550 [Cloud] End of cloud request. 2026-05-16T06:43:10.550 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 2026-05-16T06:43:10.596 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:10.596 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:10.596 [Cloud] Queued cloud request. 2026-05-16T06:43:10.596 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:10.596 [Cloud] Dequeued cloud request. 2026-05-16T06:43:10.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:10.784 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ff3fe48af8fad5ffc063e3dcfb28274868808cf Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:10.784 [Cloud] End of cloud request. 2026-05-16T06:43:10.784 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 2026-05-16T06:43:10.831 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:10.831 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:10.831 [Cloud] Queued cloud request. 2026-05-16T06:43:10.831 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:10.831 [Cloud] Dequeued cloud request. 2026-05-16T06:43:10.831 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:11.034 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9acd6f44d0a5dc27b7e9545c2c0b44de61dfec8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:11.034 [Cloud] End of cloud request. 2026-05-16T06:43:11.034 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e 2026-05-16T06:43:11.065 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:11.081 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:11.081 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:11.081 [Cloud] Queued cloud request. 2026-05-16T06:43:11.081 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:11.081 [Cloud] Dequeued cloud request. 2026-05-16T06:43:11.081 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79ace9039cac84724e766e24baa16bf9d10f1eb8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:11.273 Dynamic signature received 2026-05-16T06:43:11.273 [Cloud] End of cloud request. 2026-05-16T06:43:11.273 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb 2026-05-16T06:43:11.304 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:11.304 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:11.304 [Cloud] Queued cloud request. 2026-05-16T06:43:11.304 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:11.304 [Cloud] Dequeued cloud request. 2026-05-16T06:43:11.304 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:11.554 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe4cc0c4301471b4465b29afc49e3d3ba5c63c87 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:11.554 [Cloud] End of cloud request. 2026-05-16T06:43:11.554 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b 2026-05-16T06:43:11.601 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:11.601 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:11.601 [Cloud] Queued cloud request. 2026-05-16T06:43:11.601 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:11.601 [Cloud] Dequeued cloud request. 2026-05-16T06:43:11.601 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:11.773 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:11.773 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6dca9bcf0ef624ddf2255ff80fa8b54e534f455a Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:11.773 [Cloud] End of cloud request. 2026-05-16T06:43:11.773 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 2026-05-16T06:43:11.851 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:11.851 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:11.851 [Cloud] Queued cloud request. 2026-05-16T06:43:11.851 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:11.851 [Cloud] Dequeued cloud request. 2026-05-16T06:43:11.851 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 2026-05-16T06:43:11.945 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:11.945 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:11.945 [Cloud] Queued cloud request. 2026-05-16T06:43:11.945 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:11.945 [Cloud] Dequeued cloud request. 2026-05-16T06:43:11.945 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:12.023 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fdfb84e8da3db2bfe48f9b33980922b3822e4879 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:12.038 [Cloud] End of cloud request. 2026-05-16T06:43:12.038 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:12.148 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\802bcf3ce5f81f45c4ac89457aa380f5ce2abbe7 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:12.148 [Cloud] End of cloud request. 2026-05-16T06:43:12.148 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d 2026-05-16T06:43:12.195 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:12.195 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:12.195 [Cloud] Queued cloud request. 2026-05-16T06:43:12.195 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:12.195 [Cloud] Dequeued cloud request. 2026-05-16T06:43:12.195 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:12.273 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:12.445 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\02f22476b69e010890690e660673f3a138e4c901 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:12.445 [Cloud] End of cloud request. 2026-05-16T06:43:12.445 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 2026-05-16T06:43:12.679 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:12.679 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:12.679 [Cloud] Queued cloud request. 2026-05-16T06:43:12.679 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:12.679 [Cloud] Dequeued cloud request. 2026-05-16T06:43:12.679 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:12.960 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:12.960 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b494fc5669fd2a4238dee0bb041dea6bffd7d43c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:12.960 [Cloud] End of cloud request. 2026-05-16T06:43:12.960 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 2026-05-16T06:43:13.038 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:13.038 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:13.038 [Cloud] Queued cloud request. 2026-05-16T06:43:13.038 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:13.038 [Cloud] Dequeued cloud request. 2026-05-16T06:43:13.038 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:13.335 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c7d32f91ea4f76af22148b7769a3181f7aeb01e3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:13.335 [Cloud] End of cloud request. 2026-05-16T06:43:13.335 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:13.476 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab 2026-05-16T06:43:13.570 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:13.570 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:13.570 [Cloud] Queued cloud request. 2026-05-16T06:43:13.570 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:13.570 [Cloud] Dequeued cloud request. 2026-05-16T06:43:13.570 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:13.570 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:13.570 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:13.570 [Cloud] Queued cloud request. 2026-05-16T06:43:13.570 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:13.570 [Cloud] Dequeued cloud request. 2026-05-16T06:43:13.570 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:13.757 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f4ab2a9c683ea934bdbee30bf053c22f7c770503 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:13 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:13.757 [Cloud] End of cloud request. 2026-05-16T06:43:13.757 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T06:43:13.804 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c925c2dd567e60bceda9a776410259afafb6b03b Dynamic Signature Compilation Timestamp:05-16-2026 06:43:13 Persistence Type:Duration Time remaining:50065408 2026-05-16T06:43:13.804 [Cloud] End of cloud request. 2026-05-16T06:43:13.804 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-16T06:43:14.263 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:43:14.389 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T06:43:14.389 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T06:43:14.389 [Cloud] Queued cloud request. 2026-05-16T06:43:14.389 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T06:43:14.389 [Cloud] Dequeued cloud request. 2026-05-16T06:43:14.389 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T06:43:14.842 [Cloud] End of cloud request. 2026-05-16T06:43:14.842 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll. status=0x40070000, statusex=0x200310, threatid=0x80000000, sigseq=0x294bdc606b459 2026-05-16T06:43:15.347 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T06:46:54.686 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T06:47:03.097 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6297, FileId: 0xf0000000b543a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:49:15.835 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6442, FileId: 0xe0000000b5441, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:49:15.851 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6444, FileId: 0x110000000b545a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T06:51:14.456 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\apache\conf\httpd.conf 2026-05-16T06:58:28.133 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7086, FileId: 0x4800000001ad32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:01:59.686 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T07:17:04.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T07:23:24.163 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7480, FileId: 0x130000000b545a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:32:09.680 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T07:34:47.300 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Windows\Prefetch\PARTITIONWIZARD.EXE-74ED46E5.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\PartitionWizard.exe, Status: 0xc000004b, State: 0, ScanRequest #7814, FileId: 0x2a000000003e33, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:34:55.440 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume1\EFI\Microsoft\Boot\BCD.LOG 2026-05-16T07:39:57.288 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8425, FileId: 0x1c0000000b5e8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:47:14.679 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T07:49:05.409 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8475, FileId: 0x4fe000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.425 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8479, FileId: 0x500000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.425 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8480, FileId: 0x4f000000035083, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.425 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8481, FileId: 0x501000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.440 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8478, FileId: 0x4ff000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.456 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8487, FileId: 0x506000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.456 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8484, FileId: 0x503000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.472 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8491, FileId: 0x58000000035083, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.472 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8488, FileId: 0x56000000035083, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.831 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8521, FileId: 0x50b000000000c6b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:49:05.831 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13cefe48-4eb4-4d9e-a22f-53b88832b374. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #8522, FileId: 0xd60000000051c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T07:54:24.309 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8654, FileId: 0x160000000b58cf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a956fa5 2026-05-16T07:59:03.737 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T07:59:03.737 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T07:59:03.737 [Cloud] Queued cloud request. 2026-05-16T07:59:03.737 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T07:59:03.737 [Cloud] Dequeued cloud request. 2026-05-16T07:59:03.737 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T07:59:04.224 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\68ac9d0249ce823d29f3185a38c4e5e7564dd6f0 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:03 Persistence Type:Duration Time remaining:150196224 2026-05-16T07:59:04.224 [Cloud] End of cloud request. 2026-05-16T07:59:04.224 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T07:59:04.732 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf4e7207d 2026-05-16T07:59:11.221 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T07:59:11.221 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T07:59:11.221 [Cloud] Queued cloud request. 2026-05-16T07:59:11.221 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T07:59:11.221 [Cloud] Dequeued cloud request. 2026-05-16T07:59:11.221 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T07:59:11.409 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5b7ddb888bf025d93152687d97e626b9cfa157a3 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:11 Persistence Type:Duration Time remaining:50065408 2026-05-16T07:59:11.409 [Cloud] End of cloud request. 2026-05-16T07:59:11.409 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T07:59:11.909 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf963f421 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2464dad5 2026-05-16T07:59:13.581 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T07:59:13.581 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T07:59:13.581 [Cloud] Queued cloud request. 2026-05-16T07:59:13.581 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T07:59:13.581 [Cloud] Dequeued cloud request. 2026-05-16T07:59:13.581 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T07:59:13.596 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T07:59:13.596 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T07:59:13.596 [Cloud] Queued cloud request. 2026-05-16T07:59:13.596 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T07:59:13.596 [Cloud] Dequeued cloud request. 2026-05-16T07:59:13.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T07:59:13.768 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c9573f5cb16454f17257b40a9abfec5178e7afd0 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:13 Persistence Type:Duration Time remaining:50065408 2026-05-16T07:59:13.768 [Cloud] End of cloud request. 2026-05-16T07:59:13.768 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T07:59:13.847 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f7d89f2f2877df2502e3e3b5a5c8ab947d4961a1 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:13 Persistence Type:Duration Time remaining:50065408 2026-05-16T07:59:13.847 [Cloud] End of cloud request. 2026-05-16T07:59:13.847 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T07:59:14.268 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8d908f31 2026-05-16T07:59:39.597 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T07:59:39.597 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T07:59:39.597 [Cloud] Queued cloud request. 2026-05-16T07:59:39.597 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T07:59:39.597 [Cloud] Dequeued cloud request. 2026-05-16T07:59:39.597 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T07:59:39.878 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd8d945fdcaffea21960875672f66b7f7301a7fd Dynamic Signature Compilation Timestamp:05-16-2026 07:59:39 Persistence Type:Duration Time remaining:50065408 2026-05-16T07:59:39.878 [Cloud] End of cloud request. 2026-05-16T07:59:39.878 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T07:59:40.378 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T08:02:19.679 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T08:10:09.315 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9446, FileId: 0x100000000b62e4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T08:17:24.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T08:17:38.425 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9515, FileId: 0x130000000b62e5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T08:26:49.504 ProcessImageName: httpd.exe, Pid: 3916, TotalTime: 11635, Count: 675, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume5\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 7% 2026-05-16T08:26:49.504 ProcessImageName: explorer.exe, Pid: 8516, TotalTime: 7409, Count: 226, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: AcroCEF.exe, Pid: 5428, TotalTime: 3187, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-16T08:26:49.504 ProcessImageName: AsPowerBar.exe, Pid: 11768, TotalTime: 2912, Count: 18, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 18% 2026-05-16T08:26:49.504 ProcessImageName: httpd.exe, Pid: 5528, TotalTime: 2715, Count: 77, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 20% 2026-05-16T08:26:49.504 ProcessImageName: DipAwayMode.exe, Pid: 6540, TotalTime: 2259, Count: 17, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: MOM.exe, Pid: 6020, TotalTime: 1931, Count: 29, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 80% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 2264, TotalTime: 1812, Count: 2, MaxTime: 953, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100% 2026-05-16T08:26:49.504 ProcessImageName: xampp-control.exe, Pid: 5712, TotalTime: 1745, Count: 11, MaxTime: 1406, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: PartitionWizard.exe, Pid: 10472, TotalTime: 1480, Count: 14, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 18% 2026-05-16T08:26:49.504 ProcessImageName: dllhost.exe, Pid: 10748, TotalTime: 1462, Count: 51, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\IYXYHJB3M0_10, EstimatedImpact: 20% 2026-05-16T08:26:49.504 ProcessImageName: AISuite3.exe, Pid: 6508, TotalTime: 1444, Count: 22, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 15% 2026-05-16T08:26:49.504 ProcessImageName: mysqld.exe, Pid: 2660, TotalTime: 1036, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: websockify.exe, Pid: 6076, TotalTime: 834, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 62% 2026-05-16T08:26:49.504 ProcessImageName: notepad++.exe, Pid: 6160, TotalTime: 766, Count: 58, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: firefox.exe, Pid: 13136, TotalTime: 541, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa08576, EstimatedImpact: 41% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 4176, TotalTime: 421, Count: 2, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AsSysCtrlService\1.00.25\AsSysCtrlService.exe, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: TeamViewer.exe, Pid: 8048, TotalTime: 394, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 4% 2026-05-16T08:26:49.504 ProcessImageName: WhatsApp.Root.exe, Pid: 10592, TotalTime: 285, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: httpd.exe, Pid: 6260, TotalTime: 215, Count: 11, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 35% 2026-05-16T08:26:49.504 ProcessImageName: FileCoAuth.exe, Pid: 12168, TotalTime: 181, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-16.0627.12168.1.aodl, EstimatedImpact: 2% 2026-05-16T08:26:49.504 ProcessImageName: Notepad.exe, Pid: 5720, TotalTime: 180, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: AdobeCollabSync.exe, Pid: 3292, TotalTime: 165, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-16.log, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: TabTip.exe, Pid: 4616, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: GUP.exe, Pid: 2944, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\gup.xml, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: PhoneExperienceHost.exe, Pid: 12080, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: mysqld.exe, Pid: 9284, TotalTime: 121, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: Acrobat.exe, Pid: 2736, TotalTime: 121, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 10% 2026-05-16T08:26:49.504 ProcessImageName: backgroundTaskHost.exe, Pid: 8432, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-16T08:26:49.504 ProcessImageName: SDXHelper.exe, Pid: 6468, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: notepad++.exe, Pid: 9952, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\autoCompletion\php.xml, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: taskhostw.exe, Pid: 8052, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 44% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 3652, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpengine.dll, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: TabTip.exe, Pid: 9016, TotalTime: 77, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% 2026-05-16T08:26:49.504 ProcessImageName: TabTip.exe, Pid: 9064, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 70% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 5728, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\B25435C5-697D-486A-A0E8-A429822004B5, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: SDXHelper.exe, Pid: 12152, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-05-16T08:26:49.504 ProcessImageName: AcroCEF.exe, Pid: 5804, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_1, EstimatedImpact: 20% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 2052, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 8152, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: mysqld.exe, Pid: 2556, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: runonce.exe, Pid: 7716, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 4% 2026-05-16T08:26:49.504 ProcessImageName: notepad++.exe, Pid: 6988, TotalTime: 46, Count: 27, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\extra\httpd-xampp.conf, EstimatedImpact: 2% 2026-05-16T08:26:49.504 ProcessImageName: , Pid: 4, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdspio.sys, EstimatedImpact: 42% 2026-05-16T08:26:49.504 ProcessImageName: dllhost.exe, Pid: 4896, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: httpd.exe, Pid: 4336, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\phpinfo.php, EstimatedImpact: 5% 2026-05-16T08:26:49.504 ProcessImageName: backgroundTaskHost.exe, Pid: 7988, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1->(UTF-8), EstimatedImpact: 6% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 4184, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OneDriveLauncher.exe, Pid: 1600, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 2% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 6028, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0858.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 4988, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0923.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OpenWith.exe, Pid: 12744, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: Acrobat.exe, Pid: 5592, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-16T08:26:49.504 ProcessImageName: mysqld.exe, Pid: 3184, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 10032, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0847.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 6192, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1010.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 6644, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1017.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 9948, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0954.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 5308, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0939.log, EstimatedImpact: 1% 2026-05-16T08:26:49.504 ProcessImageName: AdobeARM.exe, Pid: 4832, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 5% 2026-05-16T08:26:49.504 ProcessImageName: TeamViewer_Service.exe, Pid: 4504, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: brynhildr.exe, Pid: 4152, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: AggregatorHost.exe, Pid: 5856, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: OfficeC2RClient.exe, Pid: 4004, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-0836.log, EstimatedImpact: 0% 2026-05-16T08:26:49.504 ProcessImageName: svchost.exe, Pid: 8180, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-16T08:32:29.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T08:45:19.722 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9692, FileId: 0x5900000002b44d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T08:47:34.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T08:56:46.597 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #9954, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T08:58:54.268 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Windows\Prefetch\PARTITIONWIZARD.EXE-74ED46E5.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\PartitionWizard.exe, Status: 0xc000004b, State: 0, ScanRequest #10213, FileId: 0x2a000000003e33, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x35abdb83 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf97ff7bf 2026-05-16T09:01:09.612 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T09:01:09.612 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T09:01:09.612 [Cloud] Queued cloud request. 2026-05-16T09:01:09.612 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T09:01:09.612 [Cloud] Dequeued cloud request. 2026-05-16T09:01:09.612 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T09:01:09.612 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T09:01:09.612 [Cloud] Queued cloud request. 2026-05-16T09:01:09.612 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T09:01:09.612 [Cloud] Dequeued cloud request. 2026-05-16T09:01:09.612 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T09:01:09.612 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T09:01:09.987 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\77e208217a7ab31d295fb9a3e0976a10c306254e Dynamic Signature Compilation Timestamp:05-16-2026 09:01:09 Persistence Type:Duration Time remaining:150196224 2026-05-16T09:01:09.987 [Cloud] End of cloud request. 2026-05-16T09:01:09.987 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T09:01:10.003 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8a99c4b09334d7de0bc016cded98b82d0b160594 Dynamic Signature Compilation Timestamp:05-16-2026 09:01:09 Persistence Type:Duration Time remaining:150196224 2026-05-16T09:01:10.003 [Cloud] End of cloud request. 2026-05-16T09:01:10.003 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T09:01:10.503 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T09:02:39.681 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T09:10:10.914 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11027, FileId: 0xd0000000b62ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T09:11:34.717 [RTP] [Mini-filter] OpenWithoutRead notification (1192, 10003, ) sent successfully. 2026-05-16T09:17:44.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T09:32:49.679 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T09:43:32.131 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13765, FileId: 0xa70000000097f3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T09:47:54.686 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T10:02:59.676 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T10:18:04.675 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T10:26:49.518 ProcessImageName: httpd.exe, Pid: 3916, TotalTime: 12376, Count: 730, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume5\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: explorer.exe, Pid: 8516, TotalTime: 7941, Count: 269, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: dllhost.exe, Pid: 10748, TotalTime: 4101, Count: 135, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\4IX6PHAP_505\3DCT987UUQ_12, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: AcroCEF.exe, Pid: 5428, TotalTime: 3187, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 26% 2026-05-16T10:26:49.518 ProcessImageName: AsPowerBar.exe, Pid: 11768, TotalTime: 2912, Count: 18, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 18% 2026-05-16T10:26:49.518 ProcessImageName: httpd.exe, Pid: 5528, TotalTime: 2715, Count: 77, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 20% 2026-05-16T10:26:49.518 ProcessImageName: DipAwayMode.exe, Pid: 6540, TotalTime: 2259, Count: 17, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: MOM.exe, Pid: 6020, TotalTime: 1931, Count: 29, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 80% 2026-05-16T10:26:49.518 ProcessImageName: svchost.exe, Pid: 2264, TotalTime: 1812, Count: 2, MaxTime: 953, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 100% 2026-05-16T10:26:49.518 ProcessImageName: xampp-control.exe, Pid: 5712, TotalTime: 1745, Count: 11, MaxTime: 1406, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: PartitionWizard.exe, Pid: 10472, TotalTime: 1480, Count: 14, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 18% 2026-05-16T10:26:49.518 ProcessImageName: AISuite3.exe, Pid: 6508, TotalTime: 1444, Count: 22, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 15% 2026-05-16T10:26:49.518 ProcessImageName: powershell.exe, Pid: 7160, TotalTime: 1330, Count: 46, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: mysqld.exe, Pid: 2660, TotalTime: 1036, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: websockify.exe, Pid: 6076, TotalTime: 834, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 62% 2026-05-16T10:26:49.518 ProcessImageName: notepad++.exe, Pid: 6160, TotalTime: 766, Count: 58, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: firefox.exe, Pid: 13136, TotalTime: 541, Count: 53, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa08576, EstimatedImpact: 41% 2026-05-16T10:26:49.518 ProcessImageName: WmiPrvSE.exe, Pid: 5780, TotalTime: 541, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 86% 2026-05-16T10:26:49.518 ProcessImageName: PDFXCview.exe, Pid: 6316, TotalTime: 510, Count: 74, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 43% 2026-05-16T10:26:49.518 ProcessImageName: httpd.exe, Pid: 12884, TotalTime: 468, Count: 33, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\phpMyAdmin\js\dist\server\databases.js, EstimatedImpact: 1% 2026-05-16T10:26:49.518 ProcessImageName: svchost.exe, Pid: 4176, TotalTime: 421, Count: 2, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AsSysCtrlService\1.00.25\AsSysCtrlService.exe, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: TeamViewer.exe, Pid: 8048, TotalTime: 394, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 4% 2026-05-16T10:26:49.518 ProcessImageName: WhatsApp.Root.exe, Pid: 10592, TotalTime: 285, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\Settings\settings.dat, EstimatedImpact: 1% 2026-05-16T10:26:49.518 ProcessImageName: httpd.exe, Pid: 6260, TotalTime: 215, Count: 11, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 35% 2026-05-16T10:26:49.518 ProcessImageName: mysqld.exe, Pid: 9284, TotalTime: 196, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: OpenWith.exe, Pid: 1752, TotalTime: 184, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7zG.exe, EstimatedImpact: 58% 2026-05-16T10:26:49.518 ProcessImageName: FileCoAuth.exe, Pid: 12168, TotalTime: 181, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-16.0627.12168.1.aodl, EstimatedImpact: 2% 2026-05-16T10:26:49.518 ProcessImageName: Notepad.exe, Pid: 5720, TotalTime: 180, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-39.pri, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: RuntimeBroker.exe, Pid: 10312, TotalTime: 169, Count: 5, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\python\PortablePython_3.9.2.0x64__WPy64-3920\WinPython Powershell Prompt.exe, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: AdobeCollabSync.exe, Pid: 3292, TotalTime: 165, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-16.log, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: TabTip.exe, Pid: 4616, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-16T10:26:49.518 ProcessImageName: svchost.exe, Pid: 1424, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: GUP.exe, Pid: 2944, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\gup.xml, EstimatedImpact: 3% 2026-05-16T10:26:49.518 ProcessImageName: PhoneExperienceHost.exe, Pid: 12080, TotalTime: 135, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: svchost.exe, Pid: 2384, TotalTime: 123, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: Notepad.exe, Pid: 6764, TotalTime: 121, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState\48f78677-7994-4996-9711-dcef2ee25ae4.bin, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: Acrobat.exe, Pid: 2736, TotalTime: 121, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 10% 2026-05-16T10:26:49.518 ProcessImageName: notepad++.exe, Pid: 9952, TotalTime: 120, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\autoCompletion\php.xml, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: backgroundTaskHost.exe, Pid: 8432, TotalTime: 120, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 7% 2026-05-16T10:26:49.518 ProcessImageName: , Pid: 4, TotalTime: 108, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\pwdspio.sys, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: mysqld.exe, Pid: 1744, TotalTime: 105, Count: 29, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: SecurityHealthHost.exe, Pid: 5464, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-16T10:26:49.518 ProcessImageName: SDXHelper.exe, Pid: 6468, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 3% 2026-05-16T10:26:49.518 ProcessImageName: taskhostw.exe, Pid: 8052, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 44% 2026-05-16T10:26:49.518 ProcessImageName: svchost.exe, Pid: 3652, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpengine.dll, EstimatedImpact: 0% 2026-05-16T10:26:49.518 ProcessImageName: TabTip.exe, Pid: 9064, TotalTime: 77, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 70% 2026-05-16T10:26:49.518 ProcessImageName: TabTip.exe, Pid: 9016, TotalTime: 77, Count: 2, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 37% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-16-2026 16:47:41 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/16/2026 16:47:41.4181800 UTC (13718 ms since boot) 2026-05-16T16:47:41.071 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-16T16:47:41.076 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T16:47:41.076 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T16:47:41.121 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260516-164741-00000003-fffffffeffffffff.bin ... 2026-05-16T16:47:41.216 [WPP] Trace session started - MpWppTracing-20260516-164741-00000003-fffffffeffffffff.bin 2026-05-16T16:47:41.216 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-16T16:47:41.221 [RbM] Rollback manager succesfully initialized. 2026-05-16T16:47:41.221 [RbM] Rollback manager EnableRollbackManager called. 2026-05-16T16:47:41.226 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-16T16:47:41.226 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-16T16:47:41.226 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-16T16:47:41.226 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-16T16:47:41.226 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-16T16:47:41.231 MdCoreSvc is supported in this platform and OS 2026-05-16T16:47:41.231 MdCoreSvc is supported in this platform and OS 2026-05-16T16:47:41.231 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T16:47:41.231 [PlatUpd] Starting MdCoreSvc service 2026-05-16T16:47:41.261 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-16T16:47:45.201 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-16T16:47:45.201 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-16T16:47:45.201 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-16T16:47:45.201 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-16T16:47:45.201 [PlatUpd] CSP platform update started 2026-05-16T16:47:45.201 [PlatUpd] Defender MDM CSP platform update not required 2026-05-16T16:47:45.201 [PlatUpd] WMI/PS provider platform update started 2026-05-16T16:47:45.201 [PlatUpd] WMI/PS provider platform update not required 2026-05-16T16:47:45.201 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-16T16:47:45.201 MdCoreSvc is supported in this platform and OS 2026-05-16T16:47:45.201 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-16T16:47:45.201 [PlatUpd] Starting MdCoreSvc service 2026-05-16T16:47:45.201 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-16T16:47:45.201 [TS] Troubleshooting mode is not available! 2026-05-16T16:47:45.201 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T16:47:45.201 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-16T16:47:45.232 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-16T16:47:45.232 [Service] Enabling AutoLoggers ... 2026-05-16T16:47:45.232 [Service] Enabling AMSI registration ... 2026-05-16T16:47:45.232 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-16T16:47:45.248 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43228 Number of invalid entries is 0 Number of inserts issued is 1584694 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6517 Number of lookups is 108331074 Number of lookup misses is 5199127 Number of fast lookup misses is 55196645 Number of false fast lookups is 5199122 Number of invalidations is 734950 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-16T16:47:45.248 Verifying license file... 2026-05-16T16:47:45.248 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-16T16:47:45.264 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-16T16:47:45.264 Loaded module#0 MpComServer. 2026-05-16T16:47:45.264 Loaded module#1 StartupPolicies. 2026-05-16T16:47:45.264 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-16T16:47:45.264 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T16:47:45.264 COM server initialized successfully. 2026-05-16T16:47:45.279 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-16T16:47:45.279 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-16T16:47:45.279 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-16T16:47:45.295 [RTP] [RTP] FilterCommunicator object 0x000001E9AF0652F0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T16:47:45.295 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-16T16:47:45.295 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T16:47:45.295 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T16:47:45.295 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-16T16:47:45.295 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-16T16:47:45.310 [RTP] [RTP] FilterCommunicator object 0x000001E9AF0A3C10 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T16:47:45.310 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-16T16:47:45.310 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-16T16:47:45.310 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-16T16:47:45.310 [RTP] [RTP] StartCommunication 0x000001E9AF0652F0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-16T16:47:45.310 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-16T16:47:45.310 [init][RTP] RTPPlugin initialization completed 2026-05-16T16:47:45.310 OS boot count = 2 2026-05-16T16:47:45.310 OS Install = 0 2026-05-16T16:47:45.310 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-16T16:47:45.310 [KSL] Entering CKSLEngine::Initialize. 2026-05-16T16:47:45.310 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-16T16:47:45.310 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-16T16:47:45.310 [KSL] MpInstallKslD: hr=0x1 2026-05-16T16:47:45.310 [KSL] MpRegisterKslD: hr=0 2026-05-16T16:47:45.326 [KSL] MpStartKslD: hr=0 2026-05-16T16:47:45.326 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T16:47:45.326 Loading engine... 2026-05-16T16:47:45.342 Verifying engine and signature files (source: 1) ... 2026-05-16T16:47:45.342 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpengine.dll] due to PPL. 2026-05-16T16:47:45.342 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm]. File not in cache (0x1) 2026-05-16T16:47:46.357 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm] 2026-05-16T16:47:46.357 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasdlta.vdm] (file in cache) 2026-05-16T16:47:46.357 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm]. File not in cache (0x1) 2026-05-16T16:47:46.842 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavbase.vdm] 2026-05-16T16:47:46.842 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpavdlta.vdm] (file in cache) 2026-05-16T16:47:46.889 [Engine] IsHybridMode: 0 2026-05-16T16:47:46.889 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-16T16:47:46.904 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-BD6F815C8D130F9E9724667CC5D868F55032F114.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-16T16:47:50.639 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-16T16:47:50.639 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-16T16:47:50.654 [Engine] New active engine 00007FFE03655810 (no old engine). Number of active engines: 1 2026-05-16T16:47:50.670 EngineInit:Global ASOC is enabled 2026-05-16T16:47:50.670 EngineInit:ASOO is enabled for developer volumes 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.732 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:47:50.764 MpWriteUupSignatureVersion 1.449.642.0, hr = 0 2026-05-16T16:47:50.764 [SigStatUpd] CSignatureStatus: back to good 2026-05-16T16:47:50.764 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-16T16:47:50.779 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-16T16:47:50.779 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T16:47:50.779 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-16T16:47:50.779 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-16T16:47:50.779 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T16:47:50.795 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-16T16:47:50.795 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2189 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12113 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2467 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-16T16:47:50.795 [Plugin] Initializing RTP plugin state... 2026-05-16T16:47:50.795 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-16T16:47:50.795 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8} 2026-05-16T16:47:50.810 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:47:50.810 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:47:50.810 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:47:50.810 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T16:47:50.810 MdCoreSvc is supported in this platform and OS 2026-05-16T16:47:50.810 Engine loaded! 2026-05-16T16:47:50.810 [DLP] Create FeatureControlState instance 2026-05-16T16:47:50.810 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-16T16:47:50.810 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-16T16:47:50.810 RegisterSModeChangeListener: hr = 0x1 2026-05-16T16:47:50.810 RegisterHybridModeChangeListener: hr = 0 2026-05-16T16:47:50.826 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-16T16:47:50.826 [SigReleaseHb] Initialized with Stage 0 2026-05-16T16:47:50.826 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-16T16:47:50.826 [SCC][CID=23546_5548] Initializing ... 2026-05-16T16:47:50.826 [SCC][CID=23546_5548] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-16T16:47:50.826 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-16T16:47:50.826 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-16T16:47:50.826 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T16:47:50.826 [NRI] Stopping NIS service ... 2026-05-16T16:47:50.826 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-16T16:47:50.826 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.642.0 AV Signature Version: 1.449.642.0 ************************************************************ 2026-05-16T16:47:50.826 Resource usage Monitoring is enabled 2026-05-16T16:47:50.826 Job Notification: New process added to job (4744) 2026-05-16T16:47:50.826 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-16T16:47:50.904 Job Notification: New process added to job (7456) 2026-05-16T16:47:50.904 Job Notification: New process added to job (7464) 2026-05-16T16:47:50.904 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-16T16:47:50.904 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-16T16:47:50.904 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7456] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7464]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T16:47:50.904 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T16:47:50.904 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T16:47:50.904 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T16:47:50.904 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T16:47:50.904 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T16:47:50.904 [RTP] Generating the base plugin configuration ... 2026-05-16T16:47:50.904 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-16T16:47:50.904 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:47:50.904 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-16T16:47:50.904 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-16T16:47:50.904 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:47:50.904 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-16T16:47:50.920 [RTP] [RTP] StartCommunication 0x000001E9AF0A3C10 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-16T16:47:50.920 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-16T16:47:50.920 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-16T16:47:50.998 Job Notification: Process exited from job (7456) 2026-05-16T16:47:50.998 Job Notification: Process exited from job (7464) 2026-05-16T16:47:50.998 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-16T16:47:51.232 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:51.264 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-16T16:47:51.264 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-16T16:47:51.264 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T16:47:51.545 [AutoPurge] Verification Routine tasks have started. 2026-05-16T16:47:51.545 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T16:47:51.732 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-16T16:47:51.732 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-16T16:47:51.764 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-16T16:47:52.045 Job Notification: New process added to job (7648) 2026-05-16T16:47:52.045 Task(GetDeviceTicket -AccessKey E1BE7278-1DE0-3845-F85E-7F9652B657EF ) launched as network service 2026-05-16T16:47:52.295 Job Notification: Process exited from job (7648) 2026-05-16T16:47:52.498 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-16T16:47:52.498 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:47:52.498 [Cloud] Queued cloud request. 2026-05-16T16:47:52.498 [Cloud] Dequeued cloud request. 2026-05-16T16:47:52.498 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-16T16:47:52.498 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:47:52.498 [AutoPurge] Verification Routine tasks have ended. 2026-05-16T16:47:52.717 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-16T16:47:52.717 [Cloud] End of cloud request. 2026-05-16T16:47:52.810 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-16T16:47:52.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-16T16:47:52.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-16T16:47:52.826 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T16:47:52.826 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T16:47:52.826 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T16:47:52.826 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T16:47:52.826 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-16T16:47:52.826 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-16T16:47:52.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:52.842 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:52.842 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:47:53.810 [RTP] Duplicating the current plugin configuration object... 2026-05-16T16:47:53.810 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T16:47:53.810 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-05-16T16:47:53.810 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:47:53.810 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-16T16:47:53.810 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-05-16T16:48:45.262 Process scan (poststartupscan) started. 2026-05-16T16:48:45.263 Process scan (poststartupscan) completed. 2026-05-16T16:48:50.438 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2820, FileId: 0x2b0000000a7aa7, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:49:29.430 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-16T16:49:29.430 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-16T16:49:29.430 [RTP] Duplicating the current plugin configuration object... 2026-05-16T16:49:29.430 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T16:49:29.430 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-16T16:49:29.430 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-16T16:49:29.430 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-16T16:49:30.003 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-16T16:49:43.334 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T16:49:43.347 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T16:49:43.347 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T16:50:25.922 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\PARTITIONWIZARD.EXE-74ED46E5.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\PartitionWizard.exe, Status: 0xc000004b, State: 0, ScanRequest #4203, FileId: 0x2a000000003e33, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:50:28.255 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume1\EFI\Microsoft\Boot\BCD.LOG 2026-05-16T16:50:43.344 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #4352, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:50:47.340 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\00017441-AC50-27C2-2060-FC2582E80200-0.bin loaded. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-16T16:50:48.619 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:50:48.619 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:50:48.620 [Cloud] Queued cloud request. 2026-05-16T16:50:48.620 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:50:48.620 [Cloud] Dequeued cloud request. 2026-05-16T16:50:48.620 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4403b4e3a3ef7366fe9b909d6c45d5014b00bef6 Dynamic Signature Compilation Timestamp:05-16-2026 16:50:49 Persistence Type:Duration Time remaining:288000000 2026-05-16T16:50:49.223 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:50:49.227 [Cloud] End of cloud request. 2026-05-16T16:50:49.728 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:50:50.648 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x8f3e43bf 2026-05-16T16:51:42.695 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:51:42.697 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:51:42.697 [Cloud] Queued cloud request. 2026-05-16T16:51:42.697 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:51:42.697 [Cloud] Dequeued cloud request. 2026-05-16T16:51:42.697 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:51:43.062 [Cloud] End of cloud request. 2026-05-16T16:51:43.062 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-16T16:51:43.582 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:52:50.711 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-16T16:52:50.833 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T16:53:19.716 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4722, FileId: 0x31000000032ffa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:54:33.523 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xefaa5d78 2026-05-16T16:54:35.472 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:35.472 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:35.472 [Cloud] Queued cloud request. 2026-05-16T16:54:35.472 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:35.472 [Cloud] Dequeued cloud request. 2026-05-16T16:54:35.472 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:35.778 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cd7abf4f758b7f11b7b924c03bc78d06e697632b Dynamic Signature Compilation Timestamp:05-16-2026 16:54:35 Persistence Type:Duration Time remaining:150196224 2026-05-16T16:54:35.779 [Cloud] End of cloud request. 2026-05-16T16:54:35.779 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:36.300 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:54:42.574 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-57224378.pf. Process: \Device\HarddiskVolume10\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #10630, FileId: 0xf50000000011dd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:54:42.783 [RTP] [Mini-filter] OpenWithoutRead notification (608, 10130, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13dbd17f 2026-05-16T16:54:44.072 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:44.072 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:44.072 [Cloud] Queued cloud request. 2026-05-16T16:54:44.072 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:44.072 [Cloud] Dequeued cloud request. 2026-05-16T16:54:44.072 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\91cb1caddabbcd6c04753421191cd1bb6567a503 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:44.258 Dynamic signature received 2026-05-16T16:54:44.258 [Cloud] End of cloud request. 2026-05-16T16:54:44.258 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xde65ca27 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x02f929b1 2026-05-16T16:54:44.534 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:44.534 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:44.534 [Cloud] Queued cloud request. 2026-05-16T16:54:44.534 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:44.534 [Cloud] Dequeued cloud request. 2026-05-16T16:54:44.534 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:44.543 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:44.543 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:44.543 [Cloud] Queued cloud request. 2026-05-16T16:54:44.543 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:44.543 [Cloud] Dequeued cloud request. 2026-05-16T16:54:44.543 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2be02083 2026-05-16T16:54:44.633 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:44.633 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:44.633 [Cloud] Queued cloud request. 2026-05-16T16:54:44.633 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:44.633 [Cloud] Dequeued cloud request. 2026-05-16T16:54:44.633 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:44.742 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ef582e22047da2f4e419011668efb0050d09d51 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:44.743 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:44.743 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ffdde34 2026-05-16T16:54:44.785 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-16T16:54:44.786 [RTP] Duplicating the current plugin configuration object... 2026-05-16T16:54:44.786 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T16:54:44.786 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-16T16:54:44.786 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:54:44.786 [RTP] No config change detected. Not updating plugin configuration. 2026-05-16T16:54:44.786 [RTP] No config changes found. No configuration switch. 2026-05-16T16:54:44.786 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-16T16:54:44.788 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46eeb3447a0bce7244e45146fbe57707794eb4a2 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:44.801 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:44.807 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:44.807 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:44.808 [Cloud] Queued cloud request. 2026-05-16T16:54:44.808 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:44.808 [Cloud] End of cloud request. 2026-05-16T16:54:44.808 [Cloud] Dequeued cloud request. 2026-05-16T16:54:44.809 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:44.842 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fc8cb6186c12e33816e830e1f4dac1a6ce81d942 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:44.943 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:44.948 [Cloud] End of cloud request. 2026-05-16T16:54:44.949 Dynamic signature received 2026-05-16T16:54:45.033 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fd4e2e1b8f443af3f364c27b65a196c5bef9cd0c Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:45.034 [Cloud] End of cloud request. 2026-05-16T16:54:45.034 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:45.332 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcc1c40b1 2026-05-16T16:54:46.173 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:46.173 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:46.173 [Cloud] Queued cloud request. 2026-05-16T16:54:46.173 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:46.173 [Cloud] Dequeued cloud request. 2026-05-16T16:54:46.173 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\733dfe5a9f4818634f30a77e456f7c23d05885bd Dynamic Signature Compilation Timestamp:05-16-2026 16:54:46 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:46.393 [Cloud] End of cloud request. 2026-05-16T16:54:46.393 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1bc3c001 2026-05-16T16:54:46.458 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:46.458 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:46.458 [Cloud] Queued cloud request. 2026-05-16T16:54:46.458 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:46.458 [Cloud] Dequeued cloud request. 2026-05-16T16:54:46.460 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1e30fd0bf5ac373ed0b2f5c2a3e6940d13245940 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:46 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:54:46.707 [Cloud] End of cloud request. 2026-05-16T16:54:46.707 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3be3358d 2026-05-16T16:54:46.784 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:46.784 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:46.784 [Cloud] Queued cloud request. 2026-05-16T16:54:46.784 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:46.784 [Cloud] Dequeued cloud request. 2026-05-16T16:54:46.790 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:46.913 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:54:47.990 Dynamic signature received 2026-05-16T16:54:47.991 Dynamic signature received 2026-05-16T16:54:54.664 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume10\xampp\apache\modules\mod_alias.so. Process: \Device\HarddiskVolume10\xampp\apache\bin\httpd.exe, Status: 0xc000004b, State: 0, ScanRequest #11361, FileId: 0x10000000007b0, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x100021, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5ca953c5 2026-05-16T16:54:56.680 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:54:56.680 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:54:56.681 [Cloud] Queued cloud request. 2026-05-16T16:54:56.681 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:54:56.681 [Cloud] Dequeued cloud request. 2026-05-16T16:54:56.681 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:54:56.789 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume10\xampp\apache\modules\mod_alias.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-05-16T16:54:56.825 [Cloud] End of cloud request. 2026-05-16T16:54:56.873 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\10ade06d9afbd40681463dc4ff8a426040edcf96 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:56 Persistence Type:Duration Time remaining:150196224 2026-05-16T16:54:56.874 [Cloud] End of cloud request. 2026-05-16T16:54:56.874 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:54:57.345 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:10.452 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18635, FileId: 0x18300000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:10.459 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18638, FileId: 0x1ec00000001311f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:10.460 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18636, FileId: 0x1eb00000001311f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.154 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18816, FileId: 0xdc00000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.155 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18818, FileId: 0xdd00000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.159 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18815, FileId: 0x19000000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.177 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18817, FileId: 0x19100000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.258 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18828, FileId: 0xe400000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.264 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18827, FileId: 0x19700000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.304 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18835, FileId: 0xe500000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.338 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18829, FileId: 0x19800000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.340 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18859, FileId: 0xe600000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:12.360 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18833, FileId: 0x19900000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:13.045 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18984, FileId: 0xe10000000022ff, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:13.049 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18986, FileId: 0xe20000000022ff, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:13.051 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #18985, FileId: 0xeb00000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:15.385 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #19702, FileId: 0xed00000000a8b7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3be3358d 2026-05-16T16:55:15.729 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:15.729 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:15.729 [Cloud] Queued cloud request. 2026-05-16T16:55:15.729 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:15.729 [Cloud] Dequeued cloud request. 2026-05-16T16:55:15.731 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c60e9a0822572f9e63e6ed21341a2cda1de5ffaa Dynamic Signature Compilation Timestamp:05-16-2026 16:55:15 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:15.908 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:15.913 Dynamic signature received 2026-05-16T16:55:15.914 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x562d4543 2026-05-16T16:55:15.994 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:15.994 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:15.994 [Cloud] Queued cloud request. 2026-05-16T16:55:15.994 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:15.994 [Cloud] Dequeued cloud request. 2026-05-16T16:55:15.995 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31a5f79a9c83ff19cfae3cb9bb5fe6aa7251f737 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:16.247 [Cloud] End of cloud request. 2026-05-16T16:55:16.248 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:16.248 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x325a00a0 2026-05-16T16:55:16.315 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:16.315 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:16.315 [Cloud] Queued cloud request. 2026-05-16T16:55:16.315 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:16.316 [Cloud] Dequeued cloud request. 2026-05-16T16:55:16.316 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:16.426 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:16.643 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\190446bbd08cc17d92d9f5dd79b591eedfc209f3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:16.644 [Cloud] End of cloud request. 2026-05-16T16:55:16.644 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcc56acdd 2026-05-16T16:55:16.746 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:16.746 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:16.746 [Cloud] Queued cloud request. 2026-05-16T16:55:16.746 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:16.746 [Cloud] Dequeued cloud request. 2026-05-16T16:55:16.747 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:16.940 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2ba4ed1d071f40ec715cbb4c25e4ca100a827931 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:16.941 [Cloud] End of cloud request. 2026-05-16T16:55:16.941 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59eeeee6 2026-05-16T16:55:17.043 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:17.043 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:17.043 [Cloud] Queued cloud request. 2026-05-16T16:55:17.043 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:17.043 [Cloud] Dequeued cloud request. 2026-05-16T16:55:17.044 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:17.163 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ec5ac2fd4c957aa423d8c34ba9e9919976a2ab7 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:17.242 Dynamic signature received 2026-05-16T16:55:17.243 [Cloud] End of cloud request. 2026-05-16T16:55:17.243 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0b179430 2026-05-16T16:55:17.290 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:17.290 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:17.290 [Cloud] Queued cloud request. 2026-05-16T16:55:17.290 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:17.290 [Cloud] Dequeued cloud request. 2026-05-16T16:55:17.290 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8625148623f5d93480268e4436ca89622bf46b76 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:17.628 Dynamic signature received 2026-05-16T16:55:17.628 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:17.628 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ce565f8 2026-05-16T16:55:17.697 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:17.697 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:17.697 [Cloud] Queued cloud request. 2026-05-16T16:55:17.697 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:17.697 [Cloud] Dequeued cloud request. 2026-05-16T16:55:17.697 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:17.766 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:17.977 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\388feddf6bc2a66f5732586515c96cd551776c0b Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:17.977 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:17.983 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xaff6f2c1 2026-05-16T16:55:18.058 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:18.058 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:18.059 [Cloud] Queued cloud request. 2026-05-16T16:55:18.059 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:18.059 [Cloud] Dequeued cloud request. 2026-05-16T16:55:18.060 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:18.270 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\89be32d907a34002866522e31bba2a50c8c9715d Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:18.271 [Cloud] End of cloud request. 2026-05-16T16:55:18.271 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6c0e049e 2026-05-16T16:55:18.349 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:18.349 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:18.349 [Cloud] Queued cloud request. 2026-05-16T16:55:18.349 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:18.349 [Cloud] Dequeued cloud request. 2026-05-16T16:55:18.363 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:18.506 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0edc1793a2aac7acf79e727189f168b8f2855658 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:18.563 Dynamic signature received 2026-05-16T16:55:18.563 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:18.578 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x588b10fc 2026-05-16T16:55:18.639 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:18.639 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:18.639 [Cloud] Queued cloud request. 2026-05-16T16:55:18.639 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:18.639 [Cloud] Dequeued cloud request. 2026-05-16T16:55:18.640 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:18.857 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c01108b362e83d39d68cea384ee13bb1c900e578 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:18.858 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:18.862 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd9113c45 2026-05-16T16:55:18.926 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:18.926 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:18.926 [Cloud] Queued cloud request. 2026-05-16T16:55:18.926 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:18.926 [Cloud] Dequeued cloud request. 2026-05-16T16:55:18.927 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:19.094 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9b6122979e4917cb700856362556c9e310b1757 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:19.225 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:19.227 Dynamic signature received 2026-05-16T16:55:19.229 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc9c9c33f 2026-05-16T16:55:19.308 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:19.308 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:19.308 [Cloud] Queued cloud request. 2026-05-16T16:55:19.308 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:19.308 [Cloud] Dequeued cloud request. 2026-05-16T16:55:19.308 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:19.528 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0087a7287b7966dba7eb0218aabc795930bf2a50 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:19.529 [Cloud] End of cloud request. 2026-05-16T16:55:19.529 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4dc88e49 2026-05-16T16:55:19.584 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:19.584 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:19.584 [Cloud] Queued cloud request. 2026-05-16T16:55:19.584 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:19.585 [Cloud] Dequeued cloud request. 2026-05-16T16:55:19.585 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:19.751 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:19.796 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2244730e6ee94b3cb2191e0ea6f6c39117e9621a Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:19.797 [Cloud] End of cloud request. 2026-05-16T16:55:19.797 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d47970 2026-05-16T16:55:19.892 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:19.892 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:19.892 [Cloud] Queued cloud request. 2026-05-16T16:55:19.892 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:19.892 [Cloud] Dequeued cloud request. 2026-05-16T16:55:19.892 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:20.078 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\13e7f0abfc03363de822e25b874131a852159e49 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:20.078 [Cloud] End of cloud request. 2026-05-16T16:55:20.078 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8249377e 2026-05-16T16:55:20.131 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:20.131 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:20.131 [Cloud] Queued cloud request. 2026-05-16T16:55:20.131 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:20.131 [Cloud] Dequeued cloud request. 2026-05-16T16:55:20.131 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:20.301 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:20.396 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\81e2d66d502659d38b8a47f352246d8bd261d460 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:20 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:20.396 [Cloud] End of cloud request. 2026-05-16T16:55:20.396 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7f7a6e92 2026-05-16T16:55:20.459 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:20.459 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:20.459 [Cloud] Queued cloud request. 2026-05-16T16:55:20.459 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:20.459 [Cloud] Dequeued cloud request. 2026-05-16T16:55:20.459 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:20.705 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\deeba5fb36d2a8fbcf2718babaf4dd6b11dc7144 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:20 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:20.706 [Cloud] End of cloud request. 2026-05-16T16:55:20.706 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x11228ba4 2026-05-16T16:55:20.768 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:20.768 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:20.768 [Cloud] Queued cloud request. 2026-05-16T16:55:20.768 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:20.769 [Cloud] Dequeued cloud request. 2026-05-16T16:55:20.769 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:20.911 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:21.292 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7f33c3c8acadf6416204bed290232ffb089049f Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:21.293 [Cloud] End of cloud request. 2026-05-16T16:55:21.293 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa117dc26 2026-05-16T16:55:21.365 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:21.366 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:21.366 [Cloud] Queued cloud request. 2026-05-16T16:55:21.366 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:21.366 [Cloud] Dequeued cloud request. 2026-05-16T16:55:21.366 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f44d9c3b1b30441b9e93df69d4ce0becca7c18a1 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:21.633 Dynamic signature received 2026-05-16T16:55:21.633 [Cloud] End of cloud request. 2026-05-16T16:55:21.633 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x49ab8d6d 2026-05-16T16:55:21.693 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:21.693 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:21.693 [Cloud] Queued cloud request. 2026-05-16T16:55:21.693 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:21.693 [Cloud] Dequeued cloud request. 2026-05-16T16:55:21.693 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:21.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eda4f675e4a5f0d7af8d7c5f03611c58700c519c Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:21.954 [Cloud] End of cloud request. 2026-05-16T16:55:21.954 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5bcd9393 2026-05-16T16:55:22.018 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:22.018 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:22.018 [Cloud] Queued cloud request. 2026-05-16T16:55:22.018 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:22.018 [Cloud] Dequeued cloud request. 2026-05-16T16:55:22.018 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2910defc42cc3760f831993cdf9424b505a43a58 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:22.265 [Cloud] End of cloud request. 2026-05-16T16:55:22.265 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b697b83 2026-05-16T16:55:22.328 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:22.328 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:22.328 [Cloud] Queued cloud request. 2026-05-16T16:55:22.328 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:22.328 [Cloud] Dequeued cloud request. 2026-05-16T16:55:22.328 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:22.472 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ff9725cd7464adb6e561fe066695dfd6d2465e25 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:22.656 [Cloud] End of cloud request. 2026-05-16T16:55:22.656 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1b8835a8 2026-05-16T16:55:22.721 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:22.721 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:22.721 [Cloud] Queued cloud request. 2026-05-16T16:55:22.721 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:22.721 [Cloud] Dequeued cloud request. 2026-05-16T16:55:22.722 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a953f2a7dd11f745dc91c55617266b5b9fe22fd Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:22.964 [Cloud] End of cloud request. 2026-05-16T16:55:22.964 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa74f9bb2 2026-05-16T16:55:23.037 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:23.037 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:23.037 [Cloud] Queued cloud request. 2026-05-16T16:55:23.037 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:23.037 [Cloud] Dequeued cloud request. 2026-05-16T16:55:23.038 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:23.177 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\566787fd21d3d84a98c97724dc770648d7a69360 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:23.251 [Cloud] End of cloud request. 2026-05-16T16:55:23.251 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4dbf0cc6 2026-05-16T16:55:23.315 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:23.315 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:23.315 [Cloud] Queued cloud request. 2026-05-16T16:55:23.315 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:23.315 [Cloud] Dequeued cloud request. 2026-05-16T16:55:23.315 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\72bdc1e1c354f8d96e3b2dc737e4a3704b212044 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:23.589 [Cloud] End of cloud request. 2026-05-16T16:55:23.589 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc1218489 2026-05-16T16:55:23.651 Dynamic signature received 2026-05-16T16:55:23.651 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:23.651 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:23.651 [Cloud] Queued cloud request. 2026-05-16T16:55:23.651 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:23.651 [Cloud] Dequeued cloud request. 2026-05-16T16:55:23.651 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:23.768 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48d32e388a1de406dc93a6336f3cdf084a5830cc Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:23.840 [Cloud] End of cloud request. 2026-05-16T16:55:23.840 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7bc3e064 2026-05-16T16:55:23.910 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:23.910 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:23.910 [Cloud] Queued cloud request. 2026-05-16T16:55:23.910 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:23.910 [Cloud] Dequeued cloud request. 2026-05-16T16:55:23.910 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\47ac7524ffc09f594db57320d916d2d53f1d50d3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:24.206 [Cloud] End of cloud request. 2026-05-16T16:55:24.206 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x350cd24a 2026-05-16T16:55:24.269 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:24.269 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:24.269 [Cloud] Queued cloud request. 2026-05-16T16:55:24.269 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:24.269 [Cloud] Dequeued cloud request. 2026-05-16T16:55:24.269 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:24.362 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3a2b648963bec7a7cb4cd6e997379c2ccb020bbe Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:24.452 [Cloud] End of cloud request. 2026-05-16T16:55:24.452 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3ff7a575 2026-05-16T16:55:24.522 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:24.522 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:24.522 [Cloud] Queued cloud request. 2026-05-16T16:55:24.522 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:24.522 [Cloud] Dequeued cloud request. 2026-05-16T16:55:24.523 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\db67e05983f91c1258577588c561f4f577287092 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:24.746 [Cloud] End of cloud request. 2026-05-16T16:55:24.746 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x338c1385 2026-05-16T16:55:24.805 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:24.805 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:24.805 [Cloud] Queued cloud request. 2026-05-16T16:55:24.805 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:24.805 [Cloud] Dequeued cloud request. 2026-05-16T16:55:24.805 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:24.913 Dynamic signature received 2026-05-16T16:55:24.913 Dynamic signature received 2026-05-16T16:55:24.913 Dynamic signature received 2026-05-16T16:55:24.916 Dynamic signature received 2026-05-16T16:55:24.916 Dynamic signature received 2026-05-16T16:55:24.917 Dynamic signature received 2026-05-16T16:55:24.917 Dynamic signature received 2026-05-16T16:55:24.917 Dynamic signature received 2026-05-16T16:55:24.918 Dynamic signature received 2026-05-16T16:55:24.969 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52763bfdf065042ede80ef01b0279751d7ecb78b Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:25.040 Dynamic signature received 2026-05-16T16:55:25.040 [Cloud] End of cloud request. 2026-05-16T16:55:25.040 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7745d804 2026-05-16T16:55:25.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:25.096 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:25.096 [Cloud] Queued cloud request. 2026-05-16T16:55:25.096 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:25.096 [Cloud] Dequeued cloud request. 2026-05-16T16:55:25.096 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82c05a575526cd775aaf75b3bf178ace6ef380f4 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:25.319 Dynamic signature received 2026-05-16T16:55:25.319 [Cloud] End of cloud request. 2026-05-16T16:55:25.319 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa3740135 2026-05-16T16:55:25.396 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:25.396 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:25.396 [Cloud] Queued cloud request. 2026-05-16T16:55:25.396 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:25.396 [Cloud] Dequeued cloud request. 2026-05-16T16:55:25.397 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:25.563 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:25.750 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\09250b9efb569978b4a94d1850e070e3ae7cdab8 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:25.751 [Cloud] End of cloud request. 2026-05-16T16:55:25.751 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbb5a75e6 2026-05-16T16:55:25.918 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:25.918 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:25.918 [Cloud] Queued cloud request. 2026-05-16T16:55:25.918 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:25.918 [Cloud] Dequeued cloud request. 2026-05-16T16:55:25.918 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0038efb4 2026-05-16T16:55:26.048 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:26.048 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:26.048 [Cloud] Queued cloud request. 2026-05-16T16:55:26.048 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:26.048 [Cloud] Dequeued cloud request. 2026-05-16T16:55:26.048 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:26.104 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46b4c6c393f6e6c1da4a0831aff5ec5ce3ddfc83 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:26.105 [Cloud] End of cloud request. 2026-05-16T16:55:26.105 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:26.267 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:26.589 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3dc3af4b59bb7b09aebef44c7d900f0601c139fe Dynamic Signature Compilation Timestamp:05-16-2026 16:55:26 Persistence Type:Duration Time remaining:150196224 2026-05-16T16:55:26.589 [Cloud] End of cloud request. 2026-05-16T16:55:26.589 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ab81960 2026-05-16T16:55:26.667 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:26.667 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:26.667 [Cloud] Queued cloud request. 2026-05-16T16:55:26.667 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:26.667 [Cloud] Dequeued cloud request. 2026-05-16T16:55:26.667 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f6c8a014fee610dc20b4b14bd8c14a2a533fcb44 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:26 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:26.877 Dynamic signature received 2026-05-16T16:55:26.878 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:26.878 [Cloud] End of cloud request. 2026-05-16T16:55:27.110 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b7d3581 2026-05-16T16:55:27.766 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:27.766 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:27.766 [Cloud] Queued cloud request. 2026-05-16T16:55:27.766 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:27.766 [Cloud] Dequeued cloud request. 2026-05-16T16:55:27.767 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\292f74f5118db944cef626af4eefba8434087045 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:27 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:27.962 Dynamic signature received 2026-05-16T16:55:27.963 [Cloud] End of cloud request. 2026-05-16T16:55:27.963 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6b5411ee 2026-05-16T16:55:28.115 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:28.115 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:28.115 [Cloud] Queued cloud request. 2026-05-16T16:55:28.115 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:28.115 [Cloud] Dequeued cloud request. 2026-05-16T16:55:28.115 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:28.485 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:29.081 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj05E4BB93E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21404, FileId: 0x1500000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.089 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDCB3F19F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21405, FileId: 0x1600000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.093 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA52D189C9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21406, FileId: 0x1e00000003cc19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.117 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4575B89A0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21407, FileId: 0x1800000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.219 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj219D8C998. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21412, FileId: 0x1c00000003cc27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.338 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFC364796C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21416, FileId: 0x2900000003cc19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.366 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE95EE1918. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21420, FileId: 0x1700000003cc28, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.609 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFF30C798E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21428, FileId: 0x2e00000003cc19, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.917 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj61564B962. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21431, FileId: 0x1f00000003cc28, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.948 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3A83B19DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21432, FileId: 0x1800000003cc2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:29.964 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj56AF739FF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21433, FileId: 0x1900000003cc2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.006 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC957F79F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21434, FileId: 0x13000000000e645, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.026 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj400ACF9EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21436, FileId: 0x1a00000003cc2a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.267 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj27B52F983. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21461, FileId: 0x1b00000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.283 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6D89FB965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21463, FileId: 0x1c00000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.307 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF337AE9F6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21465, FileId: 0x1d00000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.319 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB237A7979. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21466, FileId: 0x1e00000003cc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.339 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCC17509E3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21468, FileId: 0x1a00000003cc5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.402 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8CC180916. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21472, FileId: 0x1b00000003cc5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.577 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8E53169A7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21475, FileId: 0x1d00000003cc5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.578 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj482DE39F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21481, FileId: 0x1900000003cc65, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.582 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C600B91A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21479, FileId: 0x1500000003cc60, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.584 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE218549E4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21474, FileId: 0x1c00000003cc5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.808 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj96487E970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21504, FileId: 0x1a00000003ccbe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.856 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj35A5B0907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21509, FileId: 0x1d00000003ccc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.895 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0268DE9DF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21518, FileId: 0x1e00000003ccc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.904 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj67C2E39E2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21519, FileId: 0x1f00000003ccc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:30.990 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj078C279CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21529, FileId: 0x1c00000003ccc7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.007 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj037D9F9A3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21531, FileId: 0x1d00000003ccc7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.020 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9f1db4af7a0dafc0bea3ee9a1e30c453d298811e Dynamic Signature Compilation Timestamp:05-16-2026 16:55:30 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:31.021 [Cloud] End of cloud request. 2026-05-16T16:55:31.021 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf8111669 2026-05-16T16:55:31.098 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:31.098 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:31.098 [Cloud] Queued cloud request. 2026-05-16T16:55:31.098 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:31.098 [Cloud] Dequeued cloud request. 2026-05-16T16:55:31.099 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:31.204 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDAE5FC966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21543, FileId: 0x1800000003ccd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.206 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBE2F7B92A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21542, FileId: 0x1400000003ccd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.207 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAB21DD965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21544, FileId: 0x1900000003ccd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.216 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj852A819ED. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21545, FileId: 0x1a00000003ccd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.230 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF285CE937. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21546, FileId: 0x1b00000003ccd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.349 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1F402A920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21551, FileId: 0x1d00000003ccd0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.352 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD89731959. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21550, FileId: 0x1500000003ccd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\969773405919d3b4877dfd75df65667b2a5df40a Dynamic Signature Compilation Timestamp:05-16-2026 16:55:31 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:31.367 Dynamic signature received 2026-05-16T16:55:31.368 [Cloud] End of cloud request. 2026-05-16T16:55:31.368 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:31.432 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6A73C1927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21555, FileId: 0x1600000003ccd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.497 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0FD9289DD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21559, FileId: 0x1700000003ccd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:31.536 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b51e504 2026-05-16T16:55:32.041 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:32.041 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:32.041 [Cloud] Queued cloud request. 2026-05-16T16:55:32.041 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:32.041 [Cloud] Dequeued cloud request. 2026-05-16T16:55:32.042 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f709d21b0327ed6b35a302bc8fcd3ac18cb76ff5 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:32.263 Dynamic signature received 2026-05-16T16:55:32.264 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:32.264 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7b9a754b 2026-05-16T16:55:32.367 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:32.367 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:32.378 [Cloud] Queued cloud request. 2026-05-16T16:55:32.378 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:32.378 [Cloud] Dequeued cloud request. 2026-05-16T16:55:32.378 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:32.605 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e58d073de98d1b97992b62b26863a45cd033ad4 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:32.605 [Cloud] End of cloud request. 2026-05-16T16:55:32.605 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d008459 2026-05-16T16:55:32.683 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:32.683 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:32.683 [Cloud] Queued cloud request. 2026-05-16T16:55:32.683 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:32.683 [Cloud] Dequeued cloud request. 2026-05-16T16:55:32.683 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:32.796 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:33.118 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\334aa24b7bb66925972b40e7a01194bda777efbb Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:150196224 2026-05-16T16:55:33.119 [Cloud] End of cloud request. 2026-05-16T16:55:33.119 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfadbb58b 2026-05-16T16:55:33.389 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:33.389 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:33.389 [Cloud] Queued cloud request. 2026-05-16T16:55:33.389 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:33.389 [Cloud] Dequeued cloud request. 2026-05-16T16:55:33.389 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:33.642 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:33.755 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1636d2d532c72cfb7369883307425bebe993a60 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:33 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:33.756 [Cloud] End of cloud request. 2026-05-16T16:55:33.756 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8a547fa1 2026-05-16T16:55:33.815 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:33.815 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:33.815 [Cloud] Queued cloud request. 2026-05-16T16:55:33.815 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:33.815 [Cloud] Dequeued cloud request. 2026-05-16T16:55:33.815 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:34.033 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fd0285ebbb374069f48aac53b9be2b848bacef0d Dynamic Signature Compilation Timestamp:05-16-2026 16:55:33 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:34.035 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:34.036 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x01a849d6 2026-05-16T16:55:34.206 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:34.206 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:34.206 [Cloud] Queued cloud request. 2026-05-16T16:55:34.206 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:34.206 [Cloud] Dequeued cloud request. 2026-05-16T16:55:34.206 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:34.264 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:34.483 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\50e01aa05539acb79b5a427d4b2ab69d5c5bff1e Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:34.485 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:34.485 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf559b5cf 2026-05-16T16:55:34.542 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:34.542 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:34.542 [Cloud] Queued cloud request. 2026-05-16T16:55:34.543 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:34.543 [Cloud] Dequeued cloud request. 2026-05-16T16:55:34.543 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b997e14a8dc0d7b1d53e76481bae21d74c5be2e0 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:34.881 Dynamic signature received 2026-05-16T16:55:34.882 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:34.882 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x855c0bbc 2026-05-16T16:55:34.934 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:34.934 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:34.934 [Cloud] Queued cloud request. 2026-05-16T16:55:34.934 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:34.934 [Cloud] Dequeued cloud request. 2026-05-16T16:55:34.934 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:35.002 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:35.173 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3fcdd6f5d0e8c719e9b6a47c92440667f84cd437 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:35.175 [Cloud] End of cloud request. 2026-05-16T16:55:35.175 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3e82d95a 2026-05-16T16:55:35.235 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:35.235 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:35.235 [Cloud] Queued cloud request. 2026-05-16T16:55:35.235 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:35.235 [Cloud] Dequeued cloud request. 2026-05-16T16:55:35.235 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4fc4aec0cff04ff08adb45b459cd72d3a0f4a8b2 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:35 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:35.472 [Cloud] End of cloud request. 2026-05-16T16:55:35.472 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:35.472 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x35a9d751 2026-05-16T16:55:35.534 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:35.534 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:35.534 [Cloud] Queued cloud request. 2026-05-16T16:55:35.534 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:35.534 [Cloud] Dequeued cloud request. 2026-05-16T16:55:35.534 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:35.690 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:35.755 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8632ba51d90f89b9284efa3d5447941237348cb3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:35 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:35.756 [Cloud] End of cloud request. 2026-05-16T16:55:35.756 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x995634cd 2026-05-16T16:55:35.880 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:35.880 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:35.880 [Cloud] Queued cloud request. 2026-05-16T16:55:35.880 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:35.880 [Cloud] Dequeued cloud request. 2026-05-16T16:55:35.880 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:36.266 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:36.339 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dc1fc611768cf7680c21f779c40a149ac06f2f59 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:36 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:36.340 [Cloud] End of cloud request. 2026-05-16T16:55:36.340 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0a55e18 2026-05-16T16:55:36.398 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T16:55:36.398 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T16:55:36.398 [Cloud] Queued cloud request. 2026-05-16T16:55:36.398 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T16:55:36.398 [Cloud] Dequeued cloud request. 2026-05-16T16:55:36.399 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T16:55:36.708 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b846e63ce5663ce3237be2a90a5d7fa7b4d9cbce Dynamic Signature Compilation Timestamp:05-16-2026 16:55:36 Persistence Type:Duration Time remaining:50065408 2026-05-16T16:55:36.709 [Cloud] End of cloud request. 2026-05-16T16:55:36.709 RTSD:RTSD recieved, rescanning impacted resources 2026-05-16T16:55:36.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:55:43.590 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21780, FileId: 0x1500000003cbfd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:43.808 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21783, FileId: 0x1800000003cc07, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:55:43.965 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21787, FileId: 0x11a000000013175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:19.755 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\Eureka\AcroCoreSync\Adobe\CoreSync\EntitySync\80307f885d209ff3421f3adf000d6b1e.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22950, FileId: 0xa9000000007625, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:19.783 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2A50519AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22953, FileId: 0x43000000013146, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:19.787 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22954, FileId: 0xac000000007625, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:19.811 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22956, FileId: 0x6500000000856c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:56.696 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #24724, FileId: 0x1900000001b3fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:56:59.318 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-05-16T16:57:00.625 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-05-16T16:57:00.720 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-05-16T16:57:17.707 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-16T16:57:17.707 [RTP] Duplicating the current plugin configuration object... 2026-05-16T16:57:17.707 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-05-16T16:57:17.707 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T16:57:17.707 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-16T16:57:17.707 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-16T16:57:17.707 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-16T16:57:18.262 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-05-16T16:57:50.835 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-16T16:57:50.835 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-16T16:57:50.866 Job Notification: New process added to job (11296) 2026-05-16T16:57:50.878 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-16T16:57:50.882 Job Notification: New process added to job (11172) 2026-05-16T16:57:50.882 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:11296] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11172]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T16:57:50.941 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 31221528(ms) from now at 03:38 (01:38 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-16T16:57:50.941 Aggressive catchup quick scan threshold: 1003965385502 / 25920000000000 2026-05-16T16:57:51.003 Job Notification: New process added to job (3808) 2026-05-16T16:57:51.009 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-16T16:57:51.009 Job Notification: New process added to job (5236) 2026-05-16T16:57:51.009 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:3808] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5236]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-16T16:57:51.458 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-16T16:57:51.458 [RTP] Duplicating the current plugin configuration object... 2026-05-16T16:57:51.458 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T16:57:51.458 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-16T16:57:51.459 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:57:51.459 [RTP] No config change detected. Not updating plugin configuration. 2026-05-16T16:57:51.459 [RTP] No config changes found. No configuration switch. 2026-05-16T16:57:51.459 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-16T16:58:08.395 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\DEDE1E3E-0070-4FF8-9869-49507328341C12f0.1dce5552a43469c 2026-05-16T16:58:08.533 Verifying engine and signature files (source: 0) ... 2026-05-16T16:58:08.533 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpengine.dll] due to PPL. 2026-05-16T16:58:08.533 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasbase.vdm]. File not in cache (0x1) 2026-05-16T16:58:09.324 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasbase.vdm] 2026-05-16T16:58:09.324 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-16T16:58:09.347 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasdlta.vdm] 2026-05-16T16:58:09.347 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavbase.vdm]. File not in cache (0x1) 2026-05-16T16:58:09.728 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavbase.vdm] 2026-05-16T16:58:09.728 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-16T16:58:09.757 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavdlta.vdm] 2026-05-16T16:58:09.928 [Engine] IsHybridMode: 0 2026-05-16T16:58:09.928 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-16T16:58:09.934 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0F40909C867D4F2274B01C6C7704085D27C4E4FE.bin): 0x00000002 2026-05-16T16:58:09.947 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0F40909C867D4F2274B01C6C7704085D27C4E4FE.bin) 2026-05-16T16:58:09.947 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-16T16:58:09.947 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-16T16:58:09.947 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-16T16:58:09.947 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-16T16:58:20.930 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-16T16:58:20.930 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-16T16:58:20.978 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE03655810, lRefCount: 5, hr=0 2026-05-16T16:58:20.978 [Engine] New active engine 00007FFDD0485810 replacing engine 00007FFE03655810. Number of active engines: 2 2026-05-16T16:58:20.994 EngineInit:Global ASOC is enabled 2026-05-16T16:58:20.994 EngineInit:ASOO is enabled for developer volumes 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.073 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-16T16:58:21.089 MpWriteUupSignatureVersion 1.449.649.0, hr = 0 2026-05-16T16:58:21.097 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-16T16:58:21.128 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-16T16:58:21.128 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-16T16:58:21.128 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-16T16:58:21.128 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-05-16T16:58:21.128 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValiditApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-16T16:58:21.152 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-16T16:58:21.152 [Plugin] Initializing RTP plugin state... 2026-05-16T16:58:21.152 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎16‎-‎2026 18:47:50 Last Perf:‎05‎-‎16‎-‎2026 18:47:50 First RTP Scan:‎05‎-‎16‎-‎2026 18:47:50 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2955 Misses:23030 BM Queue:0,282,0 Proc:0,196,0 File:0,92,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:32472 Pending:0 RegSize:308070 AsyncQNotif:2 AsyncQMissed:0 AsyncQTotalSent:34938038 AsyncQCurrent:1186 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:14 TotalStreamCon:33903 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:50915 TotalHits:37101 InstanceCacheInserts:2814 InstanceCacheUpdates:0 InstanceCacheDeletes:19 InstanceCacheHits:59 InstanceCacheMisses:44454 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (1284/473) Success: 473, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-16T16:58:21.152 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-16T16:58:21.152 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152} 2026-05-16T16:58:21.152 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8}\mpasbase.vdm in use, hr=0x80070020 2026-05-16T16:58:21.152 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-16T16:58:21.152 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{996E2E16-5DB7-4FE0-97CC-F0065BE8FAE7} removed 2026-05-16T16:58:21.152 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.152 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.152 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.152 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.152 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-16-2026 16:58:21 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-16-2026 16:58:21 2026-05-16T16:58:21.168 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:58:21.168 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-16T16:58:21.168 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-16T16:58:21.168 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-16T16:58:21.168 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T16:58:21.168 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.168 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.168 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.168 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-16T16:58:21.168 MdCoreSvc is supported in this platform and OS Signature updated on 05-16-2026 16:58:21 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.649.0 AV Signature Version: 1.449.649.0 ************************************************************ 2026-05-16T16:58:21.168 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-16T16:58:21.168 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\DEDE1E3E-0070-4FF8-9869-49507328341C12f0.1dce5552a43469c 2026-05-16T16:58:21.277 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-16T16:58:21.277 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 05-16-2026 16:58:21 ************************************************************ 2026-05-16T16:58:21.323 Job Notification: Process exited from job (3808) 2026-05-16T16:58:21.329 Job Notification: Process exited from job (5236) 2026-05-16T16:58:21.400 Job Notification: Process exited from job (11296) 2026-05-16T16:58:21.402 Job Notification: Process exited from job (11172) 2026-05-16T16:58:21.524 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #32476, FileId: 0x4b00000001ab90, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:58:21.617 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #32480, FileId: 0x30000000c48bd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T16:58:21.622 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-16T16:58:21.622 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-16T16:58:21.622 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-16T16:58:21.889 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-16T16:58:21.889 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-16T16:58:21.890 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-16T16:58:21.890 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-16T16:58:21.890 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-16T16:58:21.893 [Engine] Engine 00007FFE03655810 no longer in use. Number of active engines: 1 2026-05-16T16:58:21.893 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T16:58:21.893 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-16T16:58:22.025 ProcessImageName: explorer.exe, Pid: 8740, TotalTime: 6917, Count: 152, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-05-16T16:58:22.025 ProcessImageName: httpd.exe, Pid: 3844, TotalTime: 3870, Count: 68, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 18% 2026-05-16T16:58:22.025 ProcessImageName: AcroCEF.exe, Pid: 10800, TotalTime: 3805, Count: 168, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource2\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-16T16:58:22.025 ProcessImageName: AdobeARM.exe, Pid: 6604, TotalTime: 3579, Count: 36, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21529\AcroRdrDCx64Upd2600121563_incr.msp, EstimatedImpact: 6% 2026-05-16T16:58:22.025 ProcessImageName: AsPowerBar.exe, Pid: 3712, TotalTime: 2710, Count: 18, MaxTime: 1062, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 14% 2026-05-16T16:58:22.025 ProcessImageName: Integrator.exe, Pid: 13488, TotalTime: 2538, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Licenses16\ProjectPro2021R_Grace-ul-oob.xrm-ms->(UTF-8), EstimatedImpact: 10% 2026-05-16T16:58:22.025 ProcessImageName: firefox.exe, Pid: 12664, TotalTime: 2538, Count: 188, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09584, EstimatedImpact: 17% 2026-05-16T16:58:22.025 ProcessImageName: VSSVC.exe, Pid: 9380, TotalTime: 2202, Count: 2, MaxTime: 1109, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-05-16T16:58:22.025 ProcessImageName: MOM.exe, Pid: 13000, TotalTime: 2007, Count: 29, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 73% 2026-05-16T16:58:22.025 ProcessImageName: DipAwayMode.exe, Pid: 7188, TotalTime: 1995, Count: 15, MaxTime: 312, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 23% 2026-05-16T16:58:22.025 ProcessImageName: xampp-control.exe, Pid: 5920, TotalTime: 1885, Count: 10, MaxTime: 1593, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T16:58:22.025 ProcessImageName: xampp-control.exe, Pid: 14040, TotalTime: 1885, Count: 10, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 10% 2026-05-16T16:58:22.025 ProcessImageName: dllhost.exe, Pid: 10916, TotalTime: 1883, Count: 66, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\IYXYHJB3M0_10, EstimatedImpact: 38% 2026-05-16T16:58:22.025 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5296, TotalTime: 1731, Count: 73, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\OneDrive.Sync.Service.dll, EstimatedImpact: 16% 2026-05-16T16:58:22.025 ProcessImageName: PartitionWizard.exe, Pid: 2028, TotalTime: 1557, Count: 14, MaxTime: 718, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\PartitionWizard\QtGui4.dll, EstimatedImpact: 76% 2026-05-16T16:58:22.025 ProcessImageName: OfficeClickToRun.exe, Pid: 4300, TotalTime: 1543, Count: 128, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.19929.20172\OfficeClickToRun.exe, EstimatedImpact: 0% 2026-05-16T16:58:22.082 [Engine] RSIG_UNLOADENGINE, 00007FFE03655810, err=0x0 2026-05-16T16:58:22.099 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4842B5BF-75C6-4D98-B1A1-6FFC097FCBB8} removed 2026-05-16T16:58:23.187 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T16:58:23.193 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T16:58:23.195 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T16:58:45.274 Process scan (postsignatureupdatescan) started. 2026-05-16T16:59:07.297 Process scan (postsignatureupdatescan) completed. 2026-05-16T17:03:21.007 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-16T17:06:04.316 [AutoPurge] Cleanup Routine tasks have started. 2026-05-16T17:06:04.330 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-16T17:06:04.334 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-16T17:06:04.334 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-16-2026 17:06:04 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-16-2026 17:06:04 2026-05-16T17:06:04.351 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-16T17:06:04.351 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-16T17:06:04.351 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-16T17:06:04.351 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-16T17:06:04.353 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-16T17:06:04.356 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-16T17:06:04.363 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-16T17:06:04.363 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-16T17:06:04.363 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-16T17:06:04.363 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-16T17:06:04.363 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-16T17:06:04.365 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:B4F16607-B4BB-425D-A530-AD9C866B82B7, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-16T17:06:04.365 Scheduled scan with Id B4F16607-B4BB-425D-A530-AD9C866B82B7 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-16T17:06:04.367 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-16T17:06:04.367 [SFC] System file cache build is not needed (already completed) 2026-05-16T17:06:04.369 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.390 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.409 Engine:EMS scan for process: svchost pid: 560, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.413 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.418 Engine:EMS scan for process: svchost pid: 1196, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.429 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.436 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.440 Engine:EMS scan for process: svchost pid: 1312, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.444 Engine:EMS scan for process: svchost pid: 1320, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.444 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.444 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.460 Engine:EMS scan for process: svchost pid: 1468, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.460 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.472 Engine:EMS scan for process: svchost pid: 1576, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.476 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.476 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.476 Engine:EMS scan for process: svchost pid: 1712, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.476 Engine:EMS scan for process: svchost pid: 1888, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.492 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.492 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.492 Engine:EMS scan for process: svchost pid: 2148, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.503 Engine:EMS scan for process: svchost pid: 2220, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.508 Engine:EMS scan for process: svchost pid: 2340, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.508 Engine:EMS scan for process: svchost pid: 2360, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.508 Engine:EMS scan for process: svchost pid: 2380, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.508 Engine:EMS scan for process: svchost pid: 2388, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.523 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.523 Engine:EMS scan for process: svchost pid: 2552, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.523 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.523 Engine:EMS scan for process: svchost pid: 2672, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.534 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.539 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.539 Engine:EMS scan for process: svchost pid: 3048, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.539 Engine:EMS scan for process: svchost pid: 2136, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.555 Engine:EMS scan for process: svchost pid: 3152, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.555 Engine:EMS scan for process: svchost pid: 3576, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.566 Engine:EMS scan for process: svchost pid: 3584, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.566 Engine:EMS scan for process: svchost pid: 3668, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.571 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.587 Engine:EMS scan for process: svchost pid: 3888, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.603 Engine:EMS scan for process: svchost pid: 3928, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.603 Engine:EMS scan for process: svchost pid: 4064, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.603 Engine:EMS scan for process: svchost pid: 3616, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.618 Engine:EMS scan for process: svchost pid: 4120, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.618 Engine:EMS scan for process: svchost pid: 4316, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.634 Engine:EMS scan for process: svchost pid: 4348, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.634 Engine:EMS scan for process: svchost pid: 4372, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.650 Engine:EMS scan for process: svchost pid: 4652, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.650 Engine:EMS scan for process: svchost pid: 4700, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.650 Engine:EMS scan for process: svchost pid: 4728, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.659 Engine:EMS scan for process: svchost pid: 5488, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.690 Engine:EMS scan for process: dllhost pid: 6128, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.690 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.698 Engine:EMS scan for process: svchost pid: 6264, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.698 Engine:EMS scan for process: svchost pid: 6768, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.713 Engine:EMS scan for process: svchost pid: 6776, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.713 Engine:EMS scan for process: svchost pid: 6840, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.729 Engine:EMS scan for process: svchost pid: 7248, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.729 Engine:EMS scan for process: svchost pid: 7488, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.729 Engine:EMS scan for process: svchost pid: 5496, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.745 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.745 Engine:EMS scan for process: svchost pid: 7220, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.760 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.760 Engine:EMS scan for process: svchost pid: 8352, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.760 Engine:EMS scan for process: explorer pid: 8740, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.843 Engine:EMS scan for process: svchost pid: 8924, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.847 Engine:EMS scan for process: svchost pid: 9036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.853 Engine:EMS scan for process: svchost pid: 6112, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.858 Engine:EMS scan for process: svchost pid: 7768, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.864 Engine:EMS scan for process: svchost pid: 9384, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.869 Engine:EMS scan for process: svchost pid: 10628, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.876 Engine:EMS scan for process: dllhost pid: 10916, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.882 Engine:EMS scan for process: svchost pid: 13448, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.888 Engine:EMS scan for process: svchost pid: 13700, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.891 Engine:EMS scan for process: svchost pid: 13968, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.895 Engine:EMS scan for process: svchost pid: 8368, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.899 Engine:EMS scan for process: svchost pid: 8844, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.911 Engine:EMS scan for process: svchost pid: 4564, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.914 Engine:EMS scan for process: svchost pid: 10324, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:04.917 Engine:EMS scan for process: svchost pid: 6860, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-05-16T17:06:06.378 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:06:06.397 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T17:06:06.399 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:06:06.415 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #34527, FileId: 0x2300000001ad01, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T17:06:37.345 QuickScan:ScanID:054D8AB1-F826-1D84-A08E-55ED59014589: Scan was stopped 2026-05-16T17:06:37.345 QuickScan:ScanID:054D8AB1-F826-1D84-A08E-55ED59014589: Quick scan aborted by callback after end stage 2026-05-16T17:06:37.346 OriginalFileName Maintenance::1 files in Moac, 0 skipped (cached), 0 filename set 2026-05-16T17:06:37.346 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-16T17:06:37.347 RPC Rundown called on ScanID: B4F16607-B4BB-425D-A530-AD9C866B82B7 2026-05-16T17:06:37.347 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:B4F16607-B4BB-425D-A530-AD9C866B82B7. bRemoveFromList(ClientKilled):1 2026-05-16T17:06:37.366 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:B4F16607-B4BB-425D-A530-AD9C866B82B7 2026-05-16T17:06:37.366 QuickScan:ScanID:B4F16607-B4BB-425D-A530-AD9C866B82B7: Scan was stopped 2026-05-16T17:06:37.367 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:B4F16607-B4BB-425D-A530-AD9C866B82B7 2026-05-16T17:06:37.367 QuickScan:ScanID:B4F16607-B4BB-425D-A530-AD9C866B82B7: Quick scan aborted by callback after end stage 2026-05-16T17:06:37.367 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:B4F16607-B4BB-425D-A530-AD9C866B82B7 2026-05-16T17:06:37.367 OnDemandScanWorker: Scan Cancelled! scanId:B4F16607-B4BB-425D-A530-AD9C866B82B7, hr = 0x80508018 2026-05-16T17:06:39.390 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:06:39.396 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T17:06:39.397 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:07:55.833 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T17:10:43.008 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-16T17:10:43.009 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-16T17:10:43.009 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-16T17:10:43.009 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-16T17:10:43.009 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-16T17:10:43.009 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-16T17:10:43.010 [AutoPurge] Cleanup Routine tasks have started. 2026-05-16T17:10:43.016 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-16T17:10:43.019 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:7389DDD5-571A-4F03-87D6-533F62E06528, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-16T17:10:43.020 Scheduled scan with Id 7389DDD5-571A-4F03-87D6-533F62E06528 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-16T17:10:43.020 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-16T17:10:43.021 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-16-2026 17:10:43 2026-05-16T17:10:43.021 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-16T17:10:43.021 [SFC] System file cache build is not needed (already completed) Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-16-2026 17:10:43 2026-05-16T17:10:43.031 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-16T17:10:43.031 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-16T17:10:43.031 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-16T17:10:43.031 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-16T17:10:43.031 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-16T17:10:43.032 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-16T17:10:44.293 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #34760, FileId: 0x2700000001ad01, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T17:10:45.032 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:10:45.039 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T17:10:45.039 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:10:56.920 Engine:Triggered AR EMS scan 2026-05-16T17:10:56.923 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.939 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.954 Engine:EMS scan for process: svchost pid: 560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.958 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.962 Engine:EMS scan for process: svchost pid: 1196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.972 Engine:EMS scan for process: svchost pid: 1216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.977 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.982 Engine:EMS scan for process: svchost pid: 1312, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.986 Engine:EMS scan for process: svchost pid: 1320, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.988 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.990 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.995 Engine:EMS scan for process: svchost pid: 1468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:56.997 Engine:EMS scan for process: svchost pid: 1524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.007 Engine:EMS scan for process: svchost pid: 1576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.011 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.014 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.021 Engine:EMS scan for process: svchost pid: 1712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.024 Engine:EMS scan for process: svchost pid: 1888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.030 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.032 Engine:EMS scan for process: svchost pid: 2092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.034 Engine:EMS scan for process: svchost pid: 2148, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.039 Engine:EMS scan for process: svchost pid: 2220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.046 Engine:EMS scan for process: svchost pid: 2340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.048 Engine:EMS scan for process: svchost pid: 2360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.050 Engine:EMS scan for process: svchost pid: 2380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.052 Engine:EMS scan for process: svchost pid: 2388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.054 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.057 Engine:EMS scan for process: svchost pid: 2552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.059 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.061 Engine:EMS scan for process: svchost pid: 2672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.063 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.066 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.070 Engine:EMS scan for process: svchost pid: 3048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.076 Engine:EMS scan for process: svchost pid: 2136, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.078 Engine:EMS scan for process: svchost pid: 3152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.087 Engine:EMS scan for process: svchost pid: 3576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.092 Engine:EMS scan for process: svchost pid: 3584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.101 Engine:EMS scan for process: svchost pid: 3668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.106 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.119 Engine:EMS scan for process: svchost pid: 3888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.124 Engine:EMS scan for process: svchost pid: 3928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.127 Engine:EMS scan for process: svchost pid: 4064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.130 Engine:EMS scan for process: svchost pid: 3616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.136 Engine:EMS scan for process: svchost pid: 4120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.139 Engine:EMS scan for process: svchost pid: 4316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.144 Engine:EMS scan for process: svchost pid: 4348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.151 Engine:EMS scan for process: svchost pid: 4372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.157 Engine:EMS scan for process: svchost pid: 4652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.161 Engine:EMS scan for process: svchost pid: 4700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.162 Engine:EMS scan for process: svchost pid: 4728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.168 Engine:EMS scan for process: svchost pid: 5488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.174 Engine:EMS scan for process: dllhost pid: 6128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.176 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.179 Engine:EMS scan for process: svchost pid: 6264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.181 Engine:EMS scan for process: svchost pid: 6768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.188 Engine:EMS scan for process: svchost pid: 6776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.196 Engine:EMS scan for process: svchost pid: 6840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.198 Engine:EMS scan for process: svchost pid: 7248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.202 Engine:EMS scan for process: svchost pid: 7488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.204 Engine:EMS scan for process: svchost pid: 5496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.208 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.218 Engine:EMS scan for process: svchost pid: 7220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.227 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.232 Engine:EMS scan for process: svchost pid: 8352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.234 Engine:EMS scan for process: explorer pid: 8740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.281 Engine:EMS scan for process: svchost pid: 8924, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.286 Engine:EMS scan for process: svchost pid: 9036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.290 Engine:EMS scan for process: svchost pid: 6112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.293 Engine:EMS scan for process: svchost pid: 7768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.299 Engine:EMS scan for process: svchost pid: 9384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.302 Engine:EMS scan for process: svchost pid: 10628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.307 Engine:EMS scan for process: dllhost pid: 10916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.310 Engine:EMS scan for process: svchost pid: 13448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.314 Engine:EMS scan for process: svchost pid: 13700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.316 Engine:EMS scan for process: svchost pid: 13968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.321 Engine:EMS scan for process: svchost pid: 8368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.323 Engine:EMS scan for process: svchost pid: 8844, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.330 Engine:EMS scan for process: svchost pid: 4564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:10:57.332 Engine:EMS scan for process: svchost pid: 10324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-16T17:15:25.404 QuickScan:ScanID:7389DDD5-571A-4F03-87D6-533F62E06528: Quick scan finished with error 0 2026-05-16T17:15:25.939 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-16T17:15:25.939 [RTP] Duplicating the current plugin configuration object... 2026-05-16T17:15:25.940 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-16T17:15:25.940 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-16T17:15:25.941 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-16T17:15:25.941 [RTP] No config change detected. Not updating plugin configuration. 2026-05-16T17:15:25.941 [RTP] No config changes found. No configuration switch. 2026-05-16T17:15:25.941 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-16T17:15:27.428 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-16T17:15:27.441 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-16T17:15:27.441 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x714dea5e 2026-05-16T17:19:44.249 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #36279, FileId: 0xba00000000db95, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T17:23:00.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T17:38:05.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T17:53:10.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T18:08:15.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T18:23:20.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{B39D2681-6ADE-FC12-9219-242BEF78ED07} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:12512 ProcessCreationTime:134234241142148561 SessionID:2 CreationTime:05-16-2026 18:30:52 ImagePath:E:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-05-16T18:30:53.910 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T18:30:53.910 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T18:30:53.910 [Cloud] Queued cloud request. 2026-05-16T18:30:53.910 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T18:30:53.910 [Cloud] Dequeued cloud request. 2026-05-16T18:30:53.910 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T18:30:54.254 [Cloud] End of cloud request. 2026-05-16T18:30:54.769 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T18:38:25.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T18:53:30.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T18:58:20.988 ProcessImageName: setup.exe, Pid: 11988, TotalTime: 9095, Count: 407, MaxTime: 3937, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.70\msedge.dll, EstimatedImpact: 23% 2026-05-16T18:58:20.988 ProcessImageName: explorer.exe, Pid: 8740, TotalTime: 5058, Count: 106, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 6860, TotalTime: 2187, Count: 2, MaxTime: 1109, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 3008, TotalTime: 1123, Count: 4, MaxTime: 968, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 1% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 3644, TotalTime: 1061, Count: 2, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOC678.tmp, EstimatedImpact: 37% 2026-05-16T18:58:20.988 ProcessImageName: WmiPrvSE.exe, Pid: 10984, TotalTime: 707, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys, EstimatedImpact: 85% 2026-05-16T18:58:20.988 ProcessImageName: backgroundTaskHost.exe, Pid: 14108, TotalTime: 240, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 12% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 213, Count: 13, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: ngentask.exe, Pid: 3088, TotalTime: 180, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-16T18:58:20.988 ProcessImageName: AdobeARM.exe, Pid: 11420, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70_148.0.3967.54.exe, Pid: 14112, TotalTime: 124, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{C36D9A47-0CD0-45AE-B12E-7570C8EEEFAC}\EDGEMITMP_AA2BF.tmp\setup.exe, EstimatedImpact: 65% 2026-05-16T18:58:20.988 ProcessImageName: OfficeC2RClient.exe, Pid: 11464, TotalTime: 107, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-16T18:58:20.988 ProcessImageName: ngentask.exe, Pid: 10828, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-05-16T18:58:20.988 ProcessImageName: SecurityHealthHost.exe, Pid: 2712, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 2092, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 24% 2026-05-16T18:58:20.988 ProcessImageName: AdobeARM.exe, Pid: 1148, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 6% 2026-05-16T18:58:20.988 ProcessImageName: httpd.exe, Pid: 7472, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: PhoneExperienceHost.exe, Pid: 9944, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 9% 2026-05-16T18:58:20.988 ProcessImageName: taskhostw.exe, Pid: 13724, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: AggregatorHost.exe, Pid: 5672, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5296, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_30070D1E013A39CA7A94F919F7922FDF, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: OfficeC2RClient.exe, Pid: 6252, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1910.log, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: OfficeClickToRun.exe, Pid: 13056, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: OfficeC2RClient.exe, Pid: 13456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1919.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 12196, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[9].htm, EstimatedImpact: 0% 2026-05-16T18:58:20.988 ProcessImageName: svchost.exe, Pid: 8844, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-16T19:08:35.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T19:23:40.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T19:38:45.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T19:49:18.506 Engine:Process 7888 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-16T19:53:50.831 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T19:54:40.282 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38297, FileId: 0x9b000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.283 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38301, FileId: 0x33000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.293 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38302, FileId: 0x9d000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.295 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38304, FileId: 0x34000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.297 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38305, FileId: 0xa0000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.299 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38306, FileId: 0x36000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.301 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38300, FileId: 0x9c000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.303 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38308, FileId: 0x37000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.319 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38310, FileId: 0xa4000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.327 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38313, FileId: 0xa5000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.327 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38314, FileId: 0x3c000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.329 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38315, FileId: 0xa6000000006273, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.330 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38312, FileId: 0x3a000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.331 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #38311, FileId: 0x39000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T19:54:40.712 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13f9ee6c-0937-4ffb-a21b-a7e5f5fb803b. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #38347, FileId: 0x270000000038de, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:04:28.824 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #39613, FileId: 0x49000000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:04:58.762 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #39638, FileId: 0x3c0000000113c5, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:04:58.762 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #39636, FileId: 0xb800000000d828, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:08:55.835 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T20:09:54.720 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #41355, FileId: 0x4a00000001ac0f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:14:22.028 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #41474, FileId: 0x240000000399c6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:22:36.957 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Recent\Anmeldung!!!.txt.lnk. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0xc0000001, State: 0, ScanRequest #41997, FileId: 0x27000000041cef, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{2F5F9F85-C6E4-B5FC-2406-F2C869499979} SignatureID:340520518878414 SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0 ThreatLevel:0 ProcessID:13852 ProcessCreationTime:134234353695819649 SessionID:2 CreationTime:05-16-2026 20:23:40 ImagePath:E:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-05-16T20:23:40.868 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T20:23:40.868 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T20:23:40.868 [Cloud] Queued cloud request. 2026-05-16T20:23:40.868 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T20:23:40.868 [Cloud] Dequeued cloud request. 2026-05-16T20:23:40.868 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T20:23:40.881 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-05-16T20:23:40.881 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T20:23:40.881 [Cloud] Queued cloud request. 2026-05-16T20:23:40.881 [Cloud] Dequeued cloud request. 2026-05-16T20:23:40.884 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T20:23:41.090 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-16T20:23:41.090 [Cloud] End of cloud request. 2026-05-16T20:23:41.180 [Cloud] End of cloud request. 2026-05-16T20:23:41.610 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T20:24:00.838 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T20:30:45.675 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume10\xampp\tmp\#sql2f70_3f_1.MAI. Process: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #43256, FileId: 0x20000000065fb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:39:05.834 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T20:51:51.139 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #44912, FileId: 0x22000000083e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T20:53:26.924 Engine:Process 10464 will be fully monitored because of injection from C:\Windows\System32\csrss.exe Internal signature match:subtype=Lowfi, sigseq=0x00002496403FB386, sigsha=1376e08e997c983466ef8ed6d2f059ea4387d219, cached=false, source=0, resourceid=0x184da864 2026-05-16T20:54:05.900 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T20:54:05.900 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T20:54:05.900 [Cloud] Queued cloud request. 2026-05-16T20:54:05.900 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T20:54:05.901 [Cloud] Dequeued cloud request. 2026-05-16T20:54:05.901 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T20:54:06.553 [Cloud] End of cloud request. 2026-05-16T20:54:07.064 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T20:54:10.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x00000555B70B128F, sigsha=07da825a667cd3bb26d41c4b11148c865f10ecb4, cached=false, source=0, resourceid=0x25212307 2026-05-16T20:54:20.296 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T20:54:20.296 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T20:54:20.296 [Cloud] Queued cloud request. 2026-05-16T20:54:20.296 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T20:54:20.296 [Cloud] Dequeued cloud request. 2026-05-16T20:54:20.296 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T20:54:20.907 [Cloud] End of cloud request. 2026-05-16T20:54:21.422 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00012096A98AC33B, sigsha=b06dee4b6287392df45840762a1caa467a845804, cached=false, source=0, resourceid=0x3e4f4ced 2026-05-16T20:54:22.535 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-16T20:54:22.535 [Cloud] Start of cloud request. Passive mode: 0 2026-05-16T20:54:22.535 [Cloud] Queued cloud request. 2026-05-16T20:54:22.535 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-16T20:54:22.535 [Cloud] Dequeued cloud request. 2026-05-16T20:54:22.535 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-16T20:54:22.565 [Cloud] End of cloud request. 2026-05-16T20:54:23.078 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-16T20:55:20.614 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #45076, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x00000555498DA744, sigsha=f9fe7263cd98e932bfa7989bfe514ab1a1359a57, cached=false, source=0, resourceid=0xe0e80e4b 2026-05-16T20:57:37.461 ExpensiveContainer:Scan time for `\\?\C:\Users\ITHAN\Downloads\webtrees-2.2.6.zip` is 259718 units 2026-05-16T20:57:37.462 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb2b1367f7ffffffe 2026-05-16T20:57:37.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xbcedd8417ffffffe 2026-05-16T20:57:37.465 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x82c1ae307ffffffe 2026-05-16T20:57:37.496 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 4 resources, RtpIoavOnly: TRUE 2026-05-16T20:58:20.991 ProcessImageName: httpd.exe, Pid: 13852, TotalTime: 39038, Count: 2522, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\Web-IPTV-Player-master_1\dist\clappr.js, EstimatedImpact: 1% 2026-05-16T20:58:20.991 ProcessImageName: setup.exe, Pid: 11988, TotalTime: 9095, Count: 407, MaxTime: 3937, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.70\msedge.dll, EstimatedImpact: 23% 2026-05-16T20:58:20.991 ProcessImageName: explorer.exe, Pid: 8740, TotalTime: 6839, Count: 212, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: dllhost.exe, Pid: 10916, TotalTime: 3444, Count: 80, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\CE44YDXXWC_27, EstimatedImpact: 58% 2026-05-16T20:58:20.991 ProcessImageName: svchost.exe, Pid: 6860, TotalTime: 2187, Count: 2, MaxTime: 1109, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-05-16T20:58:20.991 ProcessImageName: xampp-control.exe, Pid: 6728, TotalTime: 1903, Count: 7, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 68% 2026-05-16T20:58:20.991 ProcessImageName: xampp-control.exe, Pid: 9908, TotalTime: 1669, Count: 8, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: powershell.exe, Pid: 10464, TotalTime: 1530, Count: 58, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: mysqld.exe, Pid: 8244, TotalTime: 1247, Count: 120, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 66% 2026-05-16T20:58:20.991 ProcessImageName: svchost.exe, Pid: 3008, TotalTime: 1123, Count: 4, MaxTime: 968, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 1% 2026-05-16T20:58:20.991 ProcessImageName: svchost.exe, Pid: 3644, TotalTime: 1061, Count: 2, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOC678.tmp, EstimatedImpact: 37% 2026-05-16T20:58:20.991 ProcessImageName: notepad++.exe, Pid: 8464, TotalTime: 766, Count: 56, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: mysqld.exe, Pid: 6548, TotalTime: 721, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\webtrees\wt_other.ibd, EstimatedImpact: 3% 2026-05-16T20:58:20.991 ProcessImageName: WmiPrvSE.exe, Pid: 10984, TotalTime: 707, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys, EstimatedImpact: 85% 2026-05-16T20:58:20.991 ProcessImageName: firefox.exe, Pid: 12792, TotalTime: 696, Count: 53, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13004, EstimatedImpact: 53% 2026-05-16T20:58:20.991 ProcessImageName: SDXHelper.exe, Pid: 7884, TotalTime: 527, Count: 18, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 29% 2026-05-16T20:58:20.991 ProcessImageName: Photos.exe, Pid: 9568, TotalTime: 498, Count: 36, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 8% 2026-05-16T20:58:20.991 ProcessImageName: mysqld.exe, Pid: 6644, TotalTime: 390, Count: 154, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\webtrees\db.opt, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: httpd.exe, Pid: 3804, TotalTime: 348, Count: 77, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 19% 2026-05-16T20:58:20.991 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 273, Count: 19, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: httpd.exe, Pid: 8992, TotalTime: 271, Count: 77, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 15% 2026-05-16T20:58:20.991 ProcessImageName: backgroundTaskHost.exe, Pid: 14108, TotalTime: 240, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 12% 2026-05-16T20:58:20.991 ProcessImageName: TabTip.exe, Pid: 6696, TotalTime: 202, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-16T20:58:20.991 ProcessImageName: ngentask.exe, Pid: 3088, TotalTime: 180, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-16T20:58:20.991 ProcessImageName: AdobeARM.exe, Pid: 11420, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: Notepad.exe, Pid: 12884, TotalTime: 135, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\ac80c18d-13e7-4629-899e-40a6cf814df4.0.bin, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70_148.0.3967.54.exe, Pid: 14112, TotalTime: 124, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{C36D9A47-0CD0-45AE-B12E-7570C8EEEFAC}\EDGEMITMP_AA2BF.tmp\setup.exe, EstimatedImpact: 65% 2026-05-16T20:58:20.991 ProcessImageName: OfficeC2RClient.exe, Pid: 11464, TotalTime: 107, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-16T20:58:20.991 ProcessImageName: ngentask.exe, Pid: 10828, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-05-16T20:58:20.991 ProcessImageName: FileCoAuth.exe, Pid: 6884, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\general.keystore, EstimatedImpact: 1% 2026-05-16T20:58:20.991 ProcessImageName: SecurityHealthHost.exe, Pid: 2712, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-05-16T20:58:20.991 ProcessImageName: svchost.exe, Pid: 2092, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 24% 2026-05-16T20:58:20.991 ProcessImageName: AdobeARM.exe, Pid: 1148, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 6% 2026-05-16T20:58:20.991 ProcessImageName: PhoneExperienceHost.exe, Pid: 9944, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: notepad++.exe, Pid: 8648, TotalTime: 61, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: httpd.exe, Pid: 7472, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: dasHost.exe, Pid: 5664, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-16T20:58:20.991 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 9% 2026-05-16T20:58:20.991 ProcessImageName: TeamViewer.exe, Pid: 3636, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 43% 2026-05-16T20:58:20.991 ProcessImageName: AggregatorHost.exe, Pid: 5672, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: OfficeC2RClient.exe, Pid: 1616, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2251.log, EstimatedImpact: 2% 2026-05-16T20:58:20.992 ProcessImageName: RUXIMICS.exe, Pid: 1804, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\ctac.json, EstimatedImpact: 8% 2026-05-16T20:58:20.992 ProcessImageName: Notepad.exe, Pid: 7792, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\rezervi3\LIZENZ.txt, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: backgroundTaskHost.exe, Pid: 6564, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1778964592, EstimatedImpact: 6% 2026-05-16T20:58:20.992 ProcessImageName: taskhostw.exe, Pid: 13724, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: OfficeC2RClient.exe, Pid: 13952, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2214.log, EstimatedImpact: 1% 2026-05-16T20:58:20.992 ProcessImageName: Notepad.exe, Pid: 3008, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\ac80c18d-13e7-4629-899e-40a6cf814df4.1.bin, EstimatedImpact: 2% 2026-05-16T20:58:20.992 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5296, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_30070D1E013A39CA7A94F919F7922FDF, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: OfficeC2RClient.exe, Pid: 6252, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1910.log, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: OfficeClickToRun.exe, Pid: 13056, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: OfficeC2RClient.exe, Pid: 13456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1919.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: dllhost.exe, Pid: 6128, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 12196, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[9].htm, EstimatedImpact: 0% 2026-05-16T20:58:20.992 ProcessImageName: svchost.exe, Pid: 8844, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-16T20:59:59.088 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #45360, FileId: 0x110000000bd68f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:09:15.835 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T21:12:37.639 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #46304, FileId: 0x1b0000000c4adc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:24:20.835 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T21:29:29.904 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #47145, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:29:29.904 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #47144, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:39:25.826 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T21:49:05.225 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47830, FileId: 0xb0000000c4b6d, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.229 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47833, FileId: 0x48000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.229 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47831, FileId: 0x42000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.236 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47835, FileId: 0x49000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.236 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47836, FileId: 0x130000000c4b6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.239 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47838, FileId: 0x140000000c4b6d, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.241 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47834, FileId: 0x120000000c4b6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.243 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47839, FileId: 0x150000000c4b6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.252 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47829, FileId: 0x40000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.656 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #47871, FileId: 0x4d000000033122, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:49:05.667 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\318e656c-b42c-4c91-ab2c-f8431ec8cec5. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #47873, FileId: 0x3d00000000ee68, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T21:54:30.837 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T22:09:35.837 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T22:17:26.717 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #48891, FileId: 0x140000000c4b78, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T22:24:40.831 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T22:29:33.443 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #49127, FileId: 0x18f00000000ce23, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T22:39:45.832 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T22:48:48.980 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #49385, FileId: 0xa0000000c4b89, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-16T22:54:50.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 13852, TotalTime: 39038, Count: 2522, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\Web-IPTV-Player-master_1\dist\clappr.js, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: setup.exe, Pid: 11988, TotalTime: 9095, Count: 407, MaxTime: 3937, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.70\msedge.dll, EstimatedImpact: 23% 2026-05-16T22:58:21.011 ProcessImageName: explorer.exe, Pid: 8740, TotalTime: 8254, Count: 302, MaxTime: 1359, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: dllhost.exe, Pid: 10916, TotalTime: 3444, Count: 80, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\CE44YDXXWC_27, EstimatedImpact: 58% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 6860, TotalTime: 2187, Count: 2, MaxTime: 1109, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-05-16T22:58:21.011 ProcessImageName: xampp-control.exe, Pid: 6728, TotalTime: 1948, Count: 10, MaxTime: 1656, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: xampp-control.exe, Pid: 9908, TotalTime: 1669, Count: 8, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: powershell.exe, Pid: 10464, TotalTime: 1530, Count: 58, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: notepad++.exe, Pid: 14308, TotalTime: 1322, Count: 96, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\config.php@2026-05-17_000522, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 8244, TotalTime: 1292, Count: 123, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 3008, TotalTime: 1123, Count: 4, MaxTime: 968, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 3644, TotalTime: 1061, Count: 2, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOC678.tmp, EstimatedImpact: 37% 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 12120, TotalTime: 975, Count: 58, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_myWebApps\oneye\index.html, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: notepad++.exe, Pid: 8464, TotalTime: 766, Count: 56, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 6548, TotalTime: 721, Count: 75, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\webtrees\wt_other.ibd, EstimatedImpact: 3% 2026-05-16T22:58:21.011 ProcessImageName: WmiPrvSE.exe, Pid: 10984, TotalTime: 707, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys, EstimatedImpact: 85% 2026-05-16T22:58:21.011 ProcessImageName: firefox.exe, Pid: 12792, TotalTime: 696, Count: 53, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13004, EstimatedImpact: 53% 2026-05-16T22:58:21.011 ProcessImageName: PDFXCview.exe, Pid: 9564, TotalTime: 615, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 44% 2026-05-16T22:58:21.011 ProcessImageName: SDXHelper.exe, Pid: 7884, TotalTime: 527, Count: 18, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 29% 2026-05-16T22:58:21.011 ProcessImageName: Photos.exe, Pid: 9568, TotalTime: 498, Count: 36, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\drivers\hidparse.sys, EstimatedImpact: 8% 2026-05-16T22:58:21.011 ProcessImageName: OpenWith.exe, Pid: 2252, TotalTime: 427, Count: 24, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7z.exe, EstimatedImpact: 2% 2026-05-16T22:58:21.011 ProcessImageName: firefox.exe, Pid: 6328, TotalTime: 420, Count: 37, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03096, EstimatedImpact: 52% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 6644, TotalTime: 390, Count: 154, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\webtrees\db.opt, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 1440, TotalTime: 363, Count: 25, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 3804, TotalTime: 348, Count: 77, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 19% 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 8992, TotalTime: 271, Count: 77, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\php5ts.dll, EstimatedImpact: 15% 2026-05-16T22:58:21.011 ProcessImageName: splwow64.exe, Pid: 3520, TotalTime: 270, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms012.inf_amd64_fdcf98606e2a57a5\Amd64\MSIPP-manifest.ini, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: backgroundTaskHost.exe, Pid: 14108, TotalTime: 240, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 12% 2026-05-16T22:58:21.011 ProcessImageName: TabTip.exe, Pid: 6696, TotalTime: 202, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-16T22:58:21.011 ProcessImageName: ngentask.exe, Pid: 3088, TotalTime: 180, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-16T22:58:21.011 ProcessImageName: AdobeARM.exe, Pid: 11420, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\apppatch\sysmain.sdb, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: RuntimeBroker.exe, Pid: 10504, TotalTime: 155, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\python\PortablePython_3.9.2.0x64__WPy64-3920\WinPython Powershell Prompt.exe, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: Notepad.exe, Pid: 12884, TotalTime: 135, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\ac80c18d-13e7-4629-899e-40a6cf814df4.0.bin, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70_148.0.3967.54.exe, Pid: 14112, TotalTime: 124, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{C36D9A47-0CD0-45AE-B12E-7570C8EEEFAC}\EDGEMITMP_AA2BF.tmp\setup.exe, EstimatedImpact: 65% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 11464, TotalTime: 107, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-16T22:58:21.011 ProcessImageName: ngentask.exe, Pid: 10828, TotalTime: 105, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: PhoneExperienceHost.exe, Pid: 9944, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: FileCoAuth.exe, Pid: 6884, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\general.keystore, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: SecurityHealthHost.exe, Pid: 2712, TotalTime: 90, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 14844, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 2092, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 24% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 3296, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 7% 2026-05-16T22:58:21.011 ProcessImageName: AdobeARM.exe, Pid: 1148, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 6% 2026-05-16T22:58:21.011 ProcessImageName: notepad++.exe, Pid: 8648, TotalTime: 61, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: notepad++.exe, Pid: 14200, TotalTime: 61, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 42% 2026-05-16T22:58:21.011 ProcessImageName: notepad++.exe, Pid: 2440, TotalTime: 61, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 1792, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 7472, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\HTTP_NOT_FOUND.html.var, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: svchost.exe, Pid: 1100, TotalTime: 61, Count: 2, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: dasHost.exe, Pid: 5664, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: dllhost.exe, Pid: 6128, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: SDXHelper.exe, Pid: 12936, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 9% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 3840, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: mysqld.exe, Pid: 4176, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: TeamViewer.exe, Pid: 3636, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 43% 2026-05-16T22:58:21.011 ProcessImageName: spoolsv.exe, Pid: 4012, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\config.php.pdf, EstimatedImpact: 2% 2026-05-16T22:58:21.011 ProcessImageName: AggregatorHost.exe, Pid: 5672, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: Notepad.exe, Pid: 14984, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8a6a91f6-0335-43f6-a862-40f6cdf93c4b.0.bin, EstimatedImpact: 7% 2026-05-16T22:58:21.011 ProcessImageName: Notepad.exe, Pid: 11736, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_myWebApps\Webftp\webftp-ajax\webFTP_2.0\readme.txt, EstimatedImpact: 6% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 1616, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2251.log, EstimatedImpact: 2% 2026-05-16T22:58:21.011 ProcessImageName: RUXIMICS.exe, Pid: 1804, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\ctac.json, EstimatedImpact: 8% 2026-05-16T22:58:21.011 ProcessImageName: FileCoAuth.exe, Pid: 15128, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-16.2248.15128.1.aodl, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: httpd.exe, Pid: 14664, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\favicon.ico, EstimatedImpact: 7% 2026-05-16T22:58:21.011 ProcessImageName: Notepad.exe, Pid: 7792, TotalTime: 30, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\0_\rezervi3\LIZENZ.txt, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: backgroundTaskHost.exe, Pid: 6564, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1778964592, EstimatedImpact: 6% 2026-05-16T22:58:21.011 ProcessImageName: taskhostw.exe, Pid: 13724, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 9460, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2259.log, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 13952, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2214.log, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 6648, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-2312.log, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: dllhost.exe, Pid: 15128, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: Notepad.exe, Pid: 3008, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\ac80c18d-13e7-4629-899e-40a6cf814df4.1.bin, EstimatedImpact: 2% 2026-05-16T22:58:21.011 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 5296, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_30070D1E013A39CA7A94F919F7922FDF, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: SDXHelper.exe, Pid: 5152, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 1% 2026-05-16T22:58:21.011 ProcessImageName: OfficeClickToRun.exe, Pid: 13056, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 4880, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-0029.log, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 13456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1919.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 11460, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-0017.log, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: OfficeC2RClient.exe, Pid: 6252, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260516-1910.log, EstimatedImpact: 0% 2026-05-16T22:58:21.011 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 12196, TotalTime: 0, Count: 6, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\xq-start[9].htm, EstimatedImpact: 0% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-17-2026 07:21:33 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/17/2026 07:21:33.510956900 UTC (13234 ms since boot) 2026-05-17T07:21:33.526 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-17T07:21:33.531 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T07:21:33.531 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T07:21:33.556 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260517-072133-00000003-fffffffeffffffff.bin ... 2026-05-17T07:21:33.644 [WPP] Trace session started - MpWppTracing-20260517-072133-00000003-fffffffeffffffff.bin 2026-05-17T07:21:33.646 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-17T07:21:33.646 [RbM] Rollback manager succesfully initialized. 2026-05-17T07:21:33.646 [RbM] Rollback manager EnableRollbackManager called. 2026-05-17T07:21:33.656 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-17T07:21:33.656 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-17T07:21:33.656 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-17T07:21:33.656 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-17T07:21:33.656 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-17T07:21:33.659 MdCoreSvc is supported in this platform and OS 2026-05-17T07:21:33.659 MdCoreSvc is supported in this platform and OS 2026-05-17T07:21:33.659 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-17T07:21:33.659 [PlatUpd] Starting MdCoreSvc service 2026-05-17T07:21:33.710 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-17T07:21:37.281 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-17T07:21:37.281 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-17T07:21:37.281 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-17T07:21:37.281 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-17T07:21:37.281 [PlatUpd] CSP platform update started 2026-05-17T07:21:37.281 [PlatUpd] Defender MDM CSP platform update not required 2026-05-17T07:21:37.281 [PlatUpd] WMI/PS provider platform update started 2026-05-17T07:21:37.281 [PlatUpd] WMI/PS provider platform update not required 2026-05-17T07:21:37.281 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-17T07:21:37.281 MdCoreSvc is supported in this platform and OS 2026-05-17T07:21:37.281 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-17T07:21:37.281 [PlatUpd] Starting MdCoreSvc service 2026-05-17T07:21:37.281 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-17T07:21:37.281 [TS] Troubleshooting mode is not available! 2026-05-17T07:21:37.281 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-17T07:21:37.281 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-17T07:21:37.312 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-17T07:21:37.312 [Service] Enabling AutoLoggers ... 2026-05-17T07:21:37.312 [Service] Enabling AMSI registration ... 2026-05-17T07:21:37.312 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-17T07:21:37.328 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 47295 Number of invalid entries is 0 Number of inserts issued is 1589639 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6527 Number of lookups is 108458089 Number of lookup misses is 5208551 Number of fast lookup misses is 55265463 Number of false fast lookups is 5208546 Number of invalidations is 735817 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-17T07:21:37.328 Verifying license file... 2026-05-17T07:21:37.328 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-17T07:21:37.343 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-17T07:21:37.343 Loaded module#0 MpComServer. 2026-05-17T07:21:37.343 Loaded module#1 StartupPolicies. 2026-05-17T07:21:37.343 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-17T07:21:37.359 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T07:21:37.359 COM server initialized successfully. 2026-05-17T07:21:37.375 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-17T07:21:37.390 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-17T07:21:37.390 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-17T07:21:37.406 [RTP] [RTP] FilterCommunicator object 0x000001919CAA2E10 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-17T07:21:37.406 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-17T07:21:37.406 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T07:21:37.406 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T07:21:37.406 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-17T07:21:37.406 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-17T07:21:37.406 [RTP] [RTP] FilterCommunicator object 0x000001919CAA3020 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-17T07:21:37.406 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-17T07:21:37.406 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-17T07:21:37.406 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-17T07:21:37.406 [RTP] [RTP] StartCommunication 0x000001919CAA2E10 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-17T07:21:37.406 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-17T07:21:37.406 [init][RTP] RTPPlugin initialization completed 2026-05-17T07:21:37.406 OS boot count = 2 2026-05-17T07:21:37.406 OS Install = 0 2026-05-17T07:21:37.421 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-17T07:21:37.421 [KSL] Entering CKSLEngine::Initialize. 2026-05-17T07:21:37.421 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-17T07:21:37.421 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-17T07:21:37.421 [KSL] MpInstallKslD: hr=0x1 2026-05-17T07:21:37.421 [KSL] MpRegisterKslD: hr=0 2026-05-17T07:21:37.437 [KSL] MpStartKslD: hr=0 2026-05-17T07:21:37.437 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T07:21:37.437 Loading engine... 2026-05-17T07:21:37.453 Verifying engine and signature files (source: 1) ... 2026-05-17T07:21:37.453 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpengine.dll] due to PPL. 2026-05-17T07:21:37.453 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasbase.vdm] (file in cache) 2026-05-17T07:21:37.453 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasdlta.vdm] (file in cache) 2026-05-17T07:21:37.453 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavbase.vdm] (file in cache) 2026-05-17T07:21:37.453 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpavdlta.vdm] (file in cache) 2026-05-17T07:21:37.484 [Engine] IsHybridMode: 0 2026-05-17T07:21:37.484 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-17T07:21:37.515 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-0F40909C867D4F2274B01C6C7704085D27C4E4FE.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-17T07:21:41.406 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-17T07:21:41.406 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-17T07:21:41.406 [Engine] New active engine 00007FF862155810 (no old engine). Number of active engines: 1 2026-05-17T07:21:41.421 EngineInit:Global ASOC is enabled 2026-05-17T07:21:41.421 EngineInit:ASOO is enabled for developer volumes 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:21:41.500 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4403b4e3a3ef7366fe9b909d6c45d5014b00bef6 Dynamic Signature Compilation Timestamp:05-16-2026 16:50:49 Persistence Type:Duration Time remaining:288000000 2026-05-17T07:21:41.531 Dynamic signature dropped 2026-05-17T07:21:41.531 MpWriteUupSignatureVersion 1.449.649.0, hr = 0 2026-05-17T07:21:41.547 [SigStatUpd] CSignatureStatus: back to good 2026-05-17T07:21:41.547 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-17T07:21:41.562 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-17T07:21:41.562 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T07:21:41.562 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-17T07:21:41.562 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-17T07:21:41.562 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T07:21:41.578 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-17T07:21:41.578 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2070 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:11491 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2229 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-17T07:21:41.578 [Plugin] Initializing RTP plugin state... 2026-05-17T07:21:41.578 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-17T07:21:41.578 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152} 2026-05-17T07:21:41.578 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:21:41.578 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:21:41.578 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:21:41.578 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T07:21:41.578 MdCoreSvc is supported in this platform and OS 2026-05-17T07:21:41.578 Engine loaded! 2026-05-17T07:21:41.578 [DLP] Create FeatureControlState instance 2026-05-17T07:21:41.578 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-17T07:21:41.578 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-17T07:21:41.593 RegisterSModeChangeListener: hr = 0x1 2026-05-17T07:21:41.593 RegisterHybridModeChangeListener: hr = 0 2026-05-17T07:21:41.593 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-17T07:21:41.593 [SigReleaseHb] Initialized with Stage 0 2026-05-17T07:21:41.593 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-17T07:21:41.593 [SCC][CID=21312_5344] Initializing ... 2026-05-17T07:21:41.593 [SCC][CID=21312_5344] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-17T07:21:41.593 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-17T07:21:41.593 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-17T07:21:41.609 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T07:21:41.609 [NRI] Stopping NIS service ... 2026-05-17T07:21:41.609 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-17T07:21:41.609 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.649.0 AV Signature Version: 1.449.649.0 ************************************************************ 2026-05-17T07:21:41.609 Resource usage Monitoring is enabled 2026-05-17T07:21:41.609 Job Notification: New process added to job (4488) 2026-05-17T07:21:41.609 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-17T07:21:41.625 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7060] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:6948]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T07:21:41.687 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-17T07:21:41.687 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T07:21:41.687 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-17T07:21:41.687 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T07:21:41.687 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T07:21:41.687 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T07:21:41.687 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T07:21:41.687 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T07:21:41.687 [RTP] Generating the base plugin configuration ... 2026-05-17T07:21:41.687 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-17T07:21:41.687 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T07:21:41.687 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-17T07:21:41.687 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-17T07:21:41.687 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T07:21:41.687 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-17T07:21:41.703 [RTP] [RTP] StartCommunication 0x000001919CAA3020 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-17T07:21:41.703 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-17T07:21:41.703 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-17T07:21:42.015 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T07:21:42.062 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-17T07:21:42.062 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-17T07:21:42.062 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T07:21:44.593 [RTP] Duplicating the current plugin configuration object... 2026-05-17T07:21:44.593 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T07:21:44.593 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-17T07:21:44.593 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-17T07:21:44.593 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-17T07:22:37.328 Process scan (poststartupscan) started. 2026-05-17T07:22:37.328 Process scan (poststartupscan) completed. 2026-05-17T07:22:37.828 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-17T07:22:37.828 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-17T07:22:40.406 [RTP] Duplicating the current plugin configuration object... 2026-05-17T07:22:40.406 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T07:22:40.406 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-17T07:22:40.406 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-17T07:22:40.406 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-17T07:23:16.687 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2902, FileId: 0x38000000024ec8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:23:42.182 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T07:23:42.191 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T07:23:42.191 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T07:23:48.581 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T07:23:48.581 [RTP] Duplicating the current plugin configuration object... 2026-05-17T07:23:48.581 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T07:23:48.581 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T07:23:48.581 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-17T07:23:48.581 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T07:23:48.581 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T07:24:28.706 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\BF2E875C-2DF4-4DD8-8638-006A43DCB5DDe4c.1dce5ce30ee31c1 2026-05-17T07:24:28.815 Verifying engine and signature files (source: 0) ... 2026-05-17T07:24:28.815 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpengine.dll] due to PPL. 2026-05-17T07:24:28.815 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasbase.vdm]. File not in cache (0x1) 2026-05-17T07:24:29.596 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasbase.vdm] 2026-05-17T07:24:29.612 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-17T07:24:29.628 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasdlta.vdm] 2026-05-17T07:24:29.628 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavbase.vdm]. File not in cache (0x1) 2026-05-17T07:24:30.003 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavbase.vdm] 2026-05-17T07:24:30.003 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-17T07:24:30.018 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavdlta.vdm] 2026-05-17T07:24:30.190 [Engine] IsHybridMode: 0 2026-05-17T07:24:30.190 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-17T07:24:30.190 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1B815CC38831EFD5B830862BD609906A39A9BA1A.bin): 0x00000002 2026-05-17T07:24:30.206 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1B815CC38831EFD5B830862BD609906A39A9BA1A.bin) 2026-05-17T07:24:30.206 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-17T07:24:30.206 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-17T07:24:30.206 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-17T07:24:30.206 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-17T07:24:40.393 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-17T07:24:40.393 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-17T07:24:40.409 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF862155810, lRefCount: 5, hr=0 2026-05-17T07:24:40.409 [Engine] New active engine 00007FF835355810 replacing engine 00007FF862155810. Number of active engines: 2 2026-05-17T07:24:40.409 EngineInit:Global ASOC is enabled 2026-05-17T07:24:40.409 EngineInit:ASOO is enabled for developer volumes 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T07:24:40.487 MpWriteUupSignatureVersion 1.449.657.0, hr = 0 2026-05-17T07:24:40.487 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-17T07:24:40.518 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-17T07:24:40.518 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T07:24:40.518 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-17T07:24:40.518 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-17T07:24:40.518 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T07:24:40.534 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-17T07:24:40.534 [Plugin] Initializing RTP plugin state... 2026-05-17T07:24:40.534 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎17‎-‎2026 09:21:41 Last Perf:‎05‎-‎17‎-‎2026 09:21:41 First RTP Scan:‎05‎-‎17‎-‎2026 09:21:41 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1784 Misses:2375 BM Queue:0,502,0 Proc:0,284,0 File:0,221,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:4305 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:9350234 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6663 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:21689 TotalHits:14468 InstanceCacheInserts:413 InstanceCacheUpdates:0 InstanceCacheDeletes:14 InstanceCacheHits:16 InstanceCacheMisses:8294 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (887/182) Success: 182, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-17T07:24:40.534 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-17T07:24:40.534 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071} 2026-05-17T07:24:40.534 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152}\mpasbase.vdm in use, hr=0x80070020 2026-05-17T07:24:40.534 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T07:24:40.534 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C8F2F28A-7FF6-47EE-A0F3-557729415C80} removed 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-17-2026 07:24:40 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-17-2026 07:24:40 2026-05-17T07:24:40.550 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-17T07:24:40.550 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-17T07:24:40.550 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T07:24:40.550 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-17T07:24:40.550 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T07:24:40.550 MdCoreSvc is supported in this platform and OS Signature updated on 05-17-2026 07:24:40 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.657.0 AV Signature Version: 1.449.657.0 ************************************************************ 2026-05-17T07:24:40.550 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-17T07:24:40.550 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\BF2E875C-2DF4-4DD8-8638-006A43DCB5DDe4c.1dce5ce30ee31c1 2026-05-17T07:24:40.628 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-17T07:24:40.628 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T07:24:41.019 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-17T07:24:41.019 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-17T07:24:41.019 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T07:24:41.034 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T07:24:41.034 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T07:24:41.034 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T07:24:41.034 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T07:24:41.034 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T07:24:41.034 [Engine] Engine 00007FF862155810 no longer in use. Number of active engines: 1 2026-05-17T07:24:41.034 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T07:24:41.034 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-17T07:24:41.128 ProcessImageName: explorer.exe, Pid: 7436, TotalTime: 4686, Count: 138, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 6% 2026-05-17T07:24:41.128 ProcessImageName: DipAwayMode.exe, Pid: 6980, TotalTime: 2727, Count: 15, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 17% 2026-05-17T07:24:41.128 ProcessImageName: AsPowerBar.exe, Pid: 5840, TotalTime: 2680, Count: 18, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 8% 2026-05-17T07:24:41.128 ProcessImageName: dllhost.exe, Pid: 10144, TotalTime: 1987, Count: 61, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\AYO5NAVNU2_33, EstimatedImpact: 39% 2026-05-17T07:24:41.128 ProcessImageName: MOM.exe, Pid: 13904, TotalTime: 1977, Count: 29, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 81% 2026-05-17T07:24:41.128 ProcessImageName: AISuite3.exe, Pid: 3480, TotalTime: 1338, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 16% 2026-05-17T07:24:41.128 ProcessImageName: websockify.exe, Pid: 13932, TotalTime: 912, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 68% 2026-05-17T07:24:41.128 ProcessImageName: TeamViewer.exe, Pid: 4188, TotalTime: 379, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 4% 2026-05-17T07:24:41.128 ProcessImageName: TabTip.exe, Pid: 7420, TotalTime: 169, Count: 5, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 40% 2026-05-17T07:24:41.128 ProcessImageName: WhatsApp.Root.exe, Pid: 11552, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 0% 2026-05-17T07:24:41.128 ProcessImageName: FileCoAuth.exe, Pid: 9840, TotalTime: 151, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-05-17T07:24:41.128 ProcessImageName: taskhostw.exe, Pid: 1116, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\906CC149415780CFB79F39E1CF449F87CA6D4D16, EstimatedImpact: 32% 2026-05-17T07:24:41.128 ProcessImageName: svchost.exe, Pid: 4504, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 1% 2026-05-17T07:24:41.159 [Engine] RSIG_UNLOADENGINE, 00007FF862155810, err=0x0 2026-05-17T07:24:41.175 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{59189205-8192-4390-A972-599733304152} removed 2026-05-17T07:24:42.550 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T07:24:42.550 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T07:24:42.550 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T07:25:39.706 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-17T07:26:41.597 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T07:27:22.581 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-57224378.pf. Process: \Device\HarddiskVolume10\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #5497, FileId: 0xf50000000011dd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:27:46.065 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5891, FileId: 0xb0000000c4ad9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.925 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6331, FileId: 0x110000000c4af7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.940 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6332, FileId: 0x131000000028097, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.940 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6334, FileId: 0x132000000028097, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.940 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6335, FileId: 0x135000000028097, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.956 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6337, FileId: 0x23600000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.956 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6338, FileId: 0x138000000028097, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.956 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6333, FileId: 0x22f00000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:15.956 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6336, FileId: 0x23500000001314a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:16.206 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\05dcbd3e-7772-41ae-89cb-4a0f7e32e099. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6356, FileId: 0x5200000000d3c7, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:16.206 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6354, FileId: 0x13a000000028097, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:29:40.471 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-17T07:29:55.972 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\localhost\E$\xampp\xampp-control.exe 2026-05-17T07:29:55.972 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T07:29:55.972 [RTP] Duplicating the current plugin configuration object... 2026-05-17T07:29:55.972 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T07:29:55.972 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T07:29:55.972 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T07:29:55.987 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T07:31:41.600 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-17T07:31:41.600 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-17T07:31:41.616 Job Notification: New process added to job (10828) 2026-05-17T07:31:41.624 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-17T07:31:41.628 Job Notification: New process added to job (4036) 2026-05-17T07:31:41.639 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:10828] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4036]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T07:31:41.691 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 63449449(ms) from now at 03:09 (01:09 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-17T07:31:41.732 Job Notification: New process added to job (7696) 2026-05-17T07:31:41.734 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-17T07:31:41.734 Job Notification: New process added to job (9284) 2026-05-17T07:31:41.744 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7696] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:9284]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T07:31:45.359 Job Notification: Process exited from job (7696) 2026-05-17T07:31:45.364 Job Notification: Process exited from job (9284) 2026-05-17T07:31:45.434 Job Notification: Process exited from job (10828) 2026-05-17T07:31:45.435 Job Notification: Process exited from job (4036) 2026-05-17T07:32:37.347 Process scan (postsignatureupdatescan) started. 2026-05-17T07:32:57.320 Process scan (postsignatureupdatescan) completed. 2026-05-17T07:34:45.494 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj04DBEF919. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8381, FileId: 0x100000000c4bb0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:45.514 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1349DE9A2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8382, FileId: 0x120000000c4bb0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:45.524 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBC3F2290A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8383, FileId: 0x210000000c4baf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:45.565 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAF5C5C9BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8389, FileId: 0x140000000c4bb0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:45.589 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj63B6A7903. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8391, FileId: 0x150000000c4bb0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:45.740 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0FCC31965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8410, FileId: 0x2a0000000c4baf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:46.249 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCA67F39FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8436, FileId: 0x30000000c4bb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:46.425 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj431CF8914. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8449, FileId: 0x4800000000f119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:46.444 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDBDDDD981. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8451, FileId: 0xa0000000c4bb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:46.464 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj200761959. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8452, FileId: 0xb0000000c4bb8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:34:47.089 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3AE59D9CE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8476, FileId: 0x40000000c4bb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:35:00.204 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8709, FileId: 0x70000000c4b7f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:35:00.336 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8711, FileId: 0x90000000c4b9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:35:00.424 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8717, FileId: 0xe0000000c4ba4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:36:00.514 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8878, FileId: 0x2b0000000068bb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:37:48.104 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #9179, FileId: 0x49100000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:41:46.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T07:45:00.485 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20134, FileId: 0x5d00000001b531, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:45:00.504 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #20136, FileId: 0xc0000000c4b9e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T07:48:09.704 [RTP] [Mini-filter] OpenWithoutRead notification (1271, 10001, \Device\HarddiskVolume3\Windows\explorer.exe) sent successfully. 2026-05-17T07:56:51.600 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T08:11:56.602 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T08:14:09.776 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37415, FileId: 0x320000000b7fdb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T08:16:42.646 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\Users\desktop.ini 2026-05-17T08:27:01.595 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T08:42:06.601 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T08:42:28.090 mp.TriggerScanResource(0x00000008, process, pid:7436), delay = 0 from 0x002010bd9cc67d2f 2026-05-17T08:42:28.090 mp.TriggerScanResource(0x00000008, ems, pid:7436), delay = 0 from 0x002010bd9cc67d2f 2026-05-17T08:42:28.290 Engine:EMS scan for process: pid_7436 pid: 7436, sigseq: 0x0, sendMemoryScanReport: 0, source: 8 2026-05-17T08:43:16.885 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-57224378.pf. Process: \Device\HarddiskVolume10\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #39495, FileId: 0xf50000000011dd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T08:43:26.316 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #39573, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-17T08:43:29.285 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T08:43:29.285 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T08:43:29.285 [Cloud] Queued cloud request. 2026-05-17T08:43:29.285 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T08:43:29.285 [Cloud] Dequeued cloud request. 2026-05-17T08:43:29.285 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T08:43:29.973 [Cloud] End of cloud request. 2026-05-17T08:43:29.973 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll. status=0x40070000, statusex=0x200310, threatid=0x80000000, sigseq=0x294bdc606b459 2026-05-17T08:43:30.495 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x3a12bcf7 2026-05-17T08:44:14.303 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T08:44:14.303 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T08:44:14.303 [Cloud] Queued cloud request. 2026-05-17T08:44:14.303 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T08:44:14.303 [Cloud] Dequeued cloud request. 2026-05-17T08:44:14.305 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T08:44:14.917 [Cloud] End of cloud request. 2026-05-17T08:44:14.917 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T08:44:15.435 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T08:53:32.655 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #40887, FileId: 0x36000000011e1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T08:57:11.595 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T09:04:51.486 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #41427, FileId: 0xde000000011e16, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:06:54.795 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #41778, FileId: 0xb3000000003e54, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:12:16.606 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T09:15:04.409 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-57224378.pf. Process: \Device\HarddiskVolume10\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #42388, FileId: 0xf50000000011dd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:15:11.097 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #42470, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:19:50.506 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #42978, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:19:50.506 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #42979, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:19:50.506 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\plugins\config\Explorer.ini. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0xc0000001, State: 0, ScanRequest #42980, FileId: 0x6b000000002d90, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x12019f, FileAttributes:0x20, ScanAttributes:0x8, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:24:40.416 ProcessImageName: explorer.exe, Pid: 7436, TotalTime: 43643, Count: 6685, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: AcroCEF.exe, Pid: 9944, TotalTime: 3843, Count: 174, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-05-17T09:24:40.416 ProcessImageName: setup.exe, Pid: 9268, TotalTime: 2991, Count: 359, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\Edge\Application\new_msedge.exe, EstimatedImpact: 38% 2026-05-17T09:24:40.416 ProcessImageName: DeviceCensus.exe, Pid: 964, TotalTime: 2356, Count: 6, MaxTime: 1187, MaxTimeFile: \Device\Harddisk1\DR1, EstimatedImpact: 42% 2026-05-17T09:24:40.416 ProcessImageName: xampp-control.exe, Pid: 11972, TotalTime: 2171, Count: 35, MaxTime: 1593, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: dllhost.exe, Pid: 10144, TotalTime: 1911, Count: 63, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\CE44YDXXWC_27, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: xampp-control.exe, Pid: 940, TotalTime: 1793, Count: 12, MaxTime: 1531, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 10% 2026-05-17T09:24:40.416 ProcessImageName: powershell.exe, Pid: 7184, TotalTime: 1617, Count: 72, MaxTime: 906, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 1% 2026-05-17T09:24:40.416 ProcessImageName: Acrobat.exe, Pid: 15052, TotalTime: 1227, Count: 17, MaxTime: 453, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatRes.dll, EstimatedImpact: 73% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14304, TotalTime: 1186, Count: 123, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: Acrobat.exe, Pid: 4484, TotalTime: 1185, Count: 5, MaxTime: 1125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll, EstimatedImpact: 43% 2026-05-17T09:24:40.416 ProcessImageName: svchost.exe, Pid: 3592, TotalTime: 1108, Count: 2, MaxTime: 1046, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 4% 2026-05-17T09:24:40.416 ProcessImageName: notepad++.exe, Pid: 8028, TotalTime: 845, Count: 53, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 14616, TotalTime: 794, Count: 91, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\_0\01_WebApps\Webftp\webftp-ajax\webFTP_2.0\xajax_js\xajax.js, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: WmiPrvSE.exe, Pid: 15300, TotalTime: 677, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 82% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14004, TotalTime: 648, Count: 79, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\phpmyadmin\pma__table_coords.ibd, EstimatedImpact: 7% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 13208, TotalTime: 490, Count: 78, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 18% 2026-05-17T09:24:40.416 ProcessImageName: Notepad.exe, Pid: 4224, TotalTime: 480, Count: 20, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 6% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 7792, TotalTime: 454, Count: 77, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\php\ext\php_fileinfo.dll, EstimatedImpact: 11% 2026-05-17T09:24:40.416 ProcessImageName: powershell.exe, Pid: 4144, TotalTime: 447, Count: 30, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 35% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 9768, TotalTime: 377, Count: 38, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: notepad++.exe, Pid: 10880, TotalTime: 368, Count: 38, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\class.AbstractAjxpUser.php@2026-05-17_102612, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: firefox.exe, Pid: 13460, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05860, EstimatedImpact: 16% 2026-05-17T09:24:40.416 ProcessImageName: Notepad.exe, Pid: 13816, TotalTime: 272, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.WindowsNotepad_11.2512.29.0_x64__8wekyb3d8bbwe\NotepadXamlUI\ModalDialogGroup.xbf, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: AdobeCollabSync.exe, Pid: 3928, TotalTime: 228, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: Everything.exe, Pid: 14040, TotalTime: 196, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Locale\de_DE\Acrobat Elements\ContextMenuShim64.DEU, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: dllhost.exe, Pid: 15300, TotalTime: 166, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\xampp-control.exe - Verknüpfung.lnk, EstimatedImpact: 53% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 14400, TotalTime: 166, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: TabTip.exe, Pid: 7964, TotalTime: 154, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-05-17T09:24:40.416 ProcessImageName: backgroundTaskHost.exe, Pid: 8428, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1778675981, EstimatedImpact: 18% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 13748, TotalTime: 150, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 7312, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70_148.0.3967.54.exe, Pid: 5032, TotalTime: 125, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{68724E77-E1AB-4688-90E8-5DA176C9CBD6}\EDGEMITMP_87F1B.tmp\setup.exe, EstimatedImpact: 71% 2026-05-17T09:24:40.416 ProcessImageName: SDXHelper.exe, Pid: 13984, TotalTime: 121, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EDF0B1E6-B99F-47C0-906A-E85C1CDA8E2B, EstimatedImpact: 4% 2026-05-17T09:24:40.416 ProcessImageName: PhoneExperienceHost.exe, Pid: 6512, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: firefox.exe, Pid: 6992, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\browser\omni.ja, EstimatedImpact: 5% 2026-05-17T09:24:40.416 ProcessImageName: SecurityHealthHost.exe, Pid: 13792, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 9% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 9456, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: OfficeC2RClient.exe, Pid: 14856, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 4% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 7828, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql_error.log, EstimatedImpact: 6% 2026-05-17T09:24:40.416 ProcessImageName: notepad++.exe, Pid: 7008, TotalTime: 90, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: OneDriveLauncher.exe, Pid: 7308, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 5% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 3860, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 49% 2026-05-17T09:24:40.416 ProcessImageName: svchost.exe, Pid: 1128, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: backgroundTaskHost.exe, Pid: 2288, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1778676020, EstimatedImpact: 15% 2026-05-17T09:24:40.416 ProcessImageName: svchost.exe, Pid: 1448, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler->(UTF-16LE), EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: SDXHelper.exe, Pid: 7728, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: AcroCEF.exe, Pid: 10068, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 10% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 3084, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\apache\error\XAMPP_FORBIDDEN.html.var, EstimatedImpact: 1% 2026-05-17T09:24:40.416 ProcessImageName: ngentask.exe, Pid: 14140, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 42% 2026-05-17T09:24:40.416 ProcessImageName: FileCoAuth.exe, Pid: 11168, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-17.0814.11168.1.aodl, EstimatedImpact: 1% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 11440, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: notepad++.exe, Pid: 14152, TotalTime: 61, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: taskhostw.exe, Pid: 6148, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 13688, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 5516, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 7876, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 2876, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14664, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 3348, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14776, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14820, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 13028, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: OfficeC2RClient.exe, Pid: 15060, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B76BE66D46C355931939D8CF818D03FD_39DF7432E6EF50CDA9C936E29E7DA30D, EstimatedImpact: 2% 2026-05-17T09:24:40.416 ProcessImageName: xampp-control.exe, Pid: 11108, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.log, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 14696, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: xampp-control.exe, Pid: 12272, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.ini, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: mysqld.exe, Pid: 11500, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: httpd.exe, Pid: 7008, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume10\xampp\htdocs\_0\01_WebApps\Webftp\ajaxplorer-core-3.3.5\data\cache\plugins_cache.ser, EstimatedImpact: 0% 2026-05-17T09:24:40.416 ProcessImageName: SDXHelper.exe, Pid: 496, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 15% 2026-05-17T09:24:40.416 ProcessImageName: Notepad.exe, Pid: 15348, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\WindowState\8a6a91f6-0335-43f6-a862-40f6cdf93c4b.0.bin, EstimatedImpact: 5% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-17-2026 09:41:30 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/17/2026 09:41:31.5142300 UTC (14718 ms since boot) 2026-05-17T09:41:31.005 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-17T09:41:31.005 WARNING: the previous service shutdown was not expected. 2026-05-17T09:41:31.020 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T09:41:31.020 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T09:41:31.067 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260517-094131-00000003-fffffffeffffffff.bin ... 2026-05-17T09:41:31.145 [WPP] Trace session started - MpWppTracing-20260517-094131-00000003-fffffffeffffffff.bin 2026-05-17T09:41:31.145 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-17T09:41:31.145 [RbM] Rollback manager succesfully initialized. 2026-05-17T09:41:31.145 [RbM] Rollback manager EnableRollbackManager called. 2026-05-17T09:41:31.161 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-17T09:41:31.161 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-17T09:41:31.161 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-17T09:41:31.161 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-17T09:41:31.161 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-17T09:41:31.177 MdCoreSvc is supported in this platform and OS 2026-05-17T09:41:31.177 MdCoreSvc is supported in this platform and OS 2026-05-17T09:41:31.177 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-17T09:41:31.192 [PlatUpd] Starting MdCoreSvc service 2026-05-17T09:41:31.223 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-17T09:41:35.534 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-17T09:41:35.534 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-17T09:41:35.534 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-17T09:41:35.534 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-17T09:41:35.534 [PlatUpd] CSP platform update started 2026-05-17T09:41:35.534 [PlatUpd] Defender MDM CSP platform update not required 2026-05-17T09:41:35.534 [PlatUpd] WMI/PS provider platform update started 2026-05-17T09:41:35.534 [PlatUpd] WMI/PS provider platform update not required 2026-05-17T09:41:35.534 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-17T09:41:35.534 MdCoreSvc is supported in this platform and OS 2026-05-17T09:41:35.534 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-17T09:41:35.534 [PlatUpd] Starting MdCoreSvc service 2026-05-17T09:41:35.534 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-17T09:41:35.534 [TS] Troubleshooting mode is not available! 2026-05-17T09:41:35.534 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-17T09:41:35.534 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-17T09:41:35.549 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-17T09:41:35.549 [Service] Enabling AutoLoggers ... 2026-05-17T09:41:35.549 [Service] Enabling AMSI registration ... 2026-05-17T09:41:35.549 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-17T09:41:35.564 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 47403 Number of invalid entries is 0 Number of inserts issued is 1589880 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6534 Number of lookups is 108494953 Number of lookup misses is 5210271 Number of fast lookup misses is 55282633 Number of false fast lookups is 5210266 Number of invalidations is 735950 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-17T09:41:35.564 Verifying license file... 2026-05-17T09:41:35.564 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-17T09:41:35.580 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-17T09:41:35.580 Loaded module#0 MpComServer. 2026-05-17T09:41:35.595 Loaded module#1 StartupPolicies. 2026-05-17T09:41:35.595 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-17T09:41:35.595 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T09:41:35.595 COM server initialized successfully. 2026-05-17T09:41:35.611 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-17T09:41:35.611 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-17T09:41:35.611 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-17T09:41:35.627 [RTP] [RTP] FilterCommunicator object 0x000001F61CE7BB30 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-17T09:41:35.642 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-17T09:41:35.642 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T09:41:35.642 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T09:41:35.642 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-17T09:41:35.642 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-17T09:41:35.642 [RTP] [RTP] FilterCommunicator object 0x000001F61CE9A040 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-17T09:41:35.642 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-17T09:41:35.642 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-17T09:41:35.642 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-17T09:41:35.642 [RTP] [RTP] StartCommunication 0x000001F61CE7BB30 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-17T09:41:35.642 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-17T09:41:35.642 [init][RTP] RTPPlugin initialization completed 2026-05-17T09:41:35.642 OS boot count = 2 2026-05-17T09:41:35.642 OS Install = 0 2026-05-17T09:41:35.642 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-17T09:41:35.642 [KSL] Entering CKSLEngine::Initialize. 2026-05-17T09:41:35.642 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-17T09:41:35.642 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-17T09:41:35.658 [KSL] MpInstallKslD: hr=0x1 2026-05-17T09:41:35.658 [KSL] MpRegisterKslD: hr=0 2026-05-17T09:41:35.658 [KSL] MpStartKslD: hr=0 2026-05-17T09:41:35.658 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T09:41:35.658 Loading engine... 2026-05-17T09:41:35.674 Verifying engine and signature files (source: 1) ... 2026-05-17T09:41:35.674 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpengine.dll] due to PPL. 2026-05-17T09:41:35.674 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasbase.vdm] (file in cache) 2026-05-17T09:41:35.674 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasdlta.vdm] (file in cache) 2026-05-17T09:41:35.674 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavbase.vdm] (file in cache) 2026-05-17T09:41:35.674 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpavdlta.vdm] (file in cache) 2026-05-17T09:41:35.705 [Engine] IsHybridMode: 0 2026-05-17T09:41:35.705 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-17T09:41:35.736 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1B815CC38831EFD5B830862BD609906A39A9BA1A.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-17T09:41:39.565 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-17T09:41:39.580 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-17T09:41:39.580 [Engine] New active engine 00007FFE47B05810 (no old engine). Number of active engines: 1 2026-05-17T09:41:39.596 EngineInit:Global ASOC is enabled 2026-05-17T09:41:39.596 EngineInit:ASOO is enabled for developer volumes 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.674 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:41:39.705 MpWriteUupSignatureVersion 1.449.657.0, hr = 0 2026-05-17T09:41:39.721 [SigStatUpd] CSignatureStatus: back to good 2026-05-17T09:41:39.721 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-17T09:41:39.737 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-17T09:41:39.737 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T09:41:39.737 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-17T09:41:39.737 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-17T09:41:39.737 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T09:41:39.752 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-17T09:41:39.752 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2152 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12465 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2461 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-17T09:41:39.752 [Plugin] Initializing RTP plugin state... 2026-05-17T09:41:39.752 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-17T09:41:39.752 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071} 2026-05-17T09:41:39.752 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:41:39.752 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:41:39.752 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:41:39.752 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T09:41:39.752 MdCoreSvc is supported in this platform and OS 2026-05-17T09:41:39.752 Engine loaded! 2026-05-17T09:41:39.752 [DLP] Create FeatureControlState instance 2026-05-17T09:41:39.769 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-17T09:41:39.769 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-17T09:41:39.769 RegisterSModeChangeListener: hr = 0x1 2026-05-17T09:41:39.769 RegisterHybridModeChangeListener: hr = 0 2026-05-17T09:41:39.784 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-17T09:41:39.784 [SigReleaseHb] Initialized with Stage 0 2026-05-17T09:41:39.784 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-17T09:41:39.784 [SCC][CID=23500_5352] Initializing ... 2026-05-17T09:41:39.784 [SCC][CID=23500_5352] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-17T09:41:39.784 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-17T09:41:39.784 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-17T09:41:39.784 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T09:41:39.784 [NRI] Stopping NIS service ... 2026-05-17T09:41:39.784 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-17T09:41:39.784 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.657.0 AV Signature Version: 1.449.657.0 ************************************************************ 2026-05-17T09:41:39.784 Resource usage Monitoring is enabled 2026-05-17T09:41:39.784 Job Notification: New process added to job (4480) 2026-05-17T09:41:39.784 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-17T09:41:39.831 Job Notification: New process added to job (6588) 2026-05-17T09:41:39.831 Job Notification: New process added to job (3644) 2026-05-17T09:41:39.846 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:6588] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3644]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T09:41:39.893 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-17T09:41:39.893 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T09:41:39.893 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T09:41:39.893 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T09:41:39.893 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T09:41:39.893 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T09:41:39.893 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T09:41:39.893 [RTP] Generating the base plugin configuration ... 2026-05-17T09:41:39.893 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-17T09:41:39.893 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T09:41:39.893 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-17T09:41:39.893 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-17T09:41:39.893 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T09:41:39.893 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-17T09:41:39.909 [RTP] [RTP] StartCommunication 0x000001F61CE9A040 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-17T09:41:39.909 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-17T09:41:39.909 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-05-17T09:41:39.940 Job Notification: Process exited from job (6588) 2026-05-17T09:41:39.940 Job Notification: Process exited from job (3644) 2026-05-17T09:41:39.940 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-17T09:41:40.221 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-17T09:41:40.221 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-17T09:41:40.221 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T09:41:40.252 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T09:41:42.893 [RTP] Duplicating the current plugin configuration object... 2026-05-17T09:41:42.893 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T09:41:42.893 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-17T09:41:42.893 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-17T09:41:42.893 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-17T09:41:50.830 Engine:Triggered SMS scan for filename: explorer.exe, pid: 8628, sigseq: 0x65B3BACFC721, origin: signature, sendMemoryScanReport: 0 2026-05-17T09:41:51.455 [RTP] 1 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T09:41:51.455 [RTP] Duplicating the current plugin configuration object... 2026-05-17T09:41:51.455 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T09:41:51.455 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T09:41:51.455 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T09:41:51.455 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T09:41:51.518 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-05-17T09:41:51.518 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe Internal signature match:subtype=Lowfi, sigseq=0x000086782AFEC378, sigsha=cc9f3b3aeaf15da51d08ee5a856dd5567e7c5357, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00007178C8F1AC44, sigsha=2d37fce177c06ff4997765bccf1685323094e0f9, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0000AD78B7BB5581, sigsha=e24f0058af2290e624f53e02330172e8431006a3, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00009678429BCF34, sigsha=83aec20570ba60b6258a920886557705905065bc, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x0003DE78355F18B0, sigsha=0ba69d0cae4152fd347f8eea30acd834cb37dbeb, cached=false, source=0, resourceid=0xe1824bfa Internal signature match:subtype=Lowfi, sigseq=0x00008E78D379DBE3, sigsha=88d73fe0f5af64ea339480d71687f50cf84a49eb, cached=false, source=0, resourceid=0xe1824bfa 2026-05-17T09:42:20.787 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3304, FileId: 0x2a000000037582, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:42:30.596 [RTP] 1 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T09:42:30.596 [RTP] Duplicating the current plugin configuration object... 2026-05-17T09:42:30.596 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T09:42:30.596 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T09:42:30.596 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T09:42:30.596 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T09:42:30.903 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-17T09:42:35.643 Process scan (poststartupscan) started. 2026-05-17T09:42:35.659 Process scan (poststartupscan) completed. 2026-05-17T09:42:36.159 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-17T09:42:36.159 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-17T09:42:38.717 [RTP] Duplicating the current plugin configuration object... 2026-05-17T09:42:38.717 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T09:42:38.717 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-17T09:42:38.717 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-17T09:42:38.717 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-17T09:43:34.284 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T09:43:34.284 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T09:43:34.284 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T09:46:39.627 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-17T09:46:39.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T09:46:45.159 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5729, FileId: 0xd500000000866b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:51:02.190 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #6180, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-17T09:51:06.987 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T09:51:06.987 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T09:51:06.987 [Cloud] Queued cloud request. 2026-05-17T09:51:06.987 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T09:51:06.987 [Cloud] Dequeued cloud request. 2026-05-17T09:51:06.987 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3fb4107645e5705799eec11afedc51c659fbbe74 Dynamic Signature Compilation Timestamp:05-17-2026 09:51:06 Persistence Type:Duration Time remaining:288000000 2026-05-17T09:51:07.674 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T09:51:07.674 [Cloud] End of cloud request. 2026-05-17T09:51:08.174 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T09:51:08.877 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x3a12bcf7 2026-05-17T09:51:14.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T09:51:14.096 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T09:51:14.096 [Cloud] Queued cloud request. 2026-05-17T09:51:14.096 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T09:51:14.096 [Cloud] Dequeued cloud request. 2026-05-17T09:51:14.096 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T09:51:14.502 [Cloud] End of cloud request. 2026-05-17T09:51:14.502 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T09:51:15.002 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T09:51:39.799 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-17T09:51:39.799 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-17T09:51:39.830 Job Notification: New process added to job (12472) 2026-05-17T09:51:39.846 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-17T09:51:39.846 Job Notification: New process added to job (9408) 2026-05-17T09:51:39.846 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:12472] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:9408]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T09:51:39.909 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 63986343(ms) from now at 05:38 (03:38 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-17T09:51:39.940 Job Notification: New process added to job (11348) 2026-05-17T09:51:39.940 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-17T09:51:39.955 Job Notification: New process added to job (10844) 2026-05-17T09:51:39.955 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:11348] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10844]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-17T09:51:49.393 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7FB3B1BB-D1F3-4244-A3CF-9A456A0EF3D428a8.1dce5e2c69ed42e 2026-05-17T09:51:49.502 Verifying engine and signature files (source: 0) ... 2026-05-17T09:51:49.502 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpengine.dll] due to PPL. 2026-05-17T09:51:49.502 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpasbase.vdm]. File not in cache (0x1) 2026-05-17T09:51:50.252 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpasbase.vdm] 2026-05-17T09:51:50.252 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-17T09:51:50.284 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpasdlta.vdm] 2026-05-17T09:51:50.284 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpavbase.vdm]. File not in cache (0x1) 2026-05-17T09:51:50.627 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpavbase.vdm] 2026-05-17T09:51:50.627 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-17T09:51:50.643 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpavdlta.vdm] 2026-05-17T09:51:50.799 [Engine] IsHybridMode: 0 2026-05-17T09:51:50.799 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-17T09:51:50.815 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EDACA1AA4410CB0692E1CB7A17E43A7A7F2C3235.bin): 0x00000002 2026-05-17T09:51:50.815 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EDACA1AA4410CB0692E1CB7A17E43A7A7F2C3235.bin) 2026-05-17T09:51:50.815 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-17T09:51:50.815 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-17T09:51:50.815 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-17T09:51:50.815 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-17T09:52:00.705 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-17T09:52:00.705 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-17T09:52:00.737 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFE47B05810, lRefCount: 5, hr=0 2026-05-17T09:52:00.737 [Engine] New active engine 00007FFDEE955810 replacing engine 00007FFE47B05810. Number of active engines: 2 2026-05-17T09:52:00.737 EngineInit:Global ASOC is enabled 2026-05-17T09:52:00.737 EngineInit:ASOO is enabled for developer volumes 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.799 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T09:52:00.815 MpWriteUupSignatureVersion 1.449.659.0, hr = 0 2026-05-17T09:52:00.815 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-17T09:52:00.830 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-17T09:52:00.830 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T09:52:00.830 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-17T09:52:00.830 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-17T09:52:00.830 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T09:52:00.862 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-17T09:52:00.862 [Plugin] Initializing RTP plugin state... 2026-05-17T09:52:00.862 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-17T09:52:00.862 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎17‎-‎2026 11:41:39 Last Perf:‎05‎-‎17‎-‎2026 11:41:39 First RTP Scan:‎05‎-‎17‎-‎2026 11:41:39 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2326 Misses:4012 BM Queue:0,429,0 Proc:0,350,0 File:0,156,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:6585 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:19477948 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6400 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:23718 TotalHits:23048 InstanceCacheInserts:290 InstanceCacheUpdates:0 InstanceCacheDeletes:227 InstanceCacheHits:0 InstanceCacheMisses:14215 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (610/233) Success: 233, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-17T09:52:00.862 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598} 2026-05-17T09:52:00.862 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T09:52:00.862 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5ABFA1A7-EF1B-4FC5-A935-665AA890D2D4} removed 2026-05-17T09:52:00.862 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071}\mpasbase.vdm in use, hr=0x80070020 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-17-2026 09:52:00 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-17-2026 09:52:00 2026-05-17T09:52:00.862 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-17T09:52:00.862 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-17T09:52:00.862 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T09:52:00.862 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-17T09:52:00.862 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T09:52:00.862 MdCoreSvc is supported in this platform and OS Signature updated on 05-17-2026 09:52:00 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.659.0 AV Signature Version: 1.449.659.0 ************************************************************ 2026-05-17T09:52:00.877 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-17T09:52:00.877 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\7FB3B1BB-D1F3-4244-A3CF-9A456A0EF3D428a8.1dce5e2c69ed42e 2026-05-17T09:52:00.940 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-17T09:52:00.955 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 05-17-2026 09:52:00 ************************************************************ 2026-05-17T09:52:00.987 Job Notification: Process exited from job (11348) 2026-05-17T09:52:00.987 Job Notification: Process exited from job (10844) 2026-05-17T09:52:01.049 Job Notification: Process exited from job (12472) 2026-05-17T09:52:01.049 Job Notification: Process exited from job (9408) 2026-05-17T09:52:01.299 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T09:52:01.299 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T09:52:01.299 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T09:52:01.299 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T09:52:01.299 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T09:52:01.299 [Engine] Engine 00007FFE47B05810 no longer in use. Number of active engines: 1 2026-05-17T09:52:01.299 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T09:52:01.299 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-17T09:52:01.330 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-17T09:52:01.330 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-17T09:52:01.330 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T09:52:01.409 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 8546, Count: 199, MaxTime: 1468, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-05-17T09:52:01.409 ProcessImageName: AsPowerBar.exe, Pid: 12404, TotalTime: 2944, Count: 18, MaxTime: 1062, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 11% 2026-05-17T09:52:01.409 ProcessImageName: DipAwayMode.exe, Pid: 7876, TotalTime: 2493, Count: 24, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll, EstimatedImpact: 11% 2026-05-17T09:52:01.409 ProcessImageName: MOM.exe, Pid: 13784, TotalTime: 2039, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 69% 2026-05-17T09:52:01.409 ProcessImageName: dllhost.exe, Pid: 11068, TotalTime: 1876, Count: 65, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\AYO5NAVNU2_33, EstimatedImpact: 47% 2026-05-17T09:52:01.409 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1700, Count: 7, MaxTime: 1484, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 37% 2026-05-17T09:52:01.409 ProcessImageName: AISuite3.exe, Pid: 7912, TotalTime: 1506, Count: 22, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 14% 2026-05-17T09:52:01.409 ProcessImageName: powershell.exe, Pid: 7412, TotalTime: 1302, Count: 49, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 61% 2026-05-17T09:52:01.409 ProcessImageName: mysqld.exe, Pid: 1308, TotalTime: 1066, Count: 120, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 63% 2026-05-17T09:52:01.409 ProcessImageName: websockify.exe, Pid: 13832, TotalTime: 942, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\_ssl.pyd, EstimatedImpact: 61% 2026-05-17T09:52:01.409 ProcessImageName: httpd.exe, Pid: 5888, TotalTime: 567, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 22% 2026-05-17T09:52:01.409 ProcessImageName: TeamViewer.exe, Pid: 7920, TotalTime: 333, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\nz2bac3n.default-release-1\prefs.js, EstimatedImpact: 3% 2026-05-17T09:52:01.409 ProcessImageName: WhatsApp.Root.exe, Pid: 12692, TotalTime: 316, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\config.json, EstimatedImpact: 0% 2026-05-17T09:52:01.409 ProcessImageName: svchost.exe, Pid: 4144, TotalTime: 280, Count: 2, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 0% 2026-05-17T09:52:01.409 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 241, Count: 33, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 90% 2026-05-17T09:52:01.440 [Engine] RSIG_UNLOADENGINE, 00007FFE47B05810, err=0x0 2026-05-17T09:52:01.440 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{675F830F-9AC0-4D93-A96F-28A20D2CA071} removed 2026-05-17T09:52:02.877 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T09:52:02.877 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T09:52:02.877 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T09:52:35.675 Process scan (postsignatureupdatescan) started. Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-17T09:52:56.284 Process scan (postsignatureupdatescan) completed. 2026-05-17T09:53:44.455 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7435F9903. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7072, FileId: 0x4700000000cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.487 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7F856F941. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7075, FileId: 0x4800000000cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.487 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF22ABE9C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7077, FileId: 0x2e00000000cb08, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.518 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1A34DC97C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7080, FileId: 0x7900000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.612 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCFAEF490D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7084, FileId: 0x4b00000000cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.724 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD31DCE95F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7111, FileId: 0x5300000000cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.780 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj55AD0A9B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7134, FileId: 0x7c00000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.806 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9622C4978. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7143, FileId: 0x5500000000cbb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.822 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj95BFD59E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7151, FileId: 0x7d00000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.837 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj17996995C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7153, FileId: 0x7e00000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:44.853 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8820DB996. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7155, FileId: 0x7f00000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:59.071 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7333, FileId: 0x1d000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:59.181 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7337, FileId: 0x6100000000a8ce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:53:59.259 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7341, FileId: 0x161000000003a15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.768 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7391, FileId: 0x7100000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.768 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7394, FileId: 0x6700000000a8ce, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.768 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7393, FileId: 0x7300000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.768 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7392, FileId: 0x6500000000a8ce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.784 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7399, FileId: 0x7700000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.784 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7398, FileId: 0x6b00000000a8ce, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.784 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7397, FileId: 0x7500000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.784 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7400, FileId: 0x7800000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:40.799 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #7404, FileId: 0x6f00000000a8ce, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:41.190 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13cefe48-4eb4-4d9e-a22f-53b88832b374. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #7435, FileId: 0xd60000000051c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:54:59.440 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7438, FileId: 0x168000000003a15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:56:45.614 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #7541, FileId: 0x49200000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T09:57:00.768 [RbM] Setting Last known good engine candidate. hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x3a12bcf7 2026-05-17T10:00:29.612 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:00:29.612 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:00:29.612 [Cloud] Queued cloud request. 2026-05-17T10:00:29.612 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:00:29.612 [Cloud] Dequeued cloud request. 2026-05-17T10:00:29.612 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:00:30.081 [Cloud] End of cloud request. 2026-05-17T10:00:30.081 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:00:30.596 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T10:01:44.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T10:03:59.310 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8493, FileId: 0xda00000000866b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T10:03:59.326 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8495, FileId: 0x8800000000d0be, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{1F62988E-5D79-AC8A-A62E-3143D9EB4716} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:13528 ProcessCreationTime:134234856237820361 SessionID:2 CreationTime:05-17-2026 10:04:03 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: D:\xampp\xampp-control.exe:3236:3,C:\Windows\System32\csrss.exe:6320:2, Operations:None END BM telemetry 2026-05-17T10:04:04.508 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:04:04.508 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:04:04.508 [Cloud] Queued cloud request. 2026-05-17T10:04:04.508 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:04:04.508 [Cloud] Dequeued cloud request. 2026-05-17T10:04:04.508 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:04:04.915 [Cloud] End of cloud request. 2026-05-17T10:04:05.415 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x4ea68b1e 2026-05-17T10:08:19.737 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:08:19.737 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:08:19.737 [Cloud] Queued cloud request. 2026-05-17T10:08:19.737 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:08:19.737 [Cloud] Dequeued cloud request. 2026-05-17T10:08:19.737 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:08:20.221 [Cloud] End of cloud request. 2026-05-17T10:08:20.221 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_120819. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:08:20.737 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x3a12bcf7 2026-05-17T10:09:35.987 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #9063, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x6b4d6675 2026-05-17T10:14:17.456 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:14:17.456 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:14:17.456 [Cloud] Queued cloud request. 2026-05-17T10:14:17.456 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:14:17.456 [Cloud] Dequeued cloud request. 2026-05-17T10:14:17.456 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:14:17.893 [Cloud] End of cloud request. 2026-05-17T10:14:17.893 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_121417. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:14:18.393 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T10:16:49.784 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0xf750b8c7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0xf750b8c7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0xf750b8c7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0xf750b8c7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0xf750b8c7 2026-05-17T10:21:11.237 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:21:11.237 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:21:11.237 [Cloud] Queued cloud request. 2026-05-17T10:21:11.237 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:21:11.237 [Cloud] Dequeued cloud request. 2026-05-17T10:21:11.237 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:21:11.690 [Cloud] End of cloud request. 2026-05-17T10:21:11.690 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_121925. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:21:12.190 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0xf750b8c7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x3a12bcf7 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0xb786c7e9 2026-05-17T10:23:10.471 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:23:10.471 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:23:10.471 [Cloud] Queued cloud request. 2026-05-17T10:23:10.471 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:23:10.471 [Cloud] Dequeued cloud request. 2026-05-17T10:23:10.471 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:23:10.846 [Cloud] End of cloud request. 2026-05-17T10:23:10.846 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_122310. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:23:11.362 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0xb786c7e9 2026-05-17T10:23:45.534 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T10:23:45.534 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T10:23:45.534 [Cloud] Queued cloud request. 2026-05-17T10:23:45.534 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T10:23:45.534 [Cloud] Dequeued cloud request. 2026-05-17T10:23:45.534 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T10:23:45.862 [Cloud] End of cloud request. 2026-05-17T10:23:45.862 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_122310. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T10:23:46.362 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x3a12bcf7 2026-05-17T10:29:36.346 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10593, FileId: 0x6400000000dc58, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T10:29:47.596 [RTP] [Mini-filter] OpenWithoutRead notification (1258, 10015, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-17T10:31:54.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T10:41:39.784 [RbM] Audited automatic rollback of Platform 0x4001265b80007 --> 0x4001265a40006. hr = 0 2026-05-17T10:42:07.139 Bm signature throttled:0x000091b307051d85 2026-05-17T10:46:59.792 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x85602c18 2026-05-17T10:55:22.252 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #11670, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=2, resourceid=0x8f3e43bf 2026-05-17T11:00:01.682 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #12289, FileId: 0x4600000000d56a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:00:01.682 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, Status: 0xc0000001, State: 0, ScanRequest #12288, FileId: 0xdf000000007197, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:02:04.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T11:10:55.768 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12498, FileId: 0x1d0000000354c7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:15:47.798 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12575, FileId: 0x1f00000003580f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:17:09.798 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T11:26:20.240 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #13887, FileId: 0x34000000039e87, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0xbd3087d9 2026-05-17T11:29:26.708 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T11:29:26.708 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T11:29:26.708 [Cloud] Queued cloud request. 2026-05-17T11:29:26.708 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T11:29:26.708 [Cloud] Dequeued cloud request. 2026-05-17T11:29:26.708 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T11:29:27.338 [Cloud] End of cloud request. 2026-05-17T11:29:27.338 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager.php@2026-05-17_132926. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T11:29:27.848 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 2026-05-17T11:32:14.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T11:35:29.512 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14009, FileId: 0x3900000002b85c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x4769b360 2026-05-17T11:39:57.815 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T11:39:57.815 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T11:39:57.815 [Cloud] Queued cloud request. 2026-05-17T11:39:57.815 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T11:39:57.815 [Cloud] Dequeued cloud request. 2026-05-17T11:39:57.818 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T11:39:58.368 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager_neu.php@2026-05-17_133957. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T11:39:58.368 [Cloud] End of cloud request. 2026-05-17T11:39:58.898 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 2026-05-17T11:47:19.786 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T11:48:02.418 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14500, FileId: 0x2c000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.268 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14514, FileId: 0x26000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.270 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14518, FileId: 0x27000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.272 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14513, FileId: 0x23000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.297 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14521, FileId: 0x2c000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.299 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14515, FileId: 0x8300000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.301 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14524, FileId: 0x8900000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.312 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14526, FileId: 0x2e000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.314 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14522, FileId: 0x8800000000a87f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.316 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14527, FileId: 0x2f000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:49:05.741 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\30fc0322-0ccc-4ba0-a92e-f23b52c19884. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #14560, FileId: 0x23000000036226, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T11:52:00.742 ProcessImageName: notepad++.exe, Pid: 1216, TotalTime: 6983, Count: 695, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: AcroCEF.exe, Pid: 1192, TotalTime: 3595, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-17T11:52:00.742 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 2378, Count: 124, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume10\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1701, Count: 7, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: powershell.exe, Pid: 2828, TotalTime: 1559, Count: 61, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 9796, TotalTime: 1022, Count: 121, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 1364, TotalTime: 926, Count: 70, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: PDFXCview.exe, Pid: 2828, TotalTime: 810, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 47% 2026-05-17T11:52:00.742 ProcessImageName: firefox.exe, Pid: 13780, TotalTime: 585, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 43% 2026-05-17T11:52:00.742 ProcessImageName: splwow64.exe, Pid: 7348, TotalTime: 585, Count: 50, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: firefox.exe, Pid: 4232, TotalTime: 466, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09520, EstimatedImpact: 60% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 6288, TotalTime: 347, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 2476, TotalTime: 347, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 2168, TotalTime: 272, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-05-17T11:52:00.742 ProcessImageName: TabTip.exe, Pid: 11584, TotalTime: 186, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-17T11:52:00.742 ProcessImageName: AdobeCollabSync.exe, Pid: 11128, TotalTime: 136, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: Acrobat.exe, Pid: 10228, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 9% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 12416, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1229.log, EstimatedImpact: 3% 2026-05-17T11:52:00.742 ProcessImageName: SDXHelper.exe, Pid: 2380, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 6% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 13756, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\xampp\.modell, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: AcroCEF.exe, Pid: 12096, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 30% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 4936, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 4% 2026-05-17T11:52:00.742 ProcessImageName: spoolsv.exe, Pid: 3972, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\ch-filemanager_win.php.pdf, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: SDXHelper.exe, Pid: 11064, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 11712, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: powershell.exe, Pid: 4676, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 10052, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: xampp-control.exe, Pid: 2940, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\win.ini, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 11724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 12184, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 3% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 6128, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: svchost.exe, Pid: 2680, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 27% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 2800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1315.log, EstimatedImpact: 2% 2026-05-17T11:52:00.742 ProcessImageName: AdobeARM.exe, Pid: 11508, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 9% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 6544, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 8820, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 8% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 14260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1335.log, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: mysqld.exe, Pid: 6396, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 11476, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1310.log, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 14216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1326.log, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: httpd.exe, Pid: 6436, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\php186.tmp, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: dllhost.exe, Pid: 11448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9FE4E275.pf, EstimatedImpact: 6% 2026-05-17T11:52:00.742 ProcessImageName: svchost.exe, Pid: 3680, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: dllhost.exe, Pid: 1056, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9D002595.pf, EstimatedImpact: 6% 2026-05-17T11:52:00.742 ProcessImageName: dllhost.exe, Pid: 5552, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-96E3AFF5.pf, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: dllhost.exe, Pid: 13848, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 2% 2026-05-17T11:52:00.742 ProcessImageName: Acrobat.exe, Pid: 8900, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 1% 2026-05-17T11:52:00.742 ProcessImageName: dllhost.exe, Pid: 4664, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: OfficeC2RClient.exe, Pid: 13752, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1348.log, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: svchost.exe, Pid: 12576, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-17T11:52:00.742 ProcessImageName: AggregatorHost.exe, Pid: 5560, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x76c73e07 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 2026-05-17T12:02:21.168 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15109, FileId: 0x21000000042208, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T12:02:24.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x25266141 2026-05-17T12:02:43.654 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T12:02:43.655 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T12:02:43.655 [Cloud] Queued cloud request. 2026-05-17T12:02:43.655 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T12:02:43.655 [Cloud] Dequeued cloud request. 2026-05-17T12:02:43.655 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T12:02:44.351 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_neu.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T12:02:44.351 [Cloud] End of cloud request. 2026-05-17T12:02:44.864 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x25266141 2026-05-17T12:06:19.825 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T12:06:19.825 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T12:06:19.825 [Cloud] Queued cloud request. 2026-05-17T12:06:19.825 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T12:06:19.826 [Cloud] Dequeued cloud request. 2026-05-17T12:06:19.826 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T12:06:29.834 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_neu.php. status=0x40070000, statusex=0x200010, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T12:06:29.922 [Cloud] End of cloud request. 2026-05-17T12:06:30.436 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T12:10:24.451 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15130, FileId: 0x31000000041ceb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x82368c6b 2026-05-17T12:14:11.435 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T12:14:11.435 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T12:14:11.435 [Cloud] Queued cloud request. 2026-05-17T12:14:11.435 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T12:14:11.435 [Cloud] Dequeued cloud request. 2026-05-17T12:14:11.436 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T12:14:11.899 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager_neu.php@2026-05-17_141411. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T12:14:11.899 [Cloud] End of cloud request. 2026-05-17T12:14:12.428 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=5, resourceid=0x25266141 2026-05-17T12:16:16.253 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T12:16:16.253 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T12:16:16.253 [Cloud] Queued cloud request. 2026-05-17T12:16:16.253 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T12:16:16.253 [Cloud] Dequeued cloud request. 2026-05-17T12:16:16.254 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T12:16:16.750 [Cloud] End of cloud request. 2026-05-17T12:16:16.750 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_neu.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T12:16:17.267 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T12:17:29.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T12:24:47.588 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15258, FileId: 0x3e00000004898c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x92c05b2e Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 2026-05-17T12:32:34.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T12:33:20.543 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15738, FileId: 0x2e000000048b5c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=true, source=5, resourceid=0x25266141 2026-05-17T12:41:57.715 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15786, FileId: 0x43000000048afe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T12:47:39.785 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T12:58:47.267 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T12:58:47.267 [RTP] Duplicating the current plugin configuration object... 2026-05-17T12:58:47.267 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\DumpStack.log.tmp 2026-05-17T12:58:47.267 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T12:58:47.267 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T12:58:47.267 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T12:58:47.267 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T13:02:44.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T13:04:59.584 [AutoPurge] Verification Routine tasks have started. 2026-05-17T13:04:59.584 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-05-17T13:04:59.584 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-17T13:04:59.585 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-17T13:04:59.585 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-17T13:04:59.585 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-17T13:04:59.585 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-17T13:04:59.585 [AutoPurge] Routine task for Cache Maintenance has ended.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T13:04:59.612 [AutoPurge] Cleanup Routine tasks have started. 2026-05-17T13:04:59.618 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:9F5E0C7B-9043-43D1-91EB-6F117D13285D, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-17T13:04:59.618 Scheduled scan with Id 9F5E0C7B-9043-43D1-91EB-6F117D13285D configured CPU priority: normal (LowCpuPriority: 0) 2026-05-17T13:04:59.620 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-17T13:04:59.620 [SFC] System file cache build is not needed (already completed) 2026-05-17T13:04:59.630 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-17T13:04:59.637 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-17T13:04:59.637 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 9, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-17-2026 13:04:59 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-17-2026 13:04:59 2026-05-17T13:04:59.659 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-17T13:04:59.659 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-17T13:04:59.659 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-17T13:04:59.659 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-17T13:04:59.660 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-17T13:04:59.663 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-17T13:04:59.830 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-17T13:04:59.834 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-17T13:04:59.862 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-17T13:04:59.872 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-17T13:04:59.873 [AutoPurge] Verification Routine tasks have ended. 2026-05-17T13:05:00.789 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #16337, FileId: 0x27000000049a6d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T13:05:01.643 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T13:05:01.649 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T13:05:01.650 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-17T13:05:39.920 Engine:Triggered AR EMS scan 2026-05-17T13:05:39.920 Engine:EMS scan for process: lsass pid: 760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.940 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.950 Engine:EMS scan for process: svchost pid: 692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.962 Engine:EMS scan for process: svchost pid: 1032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.962 Engine:EMS scan for process: svchost pid: 1184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.973 Engine:EMS scan for process: svchost pid: 1268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.980 Engine:EMS scan for process: svchost pid: 1376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.980 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.980 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:39.993 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.002 Engine:EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.002 Engine:EMS scan for process: svchost pid: 1492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.010 Engine:EMS scan for process: svchost pid: 1528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.020 Engine:EMS scan for process: svchost pid: 1636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.020 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.030 Engine:EMS scan for process: svchost pid: 1756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.034 Engine:EMS scan for process: svchost pid: 1908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.040 Engine:EMS scan for process: svchost pid: 2044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.040 Engine:EMS scan for process: svchost pid: 1096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.040 Engine:EMS scan for process: svchost pid: 2096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.050 Engine:EMS scan for process: svchost pid: 2120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.050 Engine:EMS scan for process: svchost pid: 2156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.060 Engine:EMS scan for process: svchost pid: 2344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.060 Engine:EMS scan for process: svchost pid: 2360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.070 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.073 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.073 Engine:EMS scan for process: svchost pid: 2492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.080 Engine:EMS scan for process: svchost pid: 2620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.081 Engine:EMS scan for process: svchost pid: 2660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.081 Engine:EMS scan for process: svchost pid: 2680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.090 Engine:EMS scan for process: svchost pid: 2868, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.095 Engine:EMS scan for process: svchost pid: 2980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.099 Engine:EMS scan for process: svchost pid: 3012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.112 Engine:EMS scan for process: svchost pid: 3108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.120 Engine:EMS scan for process: svchost pid: 3568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.120 Engine:EMS scan for process: svchost pid: 3604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.130 Engine:EMS scan for process: svchost pid: 3612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.130 Engine:EMS scan for process: svchost pid: 3688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.140 Engine:EMS scan for process: svchost pid: 3832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.140 Engine:EMS scan for process: svchost pid: 3880, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.150 Engine:EMS scan for process: svchost pid: 1852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.159 Engine:EMS scan for process: svchost pid: 1896, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.159 Engine:EMS scan for process: svchost pid: 3216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.159 Engine:EMS scan for process: svchost pid: 4132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.173 Engine:EMS scan for process: svchost pid: 4144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.180 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.180 Engine:EMS scan for process: svchost pid: 4336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.190 Engine:EMS scan for process: svchost pid: 4344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.190 Engine:EMS scan for process: svchost pid: 4492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.200 Engine:EMS scan for process: svchost pid: 5108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.210 Engine:EMS scan for process: svchost pid: 5864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.210 Engine:EMS scan for process: svchost pid: 3664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.219 Engine:EMS scan for process: dllhost pid: 4664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.219 Engine:EMS scan for process: svchost pid: 5740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.230 Engine:EMS scan for process: svchost pid: 5916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.240 Engine:EMS scan for process: svchost pid: 6204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.240 Engine:EMS scan for process: svchost pid: 7120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.250 Engine:EMS scan for process: svchost pid: 8020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.260 Engine:EMS scan for process: svchost pid: 8036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.260 Engine:EMS scan for process: svchost pid: 6056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.288 Engine:EMS scan for process: svchost pid: 8080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.301 Engine:EMS scan for process: explorer pid: 8628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.358 Engine:EMS scan for process: svchost pid: 8740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.369 Engine:EMS scan for process: svchost pid: 8912, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.378 Engine:EMS scan for process: svchost pid: 9448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.383 Engine:EMS scan for process: svchost pid: 9780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.391 Engine:EMS scan for process: svchost pid: 10772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.397 Engine:EMS scan for process: dllhost pid: 11068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.399 Engine:EMS scan for process: svchost pid: 11392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.407 Engine:EMS scan for process: svchost pid: 4312, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.411 Engine:EMS scan for process: svchost pid: 9708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.416 Engine:EMS scan for process: svchost pid: 472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.418 Engine:EMS scan for process: svchost pid: 12576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.427 Engine:EMS scan for process: svchost pid: 2560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.435 Engine:EMS scan for process: dllhost pid: 7940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.437 Engine:EMS scan for process: svchost pid: 5976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.440 Engine:EMS scan for process: dllhost pid: 3736, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.443 Engine:EMS scan for process: powershell pid: 11452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:05:40.690 Engine:EMS scan for process: svchost pid: 3740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-17T13:09:57.461 QuickScan:ScanID:9F5E0C7B-9043-43D1-91EB-6F117D13285D: Quick scan finished with error 0 2026-05-17T13:09:57.996 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-17T13:09:58.013 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:09:58.015 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-17T13:09:58.015 [RTP] Duplicating the current plugin configuration object... 2026-05-17T13:09:58.015 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T13:09:58.015 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-17T13:09:58.015 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-17T13:09:58.015 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-17T13:09:58.015 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T13:09:58.015 [RTP] No config change detected. Not updating plugin configuration. 2026-05-17T13:09:58.015 [RTP] No config changes found. No configuration switch. 2026-05-17T13:09:58.015 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-17T13:09:58.015 [RTP] Duplicating the current plugin configuration object... 2026-05-17T13:09:58.015 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T13:09:58.015 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-17T13:09:58.016 [RTP] No config change detected. Not updating plugin configuration. 2026-05-17T13:09:58.016 [RTP] No config changes found. No configuration switch. 2026-05-17T13:09:58.016 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-17T13:09:58.016 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-17T13:09:58.016 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-17T13:09:58.016 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-17T13:09:58.016 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-17T13:09:58.016 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-17T13:09:58.016 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:09:58.016 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-17T13:09:58.016 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-17T13:09:58.016 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-17T13:09:58.016 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-17T13:09:58.016 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T13:09:58.017 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T13:09:58.017 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T13:09:58.017 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T13:09:58.017 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T13:09:58.017 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T13:09:58.017 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-17T13:09:58.017 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-17T13:09:58.019 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:09:58.022 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:09:58.025 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:09:58.082 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 39970394(ms) from now at 02:16 (00:16 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-17T13:09:59.494 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T13:09:59.499 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T13:09:59.501 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T13:10:00.567 [RTP] Duplicating the current plugin configuration object... 2026-05-17T13:10:00.567 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T13:10:00.567 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-17T13:10:00.567 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-17T13:10:00.568 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-17T13:17:49.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T13:32:54.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x3a12bcf7 2026-05-17T13:33:03.183 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T13:33:03.183 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T13:33:03.183 [Cloud] Queued cloud request. 2026-05-17T13:33:03.183 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T13:33:03.183 [Cloud] Dequeued cloud request. 2026-05-17T13:33:03.184 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T13:33:03.783 [Cloud] End of cloud request. 2026-05-17T13:33:03.783 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T13:33:04.303 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T13:43:31.190 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17389, FileId: 0x42000000036716, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T13:47:59.791 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T13:52:00.760 ProcessImageName: notepad++.exe, Pid: 1216, TotalTime: 12351, Count: 1264, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: AcroCEF.exe, Pid: 1192, TotalTime: 3595, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-17T13:52:00.760 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 3051, Count: 182, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume10\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1701, Count: 7, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: powershell.exe, Pid: 2828, TotalTime: 1559, Count: 61, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 9796, TotalTime: 1022, Count: 121, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: splwow64.exe, Pid: 7348, TotalTime: 975, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 1556, TotalTime: 936, Count: 96, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 1364, TotalTime: 926, Count: 70, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: PDFXCview.exe, Pid: 2828, TotalTime: 810, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 47% 2026-05-17T13:52:00.760 ProcessImageName: notepad++.exe, Pid: 6824, TotalTime: 615, Count: 63, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: firefox.exe, Pid: 13780, TotalTime: 585, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 43% 2026-05-17T13:52:00.760 ProcessImageName: firefox.exe, Pid: 4232, TotalTime: 466, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09520, EstimatedImpact: 60% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 6288, TotalTime: 347, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 2476, TotalTime: 347, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 2168, TotalTime: 272, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-05-17T13:52:00.760 ProcessImageName: TabTip.exe, Pid: 11584, TotalTime: 186, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-17T13:52:00.760 ProcessImageName: AdobeCollabSync.exe, Pid: 11128, TotalTime: 136, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: spoolsv.exe, Pid: 3972, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\ch-filemanager_win.php.pdf, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: Acrobat.exe, Pid: 10228, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 9% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 12416, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1229.log, EstimatedImpact: 3% 2026-05-17T13:52:00.760 ProcessImageName: SDXHelper.exe, Pid: 2380, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 6% 2026-05-17T13:52:00.760 ProcessImageName: dllhost.exe, Pid: 4664, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 13756, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\xampp\.modell, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: AcroCEF.exe, Pid: 12096, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 30% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 5408, TotalTime: 77, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 4936, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 4% 2026-05-17T13:52:00.760 ProcessImageName: SDXHelper.exe, Pid: 11064, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 11712, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: svchost.exe, Pid: 1404, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: powershell.exe, Pid: 4676, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: powershell.exe, Pid: 11452, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 10052, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: xampp-control.exe, Pid: 2940, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\win.ini, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 8240, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 12184, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 3% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 11724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 6128, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: svchost.exe, Pid: 2680, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 27% 2026-05-17T13:52:00.760 ProcessImageName: AdobeARM.exe, Pid: 11508, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 9% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 2800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1315.log, EstimatedImpact: 2% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 6544, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 8820, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 8% 2026-05-17T13:52:00.760 ProcessImageName: AdobeARM.exe, Pid: 11040, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 7% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 14260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1335.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: mysqld.exe, Pid: 6396, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: AggregatorHost.exe, Pid: 5560, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 5968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1410.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 4160, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1433.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 8568, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1504.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 11476, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1310.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 14216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1326.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1402.log, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: dllhost.exe, Pid: 11448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9FE4E275.pf, EstimatedImpact: 6% 2026-05-17T13:52:00.760 ProcessImageName: httpd.exe, Pid: 6436, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\php186.tmp, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: svchost.exe, Pid: 3680, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: dllhost.exe, Pid: 1056, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9D002595.pf, EstimatedImpact: 6% 2026-05-17T13:52:00.760 ProcessImageName: dllhost.exe, Pid: 13848, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 2% 2026-05-17T13:52:00.760 ProcessImageName: dllhost.exe, Pid: 5552, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-96E3AFF5.pf, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: Acrobat.exe, Pid: 8900, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 1% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 13752, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1348.log, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: sihost.exe, Pid: 7904, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 5384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1441.log, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: OfficeC2RClient.exe, Pid: 1172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1424.log, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: svchost.exe, Pid: 12576, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-17T13:52:00.760 ProcessImageName: brynhildr.exe, Pid: 3564, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-17T13:58:21.981 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18004, FileId: 0x4b000000040055, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T14:03:04.797 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T14:18:09.801 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T14:18:55.382 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19797, FileId: 0x35000000049a88, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T14:28:09.812 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19963, FileId: 0x4e00000004bfd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T14:33:14.794 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T14:48:19.802 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T15:03:24.802 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T15:18:29.793 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T15:33:34.784 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T15:42:19.443 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #21518, FileId: 0x4f000000008e05, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T15:48:39.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T15:52:00.773 ProcessImageName: notepad++.exe, Pid: 2436, TotalTime: 12817, Count: 1445, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_windows.php, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: notepad++.exe, Pid: 1216, TotalTime: 12351, Count: 1264, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: AcroCEF.exe, Pid: 1192, TotalTime: 3595, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-17T15:52:00.773 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 3341, Count: 207, MaxTime: 296, MaxTimeFile: \Device\HarddiskVolume10\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1701, Count: 7, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: xampp-control.exe, Pid: 13712, TotalTime: 1640, Count: 3, MaxTime: 1500, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-05-17T15:52:00.773 ProcessImageName: powershell.exe, Pid: 2828, TotalTime: 1559, Count: 61, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 1556, TotalTime: 1313, Count: 142, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 9796, TotalTime: 1022, Count: 121, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 13040, TotalTime: 976, Count: 117, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: splwow64.exe, Pid: 7348, TotalTime: 975, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 1364, TotalTime: 926, Count: 70, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: PDFXCview.exe, Pid: 2828, TotalTime: 810, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 47% 2026-05-17T15:52:00.773 ProcessImageName: notepad++.exe, Pid: 6824, TotalTime: 615, Count: 63, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: firefox.exe, Pid: 13780, TotalTime: 585, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 43% 2026-05-17T15:52:00.773 ProcessImageName: firefox.exe, Pid: 4232, TotalTime: 466, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09520, EstimatedImpact: 60% 2026-05-17T15:52:00.773 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 12832, TotalTime: 406, Count: 69, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: WmiPrvSE.exe, Pid: 2964, TotalTime: 361, Count: 60, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 10% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 6288, TotalTime: 347, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 2476, TotalTime: 347, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: splwow64.exe, Pid: 10160, TotalTime: 287, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Microsoft\OPC\DDT._ey6vknm2hdz_9033ovdwoawc.tmp, EstimatedImpact: 2% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 2168, TotalTime: 272, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 252, TotalTime: 259, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 20% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 2460, TotalTime: 231, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-05-17T15:52:00.773 ProcessImageName: TabTip.exe, Pid: 11584, TotalTime: 186, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-17T15:52:00.773 ProcessImageName: spoolsv.exe, Pid: 3972, TotalTime: 166, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\ch-filemanager_win.php.pdf, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: AdobeCollabSync.exe, Pid: 11128, TotalTime: 136, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: Acrobat.exe, Pid: 10228, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 9% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 4664, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 1404, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 9992, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4DF.tmp, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 12416, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1229.log, EstimatedImpact: 3% 2026-05-17T15:52:00.773 ProcessImageName: SDXHelper.exe, Pid: 11064, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: SDXHelper.exe, Pid: 2380, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 6% 2026-05-17T15:52:00.773 ProcessImageName: FileCoAuth.exe, Pid: 1960, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 13756, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\xampp\.modell, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: AcroCEF.exe, Pid: 12096, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 30% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 5408, TotalTime: 77, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-17T15:52:00.773 ProcessImageName: SDXHelper.exe, Pid: 13652, TotalTime: 76, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EDF0B1E6-B99F-47C0-906A-E85C1CDA8E2B, EstimatedImpact: 12% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 4936, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 4% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 11712, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 14236, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 3812, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: powershell.exe, Pid: 4676, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: powershell.exe, Pid: 11452, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 10052, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: AggregatorHost.exe, Pid: 5560, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 11236, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 8240, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: xampp-control.exe, Pid: 2940, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\win.ini, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 11724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 12184, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 3% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 6128, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 2680, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 27% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 2800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1315.log, EstimatedImpact: 2% 2026-05-17T15:52:00.773 ProcessImageName: AdobeARM.exe, Pid: 11508, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 9% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 13652, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 6544, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 8820, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 8% 2026-05-17T15:52:00.773 ProcessImageName: AdobeARM.exe, Pid: 11040, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 7% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 2952, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 18% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 14260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1335.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 2196, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1558.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 14264, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1618.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 6396, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 8568, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1504.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1402.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 5968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1410.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 4160, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1433.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 14216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1326.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 11476, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1310.log, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: httpd.exe, Pid: 6436, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\php186.tmp, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 11448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9FE4E275.pf, EstimatedImpact: 6% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 3680, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 1056, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9D002595.pf, EstimatedImpact: 6% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 5552, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-96E3AFF5.pf, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 2196, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 6% 2026-05-17T15:52:00.773 ProcessImageName: dllhost.exe, Pid: 13848, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 2% 2026-05-17T15:52:00.773 ProcessImageName: Acrobat.exe, Pid: 8900, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 1% 2026-05-17T15:52:00.773 ProcessImageName: mysqld.exe, Pid: 368, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql\db.MAI, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 3456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1628.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: sihost.exe, Pid: 7904, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 5384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1441.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 13752, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1348.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: OfficeC2RClient.exe, Pid: 1172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1424.log, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: svchost.exe, Pid: 12576, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-17T15:52:00.773 ProcessImageName: brynhildr.exe, Pid: 3564, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-17T15:56:17.643 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21702, FileId: 0x2900000003ae52, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:03:44.793 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T16:11:24.198 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22225, FileId: 0x19000000036723, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:18:49.787 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T16:33:54.797 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x8f3e43bf 2026-05-17T16:40:56.927 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T16:40:56.927 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T16:40:56.927 [Cloud] Queued cloud request. 2026-05-17T16:40:56.927 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T16:40:56.927 [Cloud] Dequeued cloud request. 2026-05-17T16:40:56.943 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T16:40:57.467 [Cloud] End of cloud request. 2026-05-17T16:40:57.467 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T16:40:57.987 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T16:48:59.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T16:54:40.247 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23433, FileId: 0x33000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.247 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23435, FileId: 0x1d7000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.257 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23438, FileId: 0x1d9000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.257 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23436, FileId: 0x34000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.262 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23440, FileId: 0x1da000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.267 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23443, FileId: 0x1db000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.267 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23439, FileId: 0x35000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.267 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23441, FileId: 0x36000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.278 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23446, FileId: 0x1de000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.283 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23444, FileId: 0x1dc000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.297 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23448, FileId: 0x1df000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.297 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23451, FileId: 0x3e000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.302 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23450, FileId: 0x1e0000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.302 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23452, FileId: 0x1e2000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.697 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23526, FileId: 0x40000000006727, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:54:40.707 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\3f1b3270-251c-4ee8-bd43-1718b9d3a8e0. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #23528, FileId: 0x1aa000000004cba, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.327 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBCF42E967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23535, FileId: 0x1f000000061dd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.347 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C9D8E98D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23536, FileId: 0x20000000061dd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.354 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE8285993F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23537, FileId: 0x21000000061dd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.357 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj743587974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23538, FileId: 0x22000000061dd2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.377 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE4ADC6990. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23540, FileId: 0x1c000000061dc8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.387 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDAA0789C4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23541, FileId: 0x25000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.597 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB7E4379E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23542, FileId: 0x23000000061fc3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.617 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6C17479B8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23543, FileId: 0x29000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.627 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj53187495B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23544, FileId: 0x2a000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.639 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj38A6D593F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23545, FileId: 0x2b000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.656 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45ED519BA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23546, FileId: 0x2c000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.667 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj26B843915. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23547, FileId: 0x2d000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.677 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C47389B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23548, FileId: 0x2e000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.687 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj677EAF9A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23549, FileId: 0x2f000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.707 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCE1FBB9AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23550, FileId: 0x30000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.717 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB8A957992. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23551, FileId: 0x31000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.727 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj66FE88966. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23552, FileId: 0x32000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.758 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj248CE99A9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23553, FileId: 0x33000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.768 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBD509B99E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23554, FileId: 0x34000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.777 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA94C8D920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23555, FileId: 0x35000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.787 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC901279F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23556, FileId: 0x36000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.807 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB14B689D8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23557, FileId: 0x3d000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.807 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6297AC902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23558, FileId: 0x3e000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.928 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC64CAF950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23559, FileId: 0x24000000061fc3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.943 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj06129397B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23560, FileId: 0x3a000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.955 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB1C58D9E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23561, FileId: 0x3b000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.967 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E5116933. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23562, FileId: 0x3c000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:30.991 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7B857292C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23563, FileId: 0x3d000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.002 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9DB0FD9E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23564, FileId: 0x3e000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.017 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBAB61D947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23565, FileId: 0x3f000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.027 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C6EA3940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23566, FileId: 0x40000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.038 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj927A759F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23567, FileId: 0x41000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.055 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3D55BF9DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23568, FileId: 0x42000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.067 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7859E399A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23569, FileId: 0x43000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.087 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF6B8D39BB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23570, FileId: 0x44000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.102 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC697CE946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23571, FileId: 0x45000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.177 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj16F5649C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23572, FileId: 0x46000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.197 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj451A4F9C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23573, FileId: 0x47000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.207 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9840E6944. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23574, FileId: 0x48000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.207 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C1B2A9E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23575, FileId: 0x49000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.227 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2C822A97C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23576, FileId: 0x56000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.237 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF4AD039D1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23577, FileId: 0x57000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.327 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj668888968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23578, FileId: 0x26000000061fc3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.342 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj85846A98B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23579, FileId: 0x4b000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.358 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj97C8119FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23580, FileId: 0x4c000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.368 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7974AA9EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23581, FileId: 0x4d000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.377 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB85FE4993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23582, FileId: 0x4e000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.403 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj922A0F938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23583, FileId: 0x4f000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.417 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj936BB198F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23584, FileId: 0x50000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.427 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4B899696E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23585, FileId: 0x51000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.432 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7D04BD9DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23586, FileId: 0x52000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.447 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5B78049E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23587, FileId: 0x66000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.455 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj06CBBD97B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23588, FileId: 0x67000000061de1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.547 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45E1349BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23589, FileId: 0x28000000061fc3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.562 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4004A19DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23590, FileId: 0x54000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.578 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC051D4980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23591, FileId: 0x55000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.587 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD6F807938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23592, FileId: 0x56000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.603 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5F2752989. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23593, FileId: 0x57000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.623 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC859FD9C5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23594, FileId: 0x58000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.637 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D431399B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23595, FileId: 0x59000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:31.660 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8B14C490D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23596, FileId: 0x5a000000061f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:45.238 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23597, FileId: 0xb200000001ac18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:45.382 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23599, FileId: 0x1d000000061dc8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:59.718 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23601, FileId: 0x29000000061d7d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T16:55:59.728 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23603, FileId: 0x28000000061da4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T17:04:04.790 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T17:19:09.788 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{BE6BD42A-23C8-F38D-F261-DB4B23094A05} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:6540 ProcessCreationTime:134235063527633134 SessionID:2 CreationTime:05-17-2026 17:34:13 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-05-17T17:34:14.428 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T17:34:14.428 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T17:34:14.428 [Cloud] Queued cloud request. 2026-05-17T17:34:14.428 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T17:34:14.428 [Cloud] Dequeued cloud request. 2026-05-17T17:34:14.428 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T17:34:14.786 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T17:34:14.828 [Cloud] End of cloud request. 2026-05-17T17:34:15.338 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T17:49:19.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T17:52:00.789 ProcessImageName: notepad++.exe, Pid: 2436, TotalTime: 13827, Count: 1559, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_windows.php, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: notepad++.exe, Pid: 1216, TotalTime: 12351, Count: 1264, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 7651, Count: 290, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: AcroCEF.exe, Pid: 1192, TotalTime: 3595, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-17T17:52:00.789 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1701, Count: 7, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: xampp-control.exe, Pid: 13712, TotalTime: 1640, Count: 3, MaxTime: 1500, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-05-17T17:52:00.789 ProcessImageName: powershell.exe, Pid: 2828, TotalTime: 1559, Count: 61, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 1556, TotalTime: 1313, Count: 142, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 9796, TotalTime: 1022, Count: 121, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 13040, TotalTime: 976, Count: 117, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: splwow64.exe, Pid: 7348, TotalTime: 975, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 1364, TotalTime: 926, Count: 70, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: PDFXCview.exe, Pid: 2828, TotalTime: 810, Count: 75, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\Languages\PDFXVW_Ar.xml, EstimatedImpact: 47% 2026-05-17T17:52:00.789 ProcessImageName: notepad++.exe, Pid: 6824, TotalTime: 615, Count: 63, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: firefox.exe, Pid: 13780, TotalTime: 585, Count: 53, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 43% 2026-05-17T17:52:00.789 ProcessImageName: firefox.exe, Pid: 4232, TotalTime: 466, Count: 42, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09520, EstimatedImpact: 60% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 11676, TotalTime: 458, Count: 56, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 3% 2026-05-17T17:52:00.789 ProcessImageName: firefox.exe, Pid: 3184, TotalTime: 450, Count: 97, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 50% 2026-05-17T17:52:00.789 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 12832, TotalTime: 421, Count: 71, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: WmiPrvSE.exe, Pid: 2964, TotalTime: 361, Count: 60, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 10% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 6288, TotalTime: 347, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 24% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 2476, TotalTime: 347, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: splwow64.exe, Pid: 10160, TotalTime: 287, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Microsoft\OPC\DDT._ey6vknm2hdz_9033ovdwoawc.tmp, EstimatedImpact: 2% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 2168, TotalTime: 272, Count: 35, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 252, TotalTime: 259, Count: 78, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\conf\httpd.conf, EstimatedImpact: 20% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 2460, TotalTime: 231, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 210, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 10% 2026-05-17T17:52:00.789 ProcessImageName: AdobeCollabSync.exe, Pid: 11128, TotalTime: 196, Count: 31, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: TabTip.exe, Pid: 11584, TotalTime: 186, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-05-17T17:52:00.789 ProcessImageName: spoolsv.exe, Pid: 3972, TotalTime: 166, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\ch-filemanager_win.php.pdf, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 1404, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 4664, TotalTime: 151, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: Acrobat.exe, Pid: 10228, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll, EstimatedImpact: 9% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 9992, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4DF.tmp, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 12416, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1229.log, EstimatedImpact: 3% 2026-05-17T17:52:00.789 ProcessImageName: SDXHelper.exe, Pid: 11064, TotalTime: 90, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: SDXHelper.exe, Pid: 2380, TotalTime: 90, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\InstallerMainShell.tlb, EstimatedImpact: 6% 2026-05-17T17:52:00.789 ProcessImageName: FileCoAuth.exe, Pid: 1960, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetry-dll-ramp-value.txt, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: AggregatorHost.exe, Pid: 5560, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 13756, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\xampp\.modell, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: AcroCEF.exe, Pid: 12096, TotalTime: 90, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index, EstimatedImpact: 30% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 5408, TotalTime: 77, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9ED94684-9B93-43AE-B8D2-1AC9DA1C5B0B, EstimatedImpact: 3% 2026-05-17T17:52:00.789 ProcessImageName: SDXHelper.exe, Pid: 13652, TotalTime: 76, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\EDF0B1E6-B99F-47C0-906A-E85C1CDA8E2B, EstimatedImpact: 12% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 4936, TotalTime: 76, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 4% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 11712, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 14236, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 3812, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: powershell.exe, Pid: 11452, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: powershell.exe, Pid: 4676, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 10052, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: xampp-control.exe, Pid: 2940, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\win.ini, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 11724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 8240, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 12184, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 3% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 11236, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 6128, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: backgroundTaskHost.exe, Pid: 12124, TotalTime: 45, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1778675974, EstimatedImpact: 9% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 2680, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msjhbd.ttc, EstimatedImpact: 27% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 2800, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1315.log, EstimatedImpact: 2% 2026-05-17T17:52:00.789 ProcessImageName: AdobeARM.exe, Pid: 11508, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 9% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 13652, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 6544, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 8820, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 8% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 2952, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 18% 2026-05-17T17:52:00.789 ProcessImageName: AdobeARM.exe, Pid: 11040, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 7% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 14260, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1335.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 2196, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1558.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 14264, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1618.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 6396, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 8568, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1504.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 11476, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1310.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 7328, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1402.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 9456, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1756.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 14216, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1326.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 5968, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1410.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 4160, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1433.log, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 11448, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9FE4E275.pf, EstimatedImpact: 6% 2026-05-17T17:52:00.789 ProcessImageName: httpd.exe, Pid: 6436, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\tmp\php186.tmp, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 3680, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 1056, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-9D002595.pf, EstimatedImpact: 6% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 5552, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-96E3AFF5.pf, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1811.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 2196, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 6% 2026-05-17T17:52:00.789 ProcessImageName: dllhost.exe, Pid: 13848, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 2% 2026-05-17T17:52:00.789 ProcessImageName: Acrobat.exe, Pid: 8900, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat, EstimatedImpact: 1% 2026-05-17T17:52:00.789 ProcessImageName: mysqld.exe, Pid: 368, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql\db.MAI, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 3456, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1628.log->(UTF-16LE), EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 5384, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1441.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 13752, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1348.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: OfficeC2RClient.exe, Pid: 1172, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260517-1424.log, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: sihost.exe, Pid: 7904, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: svchost.exe, Pid: 12576, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-17T17:52:00.789 ProcessImageName: brynhildr.exe, Pid: 3564, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-17T18:04:24.789 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T18:19:29.799 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T18:34:34.800 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T18:46:22.309 Engine:Process 6320 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-05-17T18:49:05.200 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25230, FileId: 0x1e6000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.200 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25229, FileId: 0x1e5000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.206 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25232, FileId: 0x35000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.206 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25233, FileId: 0x1e9000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.210 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25234, FileId: 0x1ea000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.210 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25238, FileId: 0x1eb000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.210 Bm signature throttled:0x000045b3435c1067 2026-05-17T18:49:05.210 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25239, FileId: 0x38000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.215 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25240, FileId: 0x1ec000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.215 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25241, FileId: 0x39000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.219 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25242, FileId: 0x1ed000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.222 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25237, FileId: 0x37000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.222 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25243, FileId: 0x3a000000041d18, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.855 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25314, FileId: 0x1fa000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:05.912 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #25323, FileId: 0x1fe000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T18:49:39.790 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T19:04:44.790 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T19:19:49.634 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T19:34:54.492 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T19:36:42.766 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\947EEBBF-93BC-4661-B7B8-95B3C9E03739140c.1dce6347bb6610d 2026-05-17T19:36:42.966 Verifying engine and signature files (source: 0) ... 2026-05-17T19:36:42.966 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpengine.dll] due to PPL. 2026-05-17T19:36:42.966 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasbase.vdm]. File not in cache (0x1) 2026-05-17T19:36:43.716 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasbase.vdm] 2026-05-17T19:36:43.726 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-17T19:36:43.746 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasdlta.vdm] 2026-05-17T19:36:43.746 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavbase.vdm]. File not in cache (0x1) 2026-05-17T19:36:44.096 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavbase.vdm] 2026-05-17T19:36:44.096 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-17T19:36:44.116 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavdlta.vdm] 2026-05-17T19:36:44.284 [Engine] IsHybridMode: 0 2026-05-17T19:36:44.284 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-17T19:36:44.286 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3632A685AD55BA50C045FDC119E112A882B1F1BB.bin): 0x00000002 2026-05-17T19:36:44.296 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3632A685AD55BA50C045FDC119E112A882B1F1BB.bin) 2026-05-17T19:36:44.296 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-17T19:36:44.296 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-17T19:36:44.296 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-17T19:36:44.296 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-17T19:36:54.766 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-17T19:36:54.766 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-17T19:36:54.790 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFDEE955810, lRefCount: 5, hr=0 2026-05-17T19:36:54.790 [Engine] New active engine 00007FFE13845810 replacing engine 00007FFDEE955810. Number of active engines: 2 2026-05-17T19:36:54.795 EngineInit:Global ASOC is enabled 2026-05-17T19:36:54.795 EngineInit:ASOO is enabled for developer volumes 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-17T19:36:54.859 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3fb4107645e5705799eec11afedc51c659fbbe74 Dynamic Signature Compilation Timestamp:05-17-2026 09:51:06 Persistence Type:Duration Time remaining:288000000 2026-05-17T19:36:54.874 Dynamic signature dropped 2026-05-17T19:36:54.874 MpWriteUupSignatureVersion 1.449.666.0, hr = 0 2026-05-17T19:36:54.874 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-17T19:36:54.895 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-17T19:36:54.895 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-17T19:36:54.895 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-17T19:36:54.895 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-17T19:36:54.895 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-17T19:36:54.915 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-17T19:36:54.915 [Plugin] Initializing RTP plugin state... 2026-05-17T19:36:54.915 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-17T19:36:54.915 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎17‎-‎2026 11:52:01 Last Perf:‎05‎-‎17‎-‎2026 11:52:00 First RTP Scan:‎05‎-‎17‎-‎2026 11:52:01 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2566 Misses:29848 BM Queue:0,666,0 Proc:0,130,0 File:0,593,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:41246 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:277777425 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:24234 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:70928 TotalHits:400264 InstanceCacheInserts:2523 InstanceCacheUpdates:0 InstanceCacheDeletes:1350 InstanceCacheHits:537 InstanceCacheMisses:38721 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:1ms (2095/1143) Success: 1143, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-17T19:36:54.915 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E} 2026-05-17T19:36:54.915 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-17T19:36:54.915 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0B62CA94-2202-43BE-90FE-61E222385E95} removed 2026-05-17T19:36:54.915 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598}\mpasbase.vdm in use, hr=0x80070020 2026-05-17T19:36:54.925 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.925 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.925 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.925 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.925 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-17-2026 19:36:54 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-17-2026 19:36:54 2026-05-17T19:36:54.925 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T19:36:54.925 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-17T19:36:54.925 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-17T19:36:54.925 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-17T19:36:54.925 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T19:36:54.935 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.935 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.935 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.935 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-17T19:36:54.935 MdCoreSvc is supported in this platform and OS Signature updated on 05-17-2026 19:36:54 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.666.0 AV Signature Version: 1.449.666.0 ************************************************************ 2026-05-17T19:36:54.937 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-17T19:36:54.937 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\947EEBBF-93BC-4661-B7B8-95B3C9E03739140c.1dce6347bb6610d 2026-05-17T19:36:54.945 Process scan (postsignatureupdatescan) started. 2026-05-17T19:36:55.025 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-17T19:36:55.025 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-17T19:36:55.395 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-17T19:36:55.395 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-17T19:36:55.395 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-17T19:36:55.395 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-17T19:36:55.395 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-17T19:36:55.395 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-17T19:36:55.395 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-17T19:36:55.395 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-17T19:36:55.400 [Engine] Engine 00007FFDEE955810 no longer in use. Number of active engines: 1 2026-05-17T19:36:55.400 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-17T19:36:55.400 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-17T19:36:55.604 ProcessImageName: notepad++.exe, Pid: 2436, TotalTime: 13887, Count: 1586, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager_windows.php, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: notepad++.exe, Pid: 1216, TotalTime: 12351, Count: 1264, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\plugins\Explorer\Explorer.dll, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: notepad++.exe, Pid: 5608, TotalTime: 10974, Count: 1225, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager_windows.php@2026-05-17_210446, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 7712, Count: 295, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: AcroCEF.exe, Pid: 1192, TotalTime: 3595, Count: 175, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 29% 2026-05-17T19:36:55.604 ProcessImageName: firefox.exe, Pid: 252, TotalTime: 2149, Count: 206, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa09460, EstimatedImpact: 74% 2026-05-17T19:36:55.604 ProcessImageName: xampp-control.exe, Pid: 3236, TotalTime: 1701, Count: 7, MaxTime: 1453, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: xampp-control.exe, Pid: 13712, TotalTime: 1640, Count: 3, MaxTime: 1500, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 38% 2026-05-17T19:36:55.604 ProcessImageName: powershell.exe, Pid: 2828, TotalTime: 1559, Count: 61, MaxTime: 937, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsPowerShell\Modules\PSReadline\2.0.0\Microsoft.PowerShell.PSReadline.dll, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: httpd.exe, Pid: 1556, TotalTime: 1313, Count: 142, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: mysqld.exe, Pid: 9796, TotalTime: 1022, Count: 121, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: mysqld.exe, Pid: 13040, TotalTime: 976, Count: 117, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: splwow64.exe, Pid: 7348, TotalTime: 975, Count: 88, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1C149F75-3AC6-4874-82C2-56388500F09C\69b8a4a.gpd, EstimatedImpact: 0% 2026-05-17T19:36:55.604 ProcessImageName: httpd.exe, Pid: 1364, TotalTime: 926, Count: 70, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-05-17T19:36:55.660 [Engine] RSIG_UNLOADENGINE, 00007FFDEE955810, err=0x0 2026-05-17T19:36:55.679 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{140CAA99-8182-4A9E-B8F2-8351166EC598} removed 2026-05-17T19:36:56.949 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-17T19:36:56.958 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-17T19:36:56.958 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 Internal signature match:subtype=Lowfi, sigseq=0x0000157E67AA49DF, sigsha=cd8f16a9d4beb15e15e36fc9a546c2d5bfbafd06, cached=false, source=0, resourceid=0x0d0ba041 2026-05-17T19:37:16.022 Process scan (postsignatureupdatescan) completed. 2026-05-17T19:41:54.788 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-17T19:49:59.388 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T19:52:14.062 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #41640, FileId: 0x9e00000000b9d3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T20:05:04.306 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T20:20:09.245 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T20:35:14.201 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T20:42:55.396 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #42606, FileId: 0x74000000013a8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T20:50:19.167 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T20:51:39.798 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #43144, FileId: 0x2e00000001ad3c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000064E730511CB7, sigsha=ee8eaa1b2bfdb8574d0f67ea4bc580435a0cb353, cached=false, source=2, resourceid=0x3a12bcf7 2026-05-17T20:56:22.530 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T20:56:22.530 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T20:56:22.530 [Cloud] Queued cloud request. 2026-05-17T20:56:22.530 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T20:56:22.530 [Cloud] Dequeued cloud request. 2026-05-17T20:56:22.530 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T20:56:23.001 [Cloud] End of cloud request. 2026-05-17T20:56:23.001 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\ch-filemanager\ch-filemanager-2.1\ch-filemanager.php. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x64e730511cb7 2026-05-17T20:56:23.530 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:00:01.775 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #43204, FileId: 0x22000000011de8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:05:24.146 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T21:11:32.189 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-17T21:11:32.189 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-05-17T21:11:32.189 [RTP] Duplicating the current plugin configuration object... 2026-05-17T21:11:32.189 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-17T21:11:32.189 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-17T21:11:32.189 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-17T21:11:32.189 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-17T21:14:11.566 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-5499C7BB.pf. Process: \Device\HarddiskVolume8\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #46514, FileId: 0xf0000000bcf0b, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x93e3d568 2026-05-17T21:14:32.506 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:32.506 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:32.506 [Cloud] Queued cloud request. 2026-05-17T21:14:32.506 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:32.506 [Cloud] Dequeued cloud request. 2026-05-17T21:14:32.506 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:32.877 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\700631d79a4043f2ddab3f75dc9273935e1271bb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:32 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:32.885 [Cloud] End of cloud request. 2026-05-17T21:14:32.885 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x78674378 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x14197fae Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d00769c 2026-05-17T21:14:33.229 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:33.229 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:33.229 [Cloud] Queued cloud request. 2026-05-17T21:14:33.229 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:33.229 [Cloud] Dequeued cloud request. 2026-05-17T21:14:33.235 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:33.235 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:33.235 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:33.235 [Cloud] Queued cloud request. 2026-05-17T21:14:33.235 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:33.235 [Cloud] Dequeued cloud request. 2026-05-17T21:14:33.235 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:33.252 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:33.252 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:33.252 [Cloud] Queued cloud request. 2026-05-17T21:14:33.252 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:33.252 [Cloud] Dequeued cloud request. 2026-05-17T21:14:33.255 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:33.408 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:33.440 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e3d8a1441791fe5e02f1dcc2dd94eda1246935f9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:33.440 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:33.440 [Cloud] End of cloud request. 2026-05-17T21:14:33.586 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aa3835be3cd34c86c8332069f8dcc81e85a79fa3 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:33.586 [Cloud] End of cloud request. 2026-05-17T21:14:33.586 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe6ba0229 2026-05-17T21:14:33.646 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:33.646 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:33.646 [Cloud] Queued cloud request. 2026-05-17T21:14:33.646 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:33.646 [Cloud] Dequeued cloud request. 2026-05-17T21:14:33.646 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:33.666 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4920cb535e221ffa67374bc2fb08498e9e8e936f Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:33.666 [Cloud] End of cloud request. 2026-05-17T21:14:33.666 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x027b0320 2026-05-17T21:14:33.839 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ec6aee504b7eb02c8e9a5e25e789deb226c5661 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:33.839 [Cloud] End of cloud request. 2026-05-17T21:14:33.839 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:33.956 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe0c57da9 2026-05-17T21:14:34.756 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:34.756 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:34.756 [Cloud] Queued cloud request. 2026-05-17T21:14:34.756 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:34.756 [Cloud] Dequeued cloud request. 2026-05-17T21:14:34.756 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:34.936 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9344e8c9ae5df45178d69f5b9e342dfbc834fbc6 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:34 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:34.936 [Cloud] End of cloud request. 2026-05-17T21:14:34.936 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6bca9ba5 2026-05-17T21:14:35.001 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:35.001 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:35.001 [Cloud] Queued cloud request. 2026-05-17T21:14:35.001 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:35.001 [Cloud] Dequeued cloud request. 2026-05-17T21:14:35.001 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:35.206 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0ed48d3bb57537187624d3851cd2fa34a70d936e Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:35.206 [Cloud] End of cloud request. 2026-05-17T21:14:35.206 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9de1bcd2 2026-05-17T21:14:35.269 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:35.269 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:35.269 [Cloud] Queued cloud request. 2026-05-17T21:14:35.269 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:35.269 [Cloud] Dequeued cloud request. 2026-05-17T21:14:35.269 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:35.451 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:35.496 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aee3ff2524f840dca96093738193552c6e7c6031 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:35.496 [Cloud] End of cloud request. 2026-05-17T21:14:35.496 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf5befb43 2026-05-17T21:14:35.556 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:35.556 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:35.556 [Cloud] Queued cloud request. 2026-05-17T21:14:35.556 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:35.556 [Cloud] Dequeued cloud request. 2026-05-17T21:14:35.556 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\45a5e391e3acd890913727b4dbb975d6e8dbc0ed Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:35.846 [Cloud] End of cloud request. 2026-05-17T21:14:35.846 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe772b5d2 2026-05-17T21:14:35.905 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:35.905 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:35.905 [Cloud] Queued cloud request. 2026-05-17T21:14:35.905 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:35.905 [Cloud] Dequeued cloud request. 2026-05-17T21:14:35.905 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:35.986 Dynamic signature received 2026-05-17T21:14:36.005 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:36.138 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b15fc3decc03b218771dbcb980a581cbae36965 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:36.138 [Cloud] End of cloud request. 2026-05-17T21:14:36.138 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x28e12625 2026-05-17T21:14:36.226 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:36.226 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:36.226 [Cloud] Queued cloud request. 2026-05-17T21:14:36.226 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:36.226 [Cloud] Dequeued cloud request. 2026-05-17T21:14:36.226 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:36.475 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1692fcd8b62163cda4132db290fd9de05b62463c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:36.475 [Cloud] End of cloud request. 2026-05-17T21:14:36.475 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbd59641e 2026-05-17T21:14:36.555 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:36.555 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:36.555 [Cloud] Queued cloud request. 2026-05-17T21:14:36.555 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:36.555 [Cloud] Dequeued cloud request. 2026-05-17T21:14:36.555 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:36.666 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:36.766 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\195a8502beb59977b82871d8971d66843694cda8 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:36.766 [Cloud] End of cloud request. 2026-05-17T21:14:36.766 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xefa01ec8 2026-05-17T21:14:36.830 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:36.830 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:36.830 [Cloud] Queued cloud request. 2026-05-17T21:14:36.830 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:36.830 [Cloud] Dequeued cloud request. 2026-05-17T21:14:36.830 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:37.020 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5185fc71333cafeec50b9eb45d78c9fa1f13b30a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:37.020 [Cloud] End of cloud request. 2026-05-17T21:14:37.020 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9852ef00 2026-05-17T21:14:37.095 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:37.095 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:37.095 [Cloud] Queued cloud request. 2026-05-17T21:14:37.095 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:37.095 [Cloud] Dequeued cloud request. 2026-05-17T21:14:37.098 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:37.276 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:37.283 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ed9c83d9b05625fc88f3e7f7b345a85a90449f9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:37.285 [Cloud] End of cloud request. 2026-05-17T21:14:37.285 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x74cae9c7 2026-05-17T21:14:37.365 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:37.365 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:37.365 [Cloud] Queued cloud request. 2026-05-17T21:14:37.365 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:37.365 [Cloud] Dequeued cloud request. 2026-05-17T21:14:37.365 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:37.586 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e366330c187e53acc5a021d87969e7518e0f28c5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:37.586 [Cloud] End of cloud request. 2026-05-17T21:14:37.586 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x88b98e66 2026-05-17T21:14:37.658 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:37.658 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:37.658 [Cloud] Queued cloud request. 2026-05-17T21:14:37.658 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:37.658 [Cloud] Dequeued cloud request. 2026-05-17T21:14:37.658 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:37.806 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:37.856 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14a8cdfd91cbee2e811d92ff356d429b52437ea7 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:37.856 [Cloud] End of cloud request. 2026-05-17T21:14:37.856 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbc3c9a04 2026-05-17T21:14:37.956 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:37.956 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:37.956 [Cloud] Queued cloud request. 2026-05-17T21:14:37.956 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:37.960 [Cloud] Dequeued cloud request. 2026-05-17T21:14:37.960 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:38.209 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c9289b2c45cfb5c8990a9407fa934b688966a4da Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:38.209 [Cloud] End of cloud request. 2026-05-17T21:14:38.209 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa36b933 2026-05-17T21:14:38.271 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:38.271 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:38.271 [Cloud] Queued cloud request. 2026-05-17T21:14:38.271 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:38.271 [Cloud] Dequeued cloud request. 2026-05-17T21:14:38.271 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:38.376 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1aa8d90d892e5c627fd9279a2360fa5b6d1205b9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:38.496 Dynamic signature received 2026-05-17T21:14:38.496 [Cloud] End of cloud request. 2026-05-17T21:14:38.496 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8f69aa98 2026-05-17T21:14:38.556 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:38.556 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:38.556 [Cloud] Queued cloud request. 2026-05-17T21:14:38.556 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:38.556 [Cloud] Dequeued cloud request. 2026-05-17T21:14:38.556 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:38.856 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\155ae337503bb8b2887c919f239f3dd8f055abbb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:38.856 [Cloud] End of cloud request. 2026-05-17T21:14:38.865 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7b1a0fd1 2026-05-17T21:14:38.927 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:38.927 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:38.927 [Cloud] Queued cloud request. 2026-05-17T21:14:38.927 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:38.927 [Cloud] Dequeued cloud request. 2026-05-17T21:14:38.927 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:39.025 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:39.165 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3cc83a1589e17cc4e019e2c7342cae1192853064 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:39.165 [Cloud] End of cloud request. 2026-05-17T21:14:39.165 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x537410d7 2026-05-17T21:14:39.223 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:39.223 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:39.223 [Cloud] Queued cloud request. 2026-05-17T21:14:39.223 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:39.223 [Cloud] Dequeued cloud request. 2026-05-17T21:14:39.223 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:39.475 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\57eed4124d719dfe55851c60ced4e26dbe946d5a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:39.475 [Cloud] End of cloud request. 2026-05-17T21:14:39.475 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4e95ed9 2026-05-17T21:14:39.537 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:39.537 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:39.537 [Cloud] Queued cloud request. 2026-05-17T21:14:39.537 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:39.537 [Cloud] Dequeued cloud request. 2026-05-17T21:14:39.537 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:39.689 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:39.736 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7272ed020e12b0f9d534786a444934e73872210c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:39.736 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:39.736 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x39da0735 2026-05-17T21:14:39.825 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:39.825 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:39.825 [Cloud] Queued cloud request. 2026-05-17T21:14:39.825 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:39.825 [Cloud] Dequeued cloud request. 2026-05-17T21:14:39.825 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:40.036 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\873979922b9d6fb730a45a9c7e6202912e1c100c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:40.036 [Cloud] End of cloud request. 2026-05-17T21:14:40.036 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x612bd000 2026-05-17T21:14:40.086 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:40.086 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:40.086 [Cloud] Queued cloud request. 2026-05-17T21:14:40.086 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:40.086 [Cloud] Dequeued cloud request. 2026-05-17T21:14:40.086 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:40.252 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:40.266 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6f26e1ea587cc11601d7a49cb2c43e31c0c8667 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:40.266 [Cloud] End of cloud request. 2026-05-17T21:14:40.266 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd11e8782 2026-05-17T21:14:40.325 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:40.325 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:40.325 [Cloud] Queued cloud request. 2026-05-17T21:14:40.325 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:40.325 [Cloud] Dequeued cloud request. 2026-05-17T21:14:40.325 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:40.556 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\81505909cbb6b4428a417e2bc9a357ad28274752 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:40.565 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:40.565 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9c83381f 2026-05-17T21:14:40.621 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:40.621 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:40.621 [Cloud] Queued cloud request. 2026-05-17T21:14:40.621 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:40.621 [Cloud] Dequeued cloud request. 2026-05-17T21:14:40.621 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:40.785 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:40.912 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9841f4907f73e443e1bf44a848bdcf2170f94663 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:40.912 [Cloud] End of cloud request. 2026-05-17T21:14:40.912 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfdcf1acc 2026-05-17T21:14:40.965 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:40.965 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:40.965 [Cloud] Queued cloud request. 2026-05-17T21:14:40.965 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:40.965 [Cloud] Dequeued cloud request. 2026-05-17T21:14:40.965 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:41.196 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3b0d7ad5c34ca5223c0fa8ba506dc3689e7a6817 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:41.196 [Cloud] End of cloud request. 2026-05-17T21:14:41.196 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6fdef17b 2026-05-17T21:14:41.265 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:41.265 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:41.265 [Cloud] Queued cloud request. 2026-05-17T21:14:41.265 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:41.265 [Cloud] Dequeued cloud request. 2026-05-17T21:14:41.265 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:41.426 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:41.546 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79e1ea606b699373172403915d08534ae908cd71 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:41.546 [Cloud] End of cloud request. 2026-05-17T21:14:41.546 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xff3fbf50 2026-05-17T21:14:41.607 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:41.607 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:41.607 [Cloud] Queued cloud request. 2026-05-17T21:14:41.607 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:41.607 [Cloud] Dequeued cloud request. 2026-05-17T21:14:41.607 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:41.795 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5dd76d166cb13da77fd71a766a4f294dfb23e4e5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:41.795 [Cloud] End of cloud request. 2026-05-17T21:14:41.795 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x014d12ed 2026-05-17T21:14:41.866 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:41.866 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:41.866 [Cloud] Queued cloud request. 2026-05-17T21:14:41.866 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:41.866 [Cloud] Dequeued cloud request. 2026-05-17T21:14:41.866 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:42.056 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:42.065 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdc7c98d8d3d1f69b8482ede4a759c42da412510 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:42.065 [Cloud] End of cloud request. 2026-05-17T21:14:42.065 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9897b9b4 2026-05-17T21:14:42.125 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:42.125 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:42.125 [Cloud] Queued cloud request. 2026-05-17T21:14:42.125 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:42.125 [Cloud] Dequeued cloud request. 2026-05-17T21:14:42.125 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:42.405 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\596714896c9717bd375ffee7d7e4a9c7fc296b6f Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:42.405 [Cloud] End of cloud request. 2026-05-17T21:14:42.405 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x102961b5 2026-05-17T21:14:42.465 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:42.465 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:42.465 [Cloud] Queued cloud request. 2026-05-17T21:14:42.465 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:42.465 [Cloud] Dequeued cloud request. 2026-05-17T21:14:42.465 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:42.576 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:42.716 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0925e94c853ba3cb7bfa7d21240cda996d430382 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:42.716 [Cloud] End of cloud request. 2026-05-17T21:14:42.716 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xddc1693b 2026-05-17T21:14:42.785 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:42.785 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:42.785 [Cloud] Queued cloud request. 2026-05-17T21:14:42.785 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:42.785 [Cloud] Dequeued cloud request. 2026-05-17T21:14:42.785 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:43.026 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dc85cfb6b79799f4415895d5bc0c048e25a30eef Dynamic Signature Compilation Timestamp:05-17-2026 21:14:43 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:43.026 [Cloud] End of cloud request. 2026-05-17T21:14:43.026 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x162b573c 2026-05-17T21:14:43.085 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:43.085 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:43.085 [Cloud] Queued cloud request. 2026-05-17T21:14:43.085 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:43.085 [Cloud] Dequeued cloud request. 2026-05-17T21:14:43.085 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:43.225 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:43.745 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\73a10524f17963af5d336f5aafbaae49454f0a17 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:43 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:43.745 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:43.745 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ffefed1 2026-05-17T21:14:43.806 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:43.806 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:43.806 [Cloud] Queued cloud request. 2026-05-17T21:14:43.806 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:43.806 [Cloud] Dequeued cloud request. 2026-05-17T21:14:43.806 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:44.076 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\66ce980165356f11f96804458fae9194e5e35ed8 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:44.076 [Cloud] End of cloud request. 2026-05-17T21:14:44.076 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x055e921d 2026-05-17T21:14:44.136 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:44.136 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:44.136 [Cloud] Queued cloud request. 2026-05-17T21:14:44.136 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:44.141 [Cloud] Dequeued cloud request. 2026-05-17T21:14:44.141 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:44.265 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:44.326 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d5d83b14bfb5b3e22797f1a99a62c3d823946233 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:44.326 [Cloud] End of cloud request. 2026-05-17T21:14:44.326 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5b9ce51c 2026-05-17T21:14:44.395 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:44.395 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:44.395 [Cloud] Queued cloud request. 2026-05-17T21:14:44.395 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:44.395 [Cloud] Dequeued cloud request. 2026-05-17T21:14:44.395 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:44.836 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\678aeacff04a71a8f774591d075e31972c06188d Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:44.836 [Cloud] End of cloud request. 2026-05-17T21:14:44.836 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:44.845 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5d46892 2026-05-17T21:14:44.915 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:44.915 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:44.915 [Cloud] Queued cloud request. 2026-05-17T21:14:44.915 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:44.915 [Cloud] Dequeued cloud request. 2026-05-17T21:14:44.915 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:45.106 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5d6151aa5ca0d2fba9be7f7531463620fa6e3fa5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:45 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:45.106 [Cloud] End of cloud request. 2026-05-17T21:14:45.106 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3f832d0f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9725238f 2026-05-17T21:14:45.345 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe3ffc57d 2026-05-17T21:14:45.515 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:45.515 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:45.515 [Cloud] Queued cloud request. 2026-05-17T21:14:45.515 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:45.515 [Cloud] Dequeued cloud request. 2026-05-17T21:14:45.515 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:45.756 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ea7af7767baa95a31e8b10fdd611b7018fedca90 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:45 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:45.756 [Cloud] End of cloud request. 2026-05-17T21:14:45.756 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:46.285 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7f33e982 2026-05-17T21:14:46.709 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:46.709 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:46.709 [Cloud] Queued cloud request. 2026-05-17T21:14:46.709 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:46.709 [Cloud] Dequeued cloud request. 2026-05-17T21:14:46.709 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:46.945 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\438b93891dae4b8cf1dd050e4e8cdae5024b7993 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:46 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:46.945 [Cloud] End of cloud request. 2026-05-17T21:14:46.945 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4b6c659b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9942ce4 2026-05-17T21:14:47.115 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:47.115 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:47.115 [Cloud] Queued cloud request. 2026-05-17T21:14:47.115 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:47.115 [Cloud] Dequeued cloud request. 2026-05-17T21:14:47.115 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:47.435 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\25fb2d54ea7c19802f50fd9f634aa18ce85de2ea Dynamic Signature Compilation Timestamp:05-17-2026 21:14:47 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:47.435 [Cloud] End of cloud request. 2026-05-17T21:14:47.435 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:47.465 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x909672fe 2026-05-17T21:14:47.805 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:47.805 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:47.805 [Cloud] Queued cloud request. 2026-05-17T21:14:47.805 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:47.805 [Cloud] Dequeued cloud request. 2026-05-17T21:14:47.805 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:48.005 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b74f9ad5a63b2a3fa8114cdb06524219cfd1a12 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:47 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:48.015 [Cloud] End of cloud request. 2026-05-17T21:14:48.015 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfba2715c 2026-05-17T21:14:48.133 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:48.135 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:48.135 [Cloud] Queued cloud request. 2026-05-17T21:14:48.135 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:48.135 [Cloud] Dequeued cloud request. 2026-05-17T21:14:48.135 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:48.356 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a9010938da4d363f740b430be498f54ad458ff6 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:48 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:48.356 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:48.356 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0de07c78 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbaedf2a7 2026-05-17T21:14:48.466 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:48.466 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:48.466 [Cloud] Queued cloud request. 2026-05-17T21:14:48.466 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:48.466 [Cloud] Dequeued cloud request. 2026-05-17T21:14:48.466 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:48.525 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:48.689 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7357c85e7c67ad901dc7f5a442a91c3ba6406edd Dynamic Signature Compilation Timestamp:05-17-2026 21:14:48 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:48.693 [Cloud] End of cloud request. 2026-05-17T21:14:48.693 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf11c2271 2026-05-17T21:14:49.016 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:49.016 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:49.016 [Cloud] Queued cloud request. 2026-05-17T21:14:49.016 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:49.016 [Cloud] Dequeued cloud request. 2026-05-17T21:14:49.016 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:49.215 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:49.235 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f0f76d264a06a04f67226f1202d45acdfaa0ab73 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:49.245 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:49.245 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb5ad208c 2026-05-17T21:14:49.305 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:49.305 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:49.305 [Cloud] Queued cloud request. 2026-05-17T21:14:49.305 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:49.305 [Cloud] Dequeued cloud request. 2026-05-17T21:14:49.305 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:49.506 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9da814708472011535a48906efa569139aaa5d55 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:49.506 [Cloud] End of cloud request. 2026-05-17T21:14:49.506 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xda5660a5 2026-05-17T21:14:49.705 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:49.705 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:49.705 [Cloud] Queued cloud request. 2026-05-17T21:14:49.705 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:49.705 [Cloud] Dequeued cloud request. 2026-05-17T21:14:49.705 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:49.775 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bf96115a1b694c95b264a9a2af0439c94eac69fb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:49.965 Dynamic signature received 2026-05-17T21:14:49.965 [Cloud] End of cloud request. 2026-05-17T21:14:49.965 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7561b1d8 2026-05-17T21:14:50.033 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:50.033 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:50.033 [Cloud] Queued cloud request. 2026-05-17T21:14:50.033 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:50.033 [Cloud] Dequeued cloud request. 2026-05-17T21:14:50.033 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:50.275 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a3770e92eb814c4a47fd605b9fba31555d630ff1 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:50.275 [Cloud] End of cloud request. 2026-05-17T21:14:50.275 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0e62217b 2026-05-17T21:14:50.335 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:50.335 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:50.335 [Cloud] Queued cloud request. 2026-05-17T21:14:50.335 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:50.335 [Cloud] Dequeued cloud request. 2026-05-17T21:14:50.335 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:50.490 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b5ae341569e89e34a13473b54aa9416e0d076339 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:50.625 Dynamic signature received 2026-05-17T21:14:50.625 [Cloud] End of cloud request. 2026-05-17T21:14:50.625 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7309bef6 2026-05-17T21:14:50.695 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:50.695 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:50.695 [Cloud] Queued cloud request. 2026-05-17T21:14:50.695 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:50.695 [Cloud] Dequeued cloud request. 2026-05-17T21:14:50.695 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:50.915 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\817b0c69240fcf09e1022604ba969ce5154094b7 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:50.915 [Cloud] End of cloud request. 2026-05-17T21:14:50.915 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4c7e81bf 2026-05-17T21:14:51.075 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:51.075 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:51.075 [Cloud] Queued cloud request. 2026-05-17T21:14:51.075 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:51.075 [Cloud] Dequeued cloud request. 2026-05-17T21:14:51.075 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:51.140 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-17T21:14:51.397 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75dd06fb7d1a88c7f088b360e0380f83e1e6090a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:51 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:51.397 [Cloud] End of cloud request. 2026-05-17T21:14:51.397 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcf5c0135 2026-05-17T21:14:51.565 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:51.565 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:51.565 [Cloud] Queued cloud request. 2026-05-17T21:14:51.565 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:51.565 [Cloud] Dequeued cloud request. 2026-05-17T21:14:51.570 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2dc6a970d21a0900d93eef4617b0c3bace225c2a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:51 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:51.765 Dynamic signature received 2026-05-17T21:14:51.770 [Cloud] End of cloud request. 2026-05-17T21:14:51.770 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa44f966 2026-05-17T21:14:51.835 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-17T21:14:51.835 [Cloud] Start of cloud request. Passive mode: 0 2026-05-17T21:14:51.835 [Cloud] Queued cloud request. 2026-05-17T21:14:51.835 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-17T21:14:51.835 [Cloud] Dequeued cloud request. 2026-05-17T21:14:51.835 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-17T21:14:51.915 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\be8ef088743863606974206a51643cd26774d2fe Dynamic Signature Compilation Timestamp:05-17-2026 21:14:52 Persistence Type:Duration Time remaining:50065408 2026-05-17T21:14:52.045 Dynamic signature received 2026-05-17T21:14:52.045 [Cloud] End of cloud request. 2026-05-17T21:14:52.045 RTSD:RTSD recieved, rescanning impacted resources 2026-05-17T21:14:52.555 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x596921ff Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfd8de666 2026-05-17T21:20:29.129 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T21:29:47.806 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_2_1.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #48520, FileId: 0x7000000004abc, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:29:47.806 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_3_1.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #48519, FileId: 0x7000000004abb, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:29:52.210 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_6_1.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #48620, FileId: 0x8000000004abc, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:31:28.252 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_25_5.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #49095, FileId: 0x7000000004adf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:31:28.413 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_25_7.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #49102, FileId: 0x7000000004ae1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:31:33.759 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_29_c.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #49133, FileId: 0xb000000004ae1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:31:33.870 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume8\xampp\tmp\#sql23a8_29_10.MAI. Process: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, Status: 0xc0000001, State: 0, ScanRequest #49140, FileId: 0xd000000004ae1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-17T21:35:34.112 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-17T21:36:54.445 ProcessImageName: httpd.exe, Pid: 5964, TotalTime: 20274, Count: 1217, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume8\xampp\phpMyAdmin\js\vendor\codemirror\lib\codemirror.js, EstimatedImpact: 3% 2026-05-17T21:36:54.445 ProcessImageName: notepad++.exe, Pid: 5608, TotalTime: 6160, Count: 755, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager_windows.php@2026-05-17_213906, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: explorer.exe, Pid: 8628, TotalTime: 5709, Count: 248, MaxTime: 328, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: httpd.exe, Pid: 488, TotalTime: 4171, Count: 78, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume8\xampp\php\php7ts.dll, EstimatedImpact: 21% 2026-05-17T21:36:54.445 ProcessImageName: httpd.exe, Pid: 11676, TotalTime: 3483, Count: 260, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\eXtplorer\eXtplorer_2.1.15\scripts\extjs3\ext-all.js, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: xampp-control.exe, Pid: 10412, TotalTime: 1654, Count: 5, MaxTime: 1546, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 3% 2026-05-17T21:36:54.445 ProcessImageName: notepad++.exe, Pid: 8748, TotalTime: 925, Count: 52, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\GUP.exe, EstimatedImpact: 1% 2026-05-17T21:36:54.445 ProcessImageName: notepad++.exe, Pid: 8296, TotalTime: 722, Count: 103, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\backup\ch-filemanager_windows.php@2026-05-17_230840->(SCRIPT0076), EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: SDXHelper.exe, Pid: 7736, TotalTime: 493, Count: 22, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 36% 2026-05-17T21:36:54.445 ProcessImageName: mysqld.exe, Pid: 13428, TotalTime: 393, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: PhoneExperienceHost.exe, Pid: 10916, TotalTime: 270, Count: 30, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-54.pri, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: xampp-control.exe, Pid: 13712, TotalTime: 248, Count: 5, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume5\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 9% 2026-05-17T21:36:54.445 ProcessImageName: Everything.exe, Pid: 1316, TotalTime: 226, Count: 25, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1020.x64\Everything.ini.tmp, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: mysqld.exe, Pid: 11984, TotalTime: 225, Count: 52, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume8\xampp\mysql\data\mysql.pid, EstimatedImpact: 0% 2026-05-17T21:36:54.445 ProcessImageName: xampp-control.exe, Pid: 7000, TotalTime: 171, Count: 2, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume8\xampp\FileZillaFTP\FileZillaServer.exe, EstimatedImpact: 18% 2026-05-17T21:36:54.445 ProcessImageName: TabTip.exe, Pid: 5900, TotalTime: 138, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 95% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-18-2026 18:14:26 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/18/2026 18:14:26.920217700 UTC (13640 ms since boot) 2026-05-18T18:14:27.076 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-18T18:14:27.086 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-18T18:14:27.086 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-18T18:14:27.146 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260518-181427-00000003-fffffffeffffffff.bin ... 2026-05-18T18:14:27.261 [WPP] Trace session started - MpWppTracing-20260518-181427-00000003-fffffffeffffffff.bin 2026-05-18T18:14:27.266 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-18T18:14:27.266 [RbM] Rollback manager succesfully initialized. 2026-05-18T18:14:27.266 [RbM] Rollback manager EnableRollbackManager called. 2026-05-18T18:14:27.276 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-18T18:14:27.276 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-18T18:14:27.276 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-18T18:14:27.276 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-18T18:14:27.276 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-18T18:14:27.281 MdCoreSvc is supported in this platform and OS 2026-05-18T18:14:27.281 MdCoreSvc is supported in this platform and OS 2026-05-18T18:14:27.281 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-18T18:14:27.281 [PlatUpd] Starting MdCoreSvc service 2026-05-18T18:14:27.316 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-18T18:14:30.820 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-18T18:14:30.820 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-18T18:14:30.820 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-18T18:14:30.820 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-18T18:14:30.820 [PlatUpd] CSP platform update started 2026-05-18T18:14:30.820 [PlatUpd] Defender MDM CSP platform update not required 2026-05-18T18:14:30.820 [PlatUpd] WMI/PS provider platform update started 2026-05-18T18:14:30.820 [PlatUpd] WMI/PS provider platform update not required 2026-05-18T18:14:30.820 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-18T18:14:30.820 MdCoreSvc is supported in this platform and OS 2026-05-18T18:14:30.820 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-18T18:14:30.820 [PlatUpd] Starting MdCoreSvc service 2026-05-18T18:14:30.820 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-18T18:14:30.820 [TS] Troubleshooting mode is not available! 2026-05-18T18:14:30.820 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-18T18:14:30.820 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-18T18:14:30.852 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-18T18:14:30.852 [Service] Enabling AutoLoggers ... 2026-05-18T18:14:30.852 [Service] Enabling AMSI registration ... 2026-05-18T18:14:30.852 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-18T18:14:30.867 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 47328 Number of invalid entries is 0 Number of inserts issued is 1590455 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6548 Number of lookups is 108630991 Number of lookup misses is 5216288 Number of fast lookup misses is 55352118 Number of false fast lookups is 5216283 Number of invalidations is 736600 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-18T18:14:30.867 Verifying license file... 2026-05-18T18:14:30.867 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-18T18:14:30.883 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-18T18:14:30.883 Loaded module#0 MpComServer. 2026-05-18T18:14:30.883 Loaded module#1 StartupPolicies. 2026-05-18T18:14:30.883 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-18T18:14:30.883 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-18T18:14:30.883 COM server initialized successfully. 2026-05-18T18:14:30.898 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-18T18:14:30.914 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-18T18:14:30.914 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-18T18:14:30.914 [RTP] [RTP] FilterCommunicator object 0x00000282FB498CB0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-18T18:14:30.930 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-18T18:14:30.930 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-18T18:14:30.930 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-18T18:14:30.930 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-18T18:14:30.930 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-18T18:14:30.930 [RTP] [RTP] FilterCommunicator object 0x00000282FB4A1A00 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-18T18:14:30.930 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-18T18:14:30.930 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-18T18:14:30.930 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-18T18:14:30.930 [RTP] [RTP] StartCommunication 0x00000282FB498CB0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-18T18:14:30.930 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-18T18:14:30.930 [init][RTP] RTPPlugin initialization completed 2026-05-18T18:14:30.930 OS boot count = 2 2026-05-18T18:14:30.930 OS Install = 0 2026-05-18T18:14:30.930 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-18T18:14:30.945 [KSL] Entering CKSLEngine::Initialize. 2026-05-18T18:14:30.945 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-18T18:14:30.945 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-18T18:14:30.945 [KSL] MpInstallKslD: hr=0x1 2026-05-18T18:14:30.945 [KSL] MpRegisterKslD: hr=0 2026-05-18T18:14:30.945 [KSL] MpStartKslD: hr=0 2026-05-18T18:14:30.945 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-18T18:14:30.945 Loading engine... 2026-05-18T18:14:30.961 Verifying engine and signature files (source: 1) ... 2026-05-18T18:14:30.961 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpengine.dll] due to PPL. 2026-05-18T18:14:30.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasbase.vdm] (file in cache) 2026-05-18T18:14:30.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasdlta.vdm] (file in cache) 2026-05-18T18:14:30.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavbase.vdm] (file in cache) 2026-05-18T18:14:30.961 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpavdlta.vdm] (file in cache) 2026-05-18T18:14:30.992 [Engine] IsHybridMode: 0 2026-05-18T18:14:30.992 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-18T18:14:31.023 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3632A685AD55BA50C045FDC119E112A882B1F1BB.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-18T18:14:35.180 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-18T18:14:35.180 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-18T18:14:35.180 [Engine] New active engine 00007FFF94345810 (no old engine). Number of active engines: 1 2026-05-18T18:14:35.195 EngineInit:Global ASOC is enabled 2026-05-18T18:14:35.195 EngineInit:ASOO is enabled for developer volumes 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.289 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:14:35.352 MpWriteUupSignatureVersion 1.449.666.0, hr = 0 2026-05-18T18:14:35.352 [SigStatUpd] CSignatureStatus: back to good 2026-05-18T18:14:35.352 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-18T18:14:35.367 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-18T18:14:35.367 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-18T18:14:35.367 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-18T18:14:35.367 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-18T18:14:35.367 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-18T18:14:35.383 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-18T18:14:35.383 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2196 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12540 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2466 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-18T18:14:35.383 [Plugin] Initializing RTP plugin state... 2026-05-18T18:14:35.383 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-18T18:14:35.383 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E} 2026-05-18T18:14:35.398 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:14:35.398 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:14:35.398 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:14:35.398 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-18T18:14:35.398 MdCoreSvc is supported in this platform and OS 2026-05-18T18:14:35.398 Engine loaded! 2026-05-18T18:14:35.398 [DLP] Create FeatureControlState instance 2026-05-18T18:14:35.398 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-18T18:14:35.398 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-18T18:14:35.398 RegisterSModeChangeListener: hr = 0x1 2026-05-18T18:14:35.398 RegisterHybridModeChangeListener: hr = 0 2026-05-18T18:14:35.414 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-18T18:14:35.414 [SigReleaseHb] Initialized with Stage 0 2026-05-18T18:14:35.414 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-18T18:14:35.414 [SCC][CID=22140_5600] Initializing ... 2026-05-18T18:14:35.414 [SCC][CID=22140_5600] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-18T18:14:35.414 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-18T18:14:35.414 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-18T18:14:35.430 [NRI] Stopping NIS service ... 2026-05-18T18:14:35.430 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-18T18:14:35.430 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-18T18:14:35.430 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.666.0 AV Signature Version: 1.449.666.0 ************************************************************ 2026-05-18T18:14:35.430 Resource usage Monitoring is enabled 2026-05-18T18:14:35.430 Job Notification: New process added to job (4612) 2026-05-18T18:14:35.430 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-18T18:14:35.430 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7576] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7588]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-18T18:14:35.508 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-18T18:14:35.523 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-18T18:14:35.523 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-18T18:14:35.539 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-18T18:14:35.539 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-18T18:14:35.539 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-18T18:14:35.539 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-18T18:14:35.539 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-18T18:14:35.539 [RTP] Generating the base plugin configuration ... 2026-05-18T18:14:35.539 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-18T18:14:35.539 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:14:35.539 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-18T18:14:35.539 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-18T18:14:35.539 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:14:35.539 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-18T18:14:35.539 [RTP] [RTP] StartCommunication 0x00000282FB4A1A00 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-18T18:14:35.539 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-18T18:14:35.539 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\msasn1.dll 2026-05-18T18:14:35.852 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-18T18:14:35.852 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-18T18:14:35.852 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-18T18:14:35.898 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:36.227 [AutoPurge] Verification Routine tasks have started. 2026-05-18T18:14:36.227 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-18T18:14:36.430 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-18T18:14:36.430 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-18T18:14:36.461 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-18T18:14:36.773 Job Notification: New process added to job (7868) 2026-05-18T18:14:36.773 Task(GetDeviceTicket -AccessKey 8D22F093-00D1-7102-8AC6-49C62A6838DC ) launched as network service 2026-05-18T18:14:37.227 Job Notification: Process exited from job (7868) 2026-05-18T18:14:37.430 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-18T18:14:37.430 [Cloud] Start of cloud request. Passive mode: 0 2026-05-18T18:14:37.430 [Cloud] Queued cloud request. 2026-05-18T18:14:37.430 [Cloud] Dequeued cloud request. 2026-05-18T18:14:37.445 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-18T18:14:37.445 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-18T18:14:37.445 [AutoPurge] Verification Routine tasks have ended. 2026-05-18T18:14:37.617 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-18T18:14:37.617 [Cloud] End of cloud request. 2026-05-18T18:14:37.742 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-18T18:14:37.758 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:37.758 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-18T18:14:37.758 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-18T18:14:37.758 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-18T18:14:37.758 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-18T18:14:37.758 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-18T18:14:37.758 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-18T18:14:37.758 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-18T18:14:37.758 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:37.773 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:37.773 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:14:38.477 [RTP] Duplicating the current plugin configuration object... 2026-05-18T18:14:38.477 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-18T18:14:38.477 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-05-18T18:14:38.477 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:14:38.477 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-18T18:14:38.477 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-05-18T18:14:49.055 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\845B4905-8C46-433A-ABCD-490B3BBC992E1fe4.1dce6f23582a97b 2026-05-18T18:14:49.164 Verifying engine and signature files (source: 0) ... 2026-05-18T18:14:49.164 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpengine.dll] due to PPL. 2026-05-18T18:14:49.164 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasbase.vdm]. File not in cache (0x1) 2026-05-18T18:14:49.898 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasbase.vdm] 2026-05-18T18:14:49.914 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-18T18:14:49.930 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasdlta.vdm] 2026-05-18T18:14:49.930 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavbase.vdm]. File not in cache (0x1) 2026-05-18T18:14:50.273 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavbase.vdm] 2026-05-18T18:14:50.273 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-18T18:14:50.289 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavdlta.vdm] 2026-05-18T18:14:50.445 [Engine] IsHybridMode: 0 2026-05-18T18:14:50.445 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-18T18:14:50.461 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D1C259F30EABAAB233A00C0760FDD47A65BAA1B1.bin): 0x00000002 2026-05-18T18:14:50.461 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D1C259F30EABAAB233A00C0760FDD47A65BAA1B1.bin) 2026-05-18T18:14:50.461 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-18T18:14:50.461 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-18T18:14:50.461 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-18T18:14:50.461 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-18T18:15:00.211 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-18T18:15:00.211 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. 2026-05-18T18:15:00.227 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFF94345810, lRefCount: 6, hr=0 2026-05-18T18:15:00.227 [Engine] New active engine 00007FFF8F3D5810 replacing engine 00007FFF94345810. Number of active engines: 2 2026-05-18T18:15:00.227 EngineInit:Global ASOC is enabled 2026-05-18T18:15:00.227 EngineInit:ASOO is enabled for developer volumes 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.289 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-18T18:15:00.305 MpWriteUupSignatureVersion 1.449.681.0, hr = 0 2026-05-18T18:15:00.305 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-18T18:15:00.320 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-18T18:15:00.320 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-18T18:15:00.320 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-18T18:15:00.320 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-18T18:15:00.320 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-18T18:15:00.336 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-18T18:15:00.336 [Plugin] Initializing RTP plugin state... 2026-05-18T18:15:00.336 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-18T18:15:00.336 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎18‎-‎2026 20:14:35 Last Perf:‎05‎-‎18‎-‎2026 20:14:35 First RTP Scan:‎05‎-‎18‎-‎2026 20:14:35 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:489 Misses:1131 BM Queue:0,11,0 Proc:0,11,0 File:0,3,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:1631 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:1509282 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2609 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14361 TotalHits:1241 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:14 InstanceCacheHits:0 InstanceCacheMisses:2905 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (27/8) Success: 8, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-18T18:15:00.336 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963} 2026-05-18T18:15:00.336 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E}\mpasbase.vdm in use, hr=0x80070020 2026-05-18T18:15:00.336 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-18T18:15:00.336 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{76E6702D-F960-42E2-A724-5497A69C8171} removed 2026-05-18T18:15:00.336 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-18-2026 18:15:00 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-18-2026 18:15:00 2026-05-18T18:15:00.352 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-18T18:15:00.352 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-18T18:15:00.352 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:15:00.352 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-18T18:15:00.352 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-18T18:15:00.352 MdCoreSvc is supported in this platform and OS Signature updated on 05-18-2026 18:15:00 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.681.0 AV Signature Version: 1.449.681.0 ************************************************************ 2026-05-18T18:15:00.352 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-18T18:15:00.352 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\845B4905-8C46-433A-ABCD-490B3BBC992E1fe4.1dce6f23582a97b 2026-05-18T18:15:00.430 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-18T18:15:00.430 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-18T18:15:00.727 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-18T18:15:00.727 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-18T18:15:00.727 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-18T18:15:00.727 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-18T18:15:00.727 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-18T18:15:00.742 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:15:00.742 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-18T18:15:00.805 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-18T18:15:00.805 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-18T18:15:00.805 [KSL] Leaving CKSLEngine::EnableKsl(0). Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-05-18T18:15:30.877 Process scan (postsignatureupdatescan) started. 2026-05-18T18:15:37.088 [Engine] Engine 00007FFF94345810 no longer in use. Number of active engines: 1 2026-05-18T18:15:37.342 ProcessImageName: taskhostw.exe, Pid: 7352, TotalTime: 936, Count: 2, MaxTime: 890, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 11% 2026-05-18T18:15:37.342 ProcessImageName: WmiPrvSE.exe, Pid: 3900, TotalTime: 390, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\basicrender.inf, EstimatedImpact: 18% 2026-05-18T18:15:37.342 ProcessImageName: brynhildr.exe, Pid: 4168, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-18T18:15:37.389 [Engine] RSIG_UNLOADENGINE, 00007FFF94345810, err=0x0 2026-05-18T18:15:37.406 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{419AADC2-8C67-4B71-A459-AEB9F62E4F3E} removed 2026-05-18T18:15:59.897 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4155, FileId: 0xda00000000e275, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:16:14.721 Process scan (postsignatureupdatescan) completed. 2026-05-18T18:16:29.502 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:16:29.502 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-18T18:16:29.515 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:16:41.877 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-05-18T18:16:41.877 [RTP] Duplicating the current plugin configuration object... 2026-05-18T18:16:41.877 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-18T18:16:41.877 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-18T18:16:41.877 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-18T18:16:41.877 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-18T18:16:41.877 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-05-18T18:16:42.486 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-05-18T18:16:42.690 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-05-18T18:16:43.096 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-05-18T18:17:33.134 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #5916, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-05-18T18:17:37.893 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-18T18:17:37.893 [Cloud] Start of cloud request. Passive mode: 0 2026-05-18T18:17:37.893 [Cloud] Queued cloud request. 2026-05-18T18:17:37.893 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-18T18:17:37.893 [Cloud] Dequeued cloud request. 2026-05-18T18:17:37.893 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7af41c3371bc9e99c425770ea2bb2833a8183555 Dynamic Signature Compilation Timestamp:05-18-2026 18:17:39 Persistence Type:Duration Time remaining:288000000 2026-05-18T18:17:38.533 [Cloud] End of cloud request. 2026-05-18T18:17:38.533 RTSD:RTSD recieved, rescanning impacted resources 2026-05-18T18:17:39.033 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-18T18:17:40.033 Dynamic signature received 2026-05-18T18:19:35.430 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-18T18:20:00.286 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-18T18:20:30.477 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #6322, FileId: 0x4400000000f702, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.349 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6607, FileId: 0x217000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.412 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6610, FileId: 0x21b000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.412 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6611, FileId: 0x7700000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.427 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6612, FileId: 0x21c000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.443 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6615, FileId: 0x7a00000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.443 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6617, FileId: 0x220000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.458 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6618, FileId: 0x7c00000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.458 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6619, FileId: 0x221000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.458 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6620, FileId: 0x8000000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.458 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6621, FileId: 0x225000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.474 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6614, FileId: 0x21d000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.474 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6623, FileId: 0x226000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.490 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6616, FileId: 0x7b00000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.677 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\04930a0b-1688-4cbe-810c-b74e276ca87e. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6638, FileId: 0xa900000000b2fc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:11.693 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6640, FileId: 0x11500000000fbab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.225 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6675, FileId: 0x6300000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.225 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6676, FileId: 0x22b000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.225 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6677, FileId: 0x6800000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.225 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6678, FileId: 0x6900000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.225 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6672, FileId: 0x6200000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.241 Bm signature throttled:0x000045b3435c1067 2026-05-18T18:21:12.241 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6673, FileId: 0x22a000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.241 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6680, FileId: 0x231000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.241 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6682, FileId: 0x233000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.241 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6683, FileId: 0x6c00000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.256 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6684, FileId: 0x234000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.256 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6679, FileId: 0x6a00000000fa80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.256 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6681, FileId: 0x232000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.663 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6725, FileId: 0xfb00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.678 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #6726, FileId: 0x238000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:12.678 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\117eaabc-5324-4073-b77e-d59d1d6aa5f2. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #6724, FileId: 0x4d000000032f23, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:14.907 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD8C0B198F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6792, FileId: 0x5100000000ac9a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:14.907 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD7F35B9E5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6794, FileId: 0x3c00000000fbb7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:14.922 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj90D2999FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6795, FileId: 0x5300000000ac9a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:14.954 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB049F295A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6798, FileId: 0x3d00000000fbb7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:14.969 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8266C9980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6800, FileId: 0x1d200000000fbd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.190 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj789D93965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6817, FileId: 0x1d300000000fbd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.220 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8644D2926. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6827, FileId: 0x1d500000000fbd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.470 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD4A4A797E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6850, FileId: 0x1d600000000fbd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.502 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF45DF9923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6851, FileId: 0x5800000000fbd3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.705 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj276002902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6864, FileId: 0x4e00000000f119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:15.845 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD9C9C798A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6869, FileId: 0x4600000000fa7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.367 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1395B913. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6893, FileId: 0x5300000000fbf1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.386 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2A57959B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6894, FileId: 0x5400000000fbf1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.453 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj037B169D5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6896, FileId: 0x1d300000000db24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.470 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj611F7F99E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6897, FileId: 0xb500000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.742 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E7D509FE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6910, FileId: 0x4600000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.758 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70784A94B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6911, FileId: 0xb700000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.809 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C0B919C5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6914, FileId: 0xb800000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.847 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB06A9D933. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6920, FileId: 0xba00000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.849 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB0F738900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6919, FileId: 0xb900000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.872 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj52C42B9F7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6921, FileId: 0xbb00000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.919 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1AA19B9E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6923, FileId: 0xbc00000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.942 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9DEB3D930. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6924, FileId: 0xbd00000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:16.958 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj229AAF908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6925, FileId: 0xbe00000000fbec, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.005 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj90F582925. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6928, FileId: 0x4700000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.661 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj98B01D91D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6983, FileId: 0x5000000000fbdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.664 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj64EEC9918. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6988, FileId: 0x5100000000fbdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.703 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj84618D9BF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6997, FileId: 0x5200000000fbdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.750 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6DE498980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7004, FileId: 0x4b00000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.860 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6FFA13912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7020, FileId: 0x4000000000fc26, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:17.877 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj33115B940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7027, FileId: 0x4d00000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.018 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj71A8589FE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7049, FileId: 0x3700000000fc29, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.049 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE00E3B9DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7055, FileId: 0x4f00000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.096 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBABDC99C2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7060, FileId: 0x5000000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.096 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBDC8DA902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7062, FileId: 0x5100000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.158 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0F13959AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7064, FileId: 0x5200000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.190 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj50542C9E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7072, FileId: 0x5300000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.205 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3DCA0A965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7075, FileId: 0x5400000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.252 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0B28B29FA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7082, FileId: 0x5500000000fc0a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.315 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj88F8A3915. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7090, FileId: 0x15200000000fc3a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.551 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj84356F9CE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7112, FileId: 0x8f00000000fc9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.567 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB426419ED. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7120, FileId: 0x15400000000fc3a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.738 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0AA44495A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7159, FileId: 0x3700000000fc48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.754 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF77444960. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7162, FileId: 0x15600000000fc3a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.832 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj35A51F923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7177, FileId: 0x15700000000fc3a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.942 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj257F43993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7189, FileId: 0xb200000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:18.988 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj954B6E948. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7193, FileId: 0xb400000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.004 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC60E0E9C5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7194, FileId: 0xb500000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.020 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC4428B971. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7195, FileId: 0xb600000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.035 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj80C0699C3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7198, FileId: 0xb700000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.066 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1C19A79E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7199, FileId: 0xb800000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.098 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE598AD993. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7201, FileId: 0xb900000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.113 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3D64FF978. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7203, FileId: 0xba00000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.113 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE88D04973. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7204, FileId: 0xbb00000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.207 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj28EA0F9D5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7206, FileId: 0x3a00000000fc48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.223 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF696579FD. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7207, FileId: 0x3b00000000fc48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.345 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD10DE79DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7218, FileId: 0xc000000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.362 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8B9CDF9A9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7219, FileId: 0xc100000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.379 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA96FC292C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7222, FileId: 0xc200000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.394 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9ED3E8904. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7223, FileId: 0xc300000000fc35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.434 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8CABEA95A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7226, FileId: 0x3d00000000fc48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.452 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD7B9E090C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7227, FileId: 0x9100000000fc9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.477 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj51EEA69C1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7228, FileId: 0x9200000000fc9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:19.494 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8706A99FB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7229, FileId: 0x9300000000fc9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:29.363 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7530, FileId: 0xfc00000000fba6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:21:29.441 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7534, FileId: 0x24800000000faab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:22:29.692 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7714, FileId: 0x12b00000000fbab, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-18T18:24:35.427 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-18T18:24:35.427 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-18T18:24:35.442 Job Notification: New process added to job (11348) 2026-05-18T18:24:35.442 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-18T18:24:35.442 Aggressive catchup quick scan threshold: 1055758350734 / 25920000000000 2026-05-18T18:24:35.458 Job Notification: New process added to job (1796) 2026-05-18T18:24:35.458 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:11348] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:1796]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-18T18:24:35.505 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 30430553(ms) from now at 04:51 (02:51 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-18T18:24:35.551 Job Notification: New process added to job (7492) 2026-05-18T18:24:35.551 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-18T18:24:35.551 Job Notification: New process added to job (7460) 2026-05-18T18:24:35.567 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7492] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7460]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-18T18:24:35.942 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-18T18:24:35.942 [RTP] Duplicating the current plugin configuration object... 2026-05-18T18:24:35.942 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-18T18:24:35.942 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-18T18:24:35.942 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-18T18:24:35.942 [RTP] No config change detected. Not updating plugin configuration. 2026-05-18T18:24:35.942 [RTP] No config changes found. No configuration switch. 2026-05-18T18:24:35.942 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-18T18:24:40.942 Job Notification: Process exited from job (7492) 2026-05-18T18:24:40.942 Job Notification: Process exited from job (7460) 2026-05-18T18:24:41.020 Job Notification: Process exited from job (11348) 2026-05-18T18:24:41.020 Job Notification: Process exited from job (1796) 2026-05-18T18:27:59.011 [AutoPurge] Cleanup Routine tasks have started. 2026-05-18T18:27:59.026 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-18T18:27:59.026 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-18T18:27:59.026 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-18-2026 18:27:59 2026-05-18T18:27:59.042 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-18T18:27:59.042 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-18T18:27:59.042 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-18T18:27:59.042 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-18T18:27:59.042 [AutoPurge] MpSignalMaintenanceMode ... Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-18-2026 18:27:59 2026-05-18T18:27:59.058 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-18T18:27:59.058 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-18T18:27:59.058 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-18T18:27:59.058 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-18T18:27:59.058 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-18T18:27:59.058 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:60AB5514-38C5-4181-9095-3429283C21FE, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-18T18:27:59.058 Scheduled scan with Id 60AB5514-38C5-4181-9095-3429283C21FE configured CPU priority: normal (LowCpuPriority: 0) 2026-05-18T18:27:59.058 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-18T18:27:59.058 [SFC] System file cache build is not needed (already completed) 2026-05-18T18:27:59.058 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-18T18:27:59.120 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-05-18T18:27:59.480 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-18T18:27:59.605 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:00.422 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-18T18:28:00.940 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-18T18:28:01.033 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-18T18:28:01.065 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-18T18:28:01.065 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:28:01.080 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-18T18:28:01.080 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:28:01.080 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1426.11910.dll", hr=0x800710da 2026-05-18T18:28:01.549 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-18T18:28:01.627 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-18T18:28:01.783 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-18T18:28:01.799 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-18T18:28:02.158 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-18T18:28:02.205 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-18T18:28:02.268 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-18T18:28:02.408 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:02.596 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-18T18:28:02.752 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-18T18:28:02.908 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-18T18:28:02.924 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:02.955 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-18T18:28:03.049 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-18T18:28:03.111 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-18T18:28:03.502 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-18T18:28:03.768 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-18T18:28:03.799 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:04.158 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-18T18:28:04.346 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-18T18:28:04.908 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:04.924 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-18T18:28:04.986 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:05.236 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-18T18:28:05.346 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-18T18:28:05.549 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-18T18:28:05.768 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-18T18:28:06.127 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-18T18:28:06.143 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-18T18:28:06.174 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-18T18:28:06.408 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-18T18:28:06.486 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-18T18:28:06.611 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-18T18:28:06.736 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-18T18:28:07.236 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-18T18:28:07.252 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-18T18:28:07.533 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-18T18:28:07.596 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-18T18:28:08.018 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.gamingapp_2605.1001.12.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-05-18T18:28:08.158 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-18T18:28:08.190 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-18T18:28:08.190 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:08.205 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-18T18:28:08.283 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-18T18:28:08.377 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-18T18:28:08.486 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-18T18:28:08.736 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ko.dll", hr=0x800710da 2026-05-18T18:28:08.830 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-18T18:28:09.033 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-18T18:28:09.065 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:09.080 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-18T18:28:09.127 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-18T18:28:09.268 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-18T18:28:09.330 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-18T18:28:09.361 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-18T18:28:09.440 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-18T18:28:09.690 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-05-18T18:28:09.861 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-18T18:28:09.861 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-18T18:28:10.065 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:10.111 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-18T18:28:10.158 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-18T18:28:10.893 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-18T18:28:11.205 Engine:Setting original file name "mini_installer.exe" for "c:\program files (x86)\microsoft\edgeupdate\download\{56eb18f8-b008-4cbd-b6d2-8c97fe7e9062}\148.0.3967.70\microsoftedge_x64_148.0.3967.70_148.0.3967.54.exe", hr=0x800710da 2026-05-18T18:28:11.252 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:11.268 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-05-18T18:28:11.315 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-18T18:28:11.580 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-18T18:28:11.596 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-18T18:28:11.908 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-18T18:28:11.986 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-18T18:28:12.002 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-18T18:28:12.111 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-18T18:28:12.111 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-18T18:28:12.143 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-18T18:28:12.533 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-18T18:28:12.580 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-18T18:28:12.690 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-18T18:28:12.736 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-18T18:28:12.893 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-18T18:28:13.033 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-18T18:28:13.080 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-18T18:28:13.127 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-18T18:28:13.268 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-18T18:28:13.533 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:13.815 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-18T18:28:13.846 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-18T18:28:13.861 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:13.924 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:14.346 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:14.424 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:15.475 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-18T18:28:15.522 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-18T18:28:15.663 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-18T18:28:15.741 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-18T18:28:15.788 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:15.803 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-18T18:28:16.163 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-18T18:28:16.241 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-18T18:28:16.319 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-18T18:28:16.397 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-18T18:28:16.428 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-18T18:28:16.522 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-18T18:28:16.663 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-18T18:28:16.772 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-18T18:28:16.850 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-18T18:28:16.866 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-18T18:28:16.881 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-18T18:28:17.100 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-18T18:28:17.100 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-18T18:28:17.272 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-18T18:28:17.772 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-18T18:28:18.026 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-18T18:28:18.073 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-05-18T18:28:18.480 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-18T18:28:18.542 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-18T18:28:18.620 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-18T18:28:18.683 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-18T18:28:18.792 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-18T18:28:18.808 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-18T18:28:18.948 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-18T18:28:19.167 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-05-18T18:28:19.183 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-18T18:28:19.386 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-18T18:28:19.495 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-18T18:28:19.823 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-18T18:28:19.917 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-18T18:28:20.042 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-18T18:28:20.401 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-18T18:28:20.495 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-18T18:28:20.542 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-18T18:28:20.683 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-18T18:28:20.683 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-18T18:28:20.808 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-18T18:28:20.870 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-18T18:28:21.026 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-18T18:28:21.136 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-18T18:28:21.136 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:21.401 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-18T18:28:21.683 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-18T18:28:21.714 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-18T18:28:21.808 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-18T18:28:21.917 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-18T18:28:22.730 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-18T18:28:22.839 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:22.855 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-18T18:28:22.995 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:23.542 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-18T18:28:23.651 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-18T18:28:23.683 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_lt.dll", hr=0x800710da 2026-05-18T18:28:23.776 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-18T18:28:24.167 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-18T18:28:24.198 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-18T18:28:24.214 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-18T18:28:24.495 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-18T18:28:24.745 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-18T18:28:24.792 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-18T18:28:24.917 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-18T18:28:25.073 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-18T18:28:25.073 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-18T18:28:25.292 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-18T18:28:25.464 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-18T18:28:25.495 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-18T18:28:25.573 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-18T18:28:25.995 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-18T18:28:26.073 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-18T18:28:26.073 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-18T18:28:26.151 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-18T18:28:26.495 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x800710da 2026-05-18T18:28:26.651 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-18T18:28:26.745 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_ro.dll", hr=0x800710da 2026-05-18T18:28:26.808 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-18T18:28:26.870 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-18T18:28:26.901 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-18T18:28:27.058 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-18T18:28:27.151 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-18T18:28:27.198 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-18T18:28:27.308 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:27.433 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-18T18:28:27.589 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-18T18:28:27.667 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_fi.dll", hr=0x800710da 2026-05-18T18:28:27.698 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-18T18:28:27.776 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-18T18:28:28.042 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-18T18:28:28.058 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-18T18:28:28.136 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-18T18:28:28.855 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-18T18:28:29.276 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-18T18:28:29.308 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-18T18:28:29.386 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-18T18:28:29.417 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-18T18:28:29.980 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-18T18:28:30.433 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-18T18:28:30.495 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-18T18:28:30.683 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-18T18:28:30.917 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-18T18:28:30.948 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-18T18:28:31.245 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-18T18:28:31.308 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-18T18:28:31.370 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-18T18:28:31.417 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-18T18:28:31.542 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-18T18:28:32.183 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-18T18:28:32.480 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-18T18:28:32.526 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-18T18:28:32.558 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-18T18:28:33.136 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-18T18:28:33.401 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-18T18:28:33.542 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-18T18:28:33.761 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:33.870 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:34.105 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-18T18:28:34.105 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:34.151 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-18T18:28:34.261 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-18T18:28:34.308 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-18T18:28:34.386 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-18T18:28:34.480 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-18T18:28:34.511 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-18T18:28:34.511 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-18T18:28:34.558 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-18T18:28:34.558 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-18T18:28:34.808 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-18T18:28:34.808 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-18T18:28:34.855 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-18T18:28:34.980 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-18T18:28:35.089 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-18T18:28:35.281 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-18T18:28:35.296 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_tr.dll", hr=0x800710da 2026-05-18T18:28:35.546 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-18T18:28:35.796 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-18T18:28:35.968 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-18T18:28:36.250 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-05-18T18:28:36.265 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2605.1001.12.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-05-18T18:28:36.515 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-18T18:28:36.578 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-18T18:28:36.687 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-18T18:28:36.796 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-18T18:28:37.156 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-18T18:28:37.234 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-18T18:28:37.296 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-18T18:28:37.312 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-18T18:28:37.312 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-18T18:28:37.375 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:37.703 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-18T18:28:37.703 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-18T18:28:38.066 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_it.dll", hr=0x800710da 2026-05-18T18:28:38.301 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-18T18:28:38.395 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-18T18:28:38.457 Engine:Setting original file name "FileSync.LocalizedResources.dll.mui" for "c:\program files\microsoft onedrive\26.074.0420.0001\filesync.localizedresources.dll", hr=0x800710da 2026-05-18T18:28:39.004 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-18T18:28:39.035 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-05-18T18:28:39.582 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-18T18:28:39.645 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-18T18:28:39.707 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-18T18:28:40.004 Engine:Setting original file name ".NET Host Resolver - 8.0.26" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2605.41181.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-18T18:28:40.066 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-18T18:28:40.176 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-18T18:28:40.535 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-18T18:28:40.910 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-18T18:28:40.957 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-18T18:28:41.191 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-18T18:28:41.410 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_da.dll", hr=0x800710da 2026-05-18T18:28:41.535 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-18T18:28:41.645 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-18T18:28:41.691 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-05-18T18:28:41.941 Engine:Setting original file name "WebInstaller.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrocef\singleclientservicesupdater.exe", hr=0x800710da 2026-05-18T18:28:41.973 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-18T18:28:42.363 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:42.379 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-18T18:28:42.473 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-05-18T18:28:42.582 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-18T18:28:42.816 Engine:Setting original file name "Microsoft.Management.Deployment.OutOfProc.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\microsoft.management.deployment.dll", hr=0x800710da 2026-05-18T18:28:42.848 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-18T18:28:42.895 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-18T18:28:43.738 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-18T18:28:43.973 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-18T18:28:44.082 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:44.207 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-18T18:28:44.629 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-18T18:28:44.738 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-18T18:28:44.785 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-18T18:28:44.816 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-18T18:28:44.895 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-18T18:28:44.910 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:45.020 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-18T18:28:45.066 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-18T18:28:45.191 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-18T18:28:45.238 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-18T18:28:45.321 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:45.415 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-18T18:28:45.727 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-18T18:28:45.805 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-18T18:28:45.993 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-18T18:28:46.305 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-18T18:28:46.415 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-18T18:28:46.790 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-18T18:28:46.868 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:47.180 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-18T18:28:47.587 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-18T18:28:47.915 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-05-18T18:28:47.993 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-18T18:28:48.040 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-05-18T18:28:48.321 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-05-18T18:28:48.462 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-18T18:28:48.571 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-18T18:28:49.196 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-18T18:28:49.493 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-18T18:28:49.508 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-18T18:28:49.587 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:49.587 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-18T18:28:49.602 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-18T18:28:50.087 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-18T18:28:50.133 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-18T18:28:50.212 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-18T18:28:50.497 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-18T18:28:50.528 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-05-18T18:28:50.747 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-18T18:28:50.778 Engine:Setting original file name "TeamViewer_Resource.dll" for "c:\program files\teamviewer\teamviewer_resource_vi.dll", hr=0x800710da 2026-05-18T18:28:50.810 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files (x86)\microsoft\edgewebview\application\148.0.3967.70\dxil.dll", hr=0x800710da 2026-05-18T18:28:50.841 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-18T18:28:50.903 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-18T18:28:50.903 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-18T18:28:51.028 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-18T18:28:51.528 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-18T18:28:51.763 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-18T18:28:51.763 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-18T18:28:51.810 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-18T18:28:52.013 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:52.107 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-18T18:28:52.247 Engine:Setting original file name "Microsoft Cognitive Services Speech SDK" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2605.41181.0_x64__8wekyb3d8bbwe\microsoft.cognitiveservices.speech.extension.lu.dll", hr=0x800710da 2026-05-18T18:28:52.403 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-18T18:28:52.403 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-18T18:28:52.419 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-18T18:28:52.638 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-18T18:28:52.903 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-18T18:28:52.997 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-05-18T18:28:53.216 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-18T18:28:53.341 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-18T18:28:53.435 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-18T18:28:53.466 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-05-18T18:28:53.513 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-18T18:28:54.580 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-18T18:28:54.705 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-18T18:28:54.752 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-18T18:28:54.971 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-05-18T18:28:55.018 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-18T18:28:55.143 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-18T18:28:55.205 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-18T18:28:55.377 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-18T18:28:55.393 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-05-18T18:28:55.424 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-18T18:28:55.580 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-18T18:28:55.611 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-18T18:28:55.690 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-18T18:28:55.736 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-18T18:28:55.736 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-18T18:28:56.033 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-05-18T18:28:56.158 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-18T18:28:56.221 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-18T18:28:56.252 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-05-18T18:28:56.580 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-05-18T18:28:56.674 Engine:Triggered AR EMS scan 2026-05-18T18:28:56.674 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.705 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-05-18T18:28:56.736 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.736 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-05-18T18:28:56.752 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-05-18T18:28:56.768 Engine:EMS scan for process: svchost pid: 560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.768 Engine:EMS scan for process: svchost pid: 1036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.768 Engine:EMS scan for process: svchost pid: 1192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.799 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.815 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.815 Engine:EMS scan for process: svchost pid: 1344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.815 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.830 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.830 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.846 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.846 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.846 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.846 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.861 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.861 Engine:EMS scan for process: svchost pid: 1680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.877 Engine:EMS scan for process: svchost pid: 1832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.877 Engine:EMS scan for process: svchost pid: 2004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.877 Engine:EMS scan for process: svchost pid: 1784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.893 Engine:EMS scan for process: svchost pid: 2104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.893 Engine:EMS scan for process: svchost pid: 2156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.893 Engine:EMS scan for process: svchost pid: 2336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.908 Engine:EMS scan for process: svchost pid: 2680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.924 Engine:EMS scan for process: svchost pid: 2732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.924 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.924 Engine:EMS scan for process: svchost pid: 2984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.940 Engine:EMS scan for process: svchost pid: 2304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.940 Engine:EMS scan for process: svchost pid: 2584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.955 Engine:EMS scan for process: svchost pid: 3104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.955 Engine:EMS scan for process: svchost pid: 3552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.955 Engine:EMS scan for process: svchost pid: 3560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.971 Engine:EMS scan for process: svchost pid: 3660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.971 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:56.986 Engine:EMS scan for process: svchost pid: 3748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.002 Engine:EMS scan for process: svchost pid: 3808, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.002 Engine:EMS scan for process: svchost pid: 3744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.018 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.018 Engine:EMS scan for process: svchost pid: 4180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.018 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.033 Engine:EMS scan for process: svchost pid: 4232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.033 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.049 Engine:EMS scan for process: svchost pid: 4476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.049 Engine:EMS scan for process: svchost pid: 4540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.049 Engine:EMS scan for process: svchost pid: 4636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-05-18T18:28:57.065 Engine:EMS scan for process: svchost pid: 5196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.065 Engine:EMS scan for process: svchost pid: 6068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.065 Engine:EMS scan for process: dllhost pid: 6104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.065 Engine:EMS scan for process: svchost pid: 6184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.080 Engine:EMS scan for process: svchost pid: 6944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.080 Engine:EMS scan for process: svchost pid: 6952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.080 Engine:EMS scan for process: svchost pid: 7052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.096 Engine:EMS scan for process: svchost pid: 3308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.096 Engine:EMS scan for process: svchost pid: 8164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.096 Engine:EMS scan for process: svchost pid: 1236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.096 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.111 Engine:EMS scan for process: svchost pid: 2100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.127 Engine:EMS scan for process: svchost pid: 2992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.127 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.127 Engine:EMS scan for process: explorer pid: 8276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.174 Engine:EMS scan for process: svchost pid: 8432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.174 Engine:EMS scan for process: svchost pid: 8548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.190 Engine:EMS scan for process: svchost pid: 9144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.190 Engine:EMS scan for process: svchost pid: 9204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.190 Engine:EMS scan for process: svchost pid: 6976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.190 Engine:EMS scan for process: svchost pid: 7068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.190 Engine:EMS scan for process: dllhost pid: 10404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.205 Engine:EMS scan for process: svchost pid: 13632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.205 Engine:EMS scan for process: svchost pid: 13760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.221 Engine:EMS scan for process: svchost pid: 14156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.221 Engine:EMS scan for process: svchost pid: 2832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.221 Engine:EMS scan for process: svchost pid: 8692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.221 Engine:EMS scan for process: svchost pid: 11772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.236 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.236 Engine:EMS scan for process: svchost pid: 9548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.236 Engine:EMS scan for process: svchost pid: 11492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.236 Engine:EMS scan for process: svchost pid: 7028, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:28:57.393 OriginalFileName Maintenance::10029 files in Moac, 245 skipped (cached), 1 filename set 2026-05-18T18:28:57.393 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-18T18:32:12.730 RPC Rundown called on ScanID: 60AB5514-38C5-4181-9095-3429283C21FE 2026-05-18T18:32:12.730 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:60AB5514-38C5-4181-9095-3429283C21FE. bRemoveFromList(ClientKilled):1 2026-05-18T18:32:12.746 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:60AB5514-38C5-4181-9095-3429283C21FE 2026-05-18T18:32:12.746 QuickScan:ScanID:60AB5514-38C5-4181-9095-3429283C21FE: User scan error=000003e3 2026-05-18T18:32:12.746 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:60AB5514-38C5-4181-9095-3429283C21FE 2026-05-18T18:32:12.746 QuickScan:ScanID:60AB5514-38C5-4181-9095-3429283C21FE: Quick scan aborted by callback after end stage 2026-05-18T18:32:12.746 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:60AB5514-38C5-4181-9095-3429283C21FE 2026-05-18T18:32:12.746 OnDemandScanWorker: Scan Cancelled! scanId:60AB5514-38C5-4181-9095-3429283C21FE, hr = 0x80508018 2026-05-18T18:32:14.752 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:32:14.768 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-18T18:32:14.768 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:34:20.940 [RTP] [Mini-filter] OpenWithoutRead notification (1207, 10023, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-18T18:34:40.424 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000409645D74FFF, sigsha=ecde1fef3aebf5e56995e66b4d12a6dc394fc3cc, cached=false, source=5, resourceid=0xcaef8ee9 2026-05-18T18:45:17.579 Lua SetAttribute:Filter caching disabled for \Device\HarddiskVolume3\Users\ITHAN\Downloads\webtrees-2.2.6\webtrees\vendor\symfony\console\Resources\bin\hiddeninput.exe (runtime MpDisableCaching from 0x000806bd7ce86a3d) 2026-05-18T18:45:17.579 MpLog-Throttle:The above 1 log lines will be snoozed for 3600000 ms 2026-05-18T18:47:10.174 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:471F8801-B293-4EF5-8D1F-6787A90D63E9, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-18T18:47:10.174 Scheduled scan with Id 471F8801-B293-4EF5-8D1F-6787A90D63E9 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-18T18:47:10.174 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-18T18:47:10.174 [SFC] System file cache build is not needed (already completed) 2026-05-18T18:47:12.179 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:47:12.179 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-18T18:47:12.194 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-18T18:47:13.402 Engine:Triggered AR EMS scan 2026-05-18T18:47:13.417 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.433 Engine:EMS scan for process: svchost pid: 968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.448 Engine:EMS scan for process: svchost pid: 560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.448 Engine:EMS scan for process: svchost pid: 1036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.448 Engine:EMS scan for process: svchost pid: 1192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.464 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.464 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.464 Engine:EMS scan for process: svchost pid: 1344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.464 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.480 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.480 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.480 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.480 Engine:EMS scan for process: svchost pid: 1504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.495 Engine:EMS scan for process: svchost pid: 1560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.495 Engine:EMS scan for process: svchost pid: 1628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.495 Engine:EMS scan for process: svchost pid: 1648, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.511 Engine:EMS scan for process: svchost pid: 1680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.511 Engine:EMS scan for process: svchost pid: 1832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.511 Engine:EMS scan for process: svchost pid: 2004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.526 Engine:EMS scan for process: svchost pid: 1784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.526 Engine:EMS scan for process: svchost pid: 2104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.526 Engine:EMS scan for process: svchost pid: 2156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.526 Engine:EMS scan for process: svchost pid: 2336, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.526 Engine:EMS scan for process: svchost pid: 2368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2628, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.542 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.558 Engine:EMS scan for process: svchost pid: 2984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.558 Engine:EMS scan for process: svchost pid: 2304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.558 Engine:EMS scan for process: svchost pid: 2584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.573 Engine:EMS scan for process: svchost pid: 3104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.573 Engine:EMS scan for process: svchost pid: 3552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.573 Engine:EMS scan for process: svchost pid: 3560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.589 Engine:EMS scan for process: svchost pid: 3660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.589 Engine:EMS scan for process: svchost pid: 3748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.589 Engine:EMS scan for process: svchost pid: 3808, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.605 Engine:EMS scan for process: svchost pid: 3744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.605 Engine:EMS scan for process: svchost pid: 2592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.605 Engine:EMS scan for process: svchost pid: 4180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.605 Engine:EMS scan for process: svchost pid: 4216, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.620 Engine:EMS scan for process: svchost pid: 4232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.620 Engine:EMS scan for process: svchost pid: 4368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.620 Engine:EMS scan for process: svchost pid: 4476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.636 Engine:EMS scan for process: svchost pid: 4540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.636 Engine:EMS scan for process: svchost pid: 4636, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.636 Engine:EMS scan for process: svchost pid: 5196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.652 Engine:EMS scan for process: svchost pid: 6068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.652 Engine:EMS scan for process: dllhost pid: 6104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.652 Engine:EMS scan for process: svchost pid: 6184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.652 Engine:EMS scan for process: svchost pid: 6944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.667 Engine:EMS scan for process: svchost pid: 6952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.667 Engine:EMS scan for process: svchost pid: 7052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.667 Engine:EMS scan for process: svchost pid: 3308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.683 Engine:EMS scan for process: svchost pid: 8164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.683 Engine:EMS scan for process: svchost pid: 1236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.683 Engine:EMS scan for process: svchost pid: 1640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.698 Engine:EMS scan for process: svchost pid: 2100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.698 Engine:EMS scan for process: svchost pid: 2992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.698 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.714 Engine:EMS scan for process: explorer pid: 8276, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.761 Engine:EMS scan for process: svchost pid: 8432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.761 Engine:EMS scan for process: svchost pid: 8548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.761 Engine:EMS scan for process: svchost pid: 9144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-18T18:47:13.761 Engine:EMS scan for process: svchost pid: 9204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-27-2026 09:46:31 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/27/2026 09:46:31.195703600 UTC (20906 ms since boot) 2026-05-27T09:46:31.202 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-27T09:46:31.202 WARNING: the previous service shutdown was not expected. 2026-05-27T09:46:31.202 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:46:31.202 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:46:31.233 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260527-094631-00000003-fffffffeffffffff.bin ... 2026-05-27T09:46:31.280 [WPP] Trace session started - MpWppTracing-20260527-094631-00000003-fffffffeffffffff.bin 2026-05-27T09:46:31.280 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-27T09:46:31.296 [RbM] Rollback manager succesfully initialized. 2026-05-27T09:46:31.296 [RbM] Rollback manager EnableRollbackManager called. 2026-05-27T09:46:31.296 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-27T09:46:31.296 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-27T09:46:31.296 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-27T09:46:31.296 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-27T09:46:31.296 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-27T09:46:31.296 MdCoreSvc is supported in this platform and OS 2026-05-27T09:46:31.296 MdCoreSvc is supported in this platform and OS 2026-05-27T09:46:31.296 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-27T09:46:31.296 [PlatUpd] Starting MdCoreSvc service 2026-05-27T09:46:31.343 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-27T09:46:35.061 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-27T09:46:35.061 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-27T09:46:35.061 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-27T09:46:35.061 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-27T09:46:35.061 [PlatUpd] CSP platform update started 2026-05-27T09:46:35.061 [PlatUpd] Defender MDM CSP platform update not required 2026-05-27T09:46:35.061 [PlatUpd] WMI/PS provider platform update started 2026-05-27T09:46:35.061 [PlatUpd] WMI/PS provider platform update not required 2026-05-27T09:46:35.061 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-27T09:46:35.061 MdCoreSvc is supported in this platform and OS 2026-05-27T09:46:35.061 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-27T09:46:35.061 [PlatUpd] Starting MdCoreSvc service 2026-05-27T09:46:35.061 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-27T09:46:35.061 [TS] Troubleshooting mode is not available! 2026-05-27T09:46:35.061 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-27T09:46:35.077 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-27T09:46:35.093 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-27T09:46:35.093 [Service] Enabling AutoLoggers ... 2026-05-27T09:46:35.093 [Service] Enabling AMSI registration ... 2026-05-27T09:46:35.093 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-27T09:46:35.108 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 47332 Number of invalid entries is 0 Number of inserts issued is 1590693 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6555 Number of lookups is 108646242 Number of lookup misses is 5216719 Number of fast lookup misses is 55357901 Number of false fast lookups is 5216714 Number of invalidations is 736834 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-27T09:46:35.108 Verifying license file... 2026-05-27T09:46:35.108 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll]. File not in cache (0x1) 2026-05-27T09:46:35.140 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] 2026-05-27T09:46:35.155 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-27T09:46:35.155 Loaded module#0 MpComServer. 2026-05-27T09:46:35.155 Loaded module#1 StartupPolicies. 2026-05-27T09:46:35.155 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-27T09:46:35.155 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-27T09:46:35.155 COM server initialized successfully. 2026-05-27T09:46:35.171 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-27T09:46:35.171 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-27T09:46:35.171 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-27T09:46:35.186 [RTP] [RTP] FilterCommunicator object 0x000001B094A94640 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-27T09:46:35.186 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-27T09:46:35.186 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:46:35.186 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:46:35.186 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-27T09:46:35.186 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-27T09:46:35.186 [RTP] [RTP] FilterCommunicator object 0x000001B094AF2CC0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-27T09:46:35.186 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-27T09:46:35.186 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-27T09:46:35.186 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-27T09:46:35.186 [RTP] [RTP] StartCommunication 0x000001B094A94640 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-27T09:46:35.202 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-27T09:46:35.202 [init][RTP] RTPPlugin initialization completed 2026-05-27T09:46:35.202 OS boot count = 2 2026-05-27T09:46:35.202 OS Install = 0 2026-05-27T09:46:35.202 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-27T09:46:35.202 [KSL] Entering CKSLEngine::Initialize. 2026-05-27T09:46:35.202 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-27T09:46:35.202 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-27T09:46:35.202 [KSL] MpInstallKslD: hr=0x1 2026-05-27T09:46:35.202 [KSL] MpRegisterKslD: hr=0 2026-05-27T09:46:35.218 [KSL] MpStartKslD: hr=0 2026-05-27T09:46:35.218 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-27T09:46:35.218 Loading engine... 2026-05-27T09:46:35.233 Verifying engine and signature files (source: 1) ... 2026-05-27T09:46:35.233 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpengine.dll] due to PPL. 2026-05-27T09:46:35.233 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasbase.vdm]. File not in cache (0x1) 2026-05-27T09:46:36.171 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasbase.vdm] 2026-05-27T09:46:36.171 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-27T09:46:36.186 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasdlta.vdm] 2026-05-27T09:46:36.186 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavbase.vdm] (file in cache) 2026-05-27T09:46:36.186 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpavdlta.vdm] (file in cache) 2026-05-27T09:46:36.233 [Engine] IsHybridMode: 0 2026-05-27T09:46:36.233 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-27T09:46:36.249 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D1C259F30EABAAB233A00C0760FDD47A65BAA1B1.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-27T09:46:42.065 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-27T09:46:42.065 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpFC_NisSrvEnableOneDSTelemetry new=0 old1 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-27T09:46:42.065 [Engine] New active engine 00007FFA608F5810 (no old engine). Number of active engines: 1 2026-05-27T09:46:42.096 EngineInit:Global ASOC is enabled 2026-05-27T09:46:42.096 EngineInit:ASOO is enabled for developer volumes 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:46:42.205 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c703967ed1a945623c2600e10d4cd23480caa174 Dynamic Signature Compilation Timestamp:04-20-2026 17:05:41 Persistence Type:Duration Time remaining:150196224 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b95c30a0c989c32a726fba15c32296c8b7a9d6c4 Dynamic Signature Compilation Timestamp:04-20-2026 17:45:18 Persistence Type:Duration Time remaining:150196224 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bb8689391a52b0d52f6b49c83594fb9b841642dd Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:150196224 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e4cbcc83926e7f0a6f747bd17f4a16b16b3db74d Dynamic Signature Compilation Timestamp:04-20-2026 17:47:52 Persistence Type:Duration Time remaining:150196224 2026-05-27T09:46:42.221 Dynamic signature dropped 2026-05-27T09:46:42.221 Dynamic signature dropped 2026-05-27T09:46:42.221 Dynamic signature dropped 2026-05-27T09:46:42.221 Dynamic signature dropped 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\06be8c6887e9f6a154c0c4db72aafd679c637a26 Dynamic Signature Compilation Timestamp:04-20-2026 17:55:20 Persistence Type:Duration Time remaining:150196224 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e19fd16402b26582924003323d97209e28c47df5 Dynamic Signature Compilation Timestamp:04-23-2026 17:44:51 Persistence Type:Duration Time remaining:150196224 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1239f991c057a24c77e3aa3270c3895d2df97c7c Dynamic Signature Compilation Timestamp:04-26-2026 08:27:47 Persistence Type:Duration Time remaining:150196224 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2170ee8b7db76e95bd0683b685c93a19f4b7a787 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:11 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9df28069c54f06cc967ef127f236c8a1611d6933 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\674d5b2b98a544ac9597110bad1887dc30b5aa79 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cba30f8b11b5cb2837316244dae1a21e942b1bfc Dynamic Signature Compilation Timestamp:05-15-2026 21:51:12 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e72bb33d32ab21d1c69a07f7a19b1cbe628e4ee2 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:13 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\47a558d44b924447c7cfb687a3f682597cf7981c Dynamic Signature Compilation Timestamp:05-15-2026 21:51:14 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\72d0a005777561e4f186bb3fca4bbb8a475158e3 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:14 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bf81dd58660cfeeca3c8692e22d318009349250b Dynamic Signature Compilation Timestamp:05-15-2026 21:51:14 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.221 Dynamic signature dropped 2026-05-27T09:46:42.221 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e7e0dd3e66568bcf903d3b70ca87d3dc6d8cebfc Dynamic Signature Compilation Timestamp:05-15-2026 21:51:15 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a0e7decc72a76b26bebbe444f47d7447b9b4edce Dynamic Signature Compilation Timestamp:05-15-2026 21:51:15 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7679f6d4a1892525832156b447c77fdaefa90a8a Dynamic Signature Compilation Timestamp:05-15-2026 21:51:15 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1dd1c2f00050896187ffce298832955c1f669acc Dynamic Signature Compilation Timestamp:05-15-2026 21:51:16 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c25c68d99ec961cc9131bf9fa1072b41929f5b77 Dynamic Signature Compilation Timestamp:05-15-2026 21:51:16 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd91e5fe4299ba54a9432f2e69927aa846fea511 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:00 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\baf17a4aede642cb6dd2256c8b0657e5845d56d1 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f2c1fc2a1073e0bf26a61faa87b5d7181f5def8c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\439178085b624c5e54867bde062bbc3e3ce8cd0e Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\233d6ba43f2cb8bef94f3a41a0d977d472d094ee Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3859d201b1c1e0d6bfbc197804e605f65296fd29 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:01 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ae8acacca1d3993cd1ad462fe4f53996047b412 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:02 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\de7ed5cf55070c6d5038783333e6c20b9b597a00 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7f7ae3dc73490b5e25874d40c3d18bd081f17b8b Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f252b0ec7a55a3e634c5f961897edda727f584b8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4e97ae12a8c229dafebb1b7dfe48d53ee5fa165c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:03 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\887ebddc08fde48f75ccd18c5f2a1e2bd6f0e3ab Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9c9c3c2df6ff2d9a1b369cc2f1eece8f8b6c5536 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b39ac7205431bf28c87dacdbe0bdf7077c17623 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:04 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.236 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\648c5f30d105dafad4dcaf54a386f45d0aa86930 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3dd10c3991096904f91d93ed4d6bca278a19e869 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d7bd50ef2215dbd71aaf1ab6b688c1c04ad061c3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:05 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\19618574d921a1a092498426de2bb62104333c01 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\42f43cf8819518049f1cc853cbebac650a6b9f5d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d4fd0c988d115c82dbacfa3af3c1704719c53956 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7a58e9532447b8c4a745e4dd6e05a3b009756db7 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:06 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\332421f2f0d8ad9450954ab9bd4eaeae373eb3e3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a0854df48684365aff7c663aba86adf2ea2e6975 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\01e3c74539adc811914eff0546db4605527c5e52 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdc5670e00bbb44bb00785362421ce84dc2e6110 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:07 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3e1dd65c7eedbcf2b5e9b1800333b080b4743bd9 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3272a0284544e020eaa214f605f1272bc6a29a5d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a643dcdd5a2e5c0e1c530e11c6ef7cf9761c19d Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82c57a44716437dc610d58aaeeee696a632a8810 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:08 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ebba7d5912dcb78ae35ea9734ee49632d3178b56 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3b89f06cd8ec26c460e54922387a1b2f44388f43 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\923314b132dd3e515ce3e86f72cf5bfadfe5e210 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87a9c1781effb536e60c1e5f736f3cb673486119 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ff3fe48af8fad5ffc063e3dcfb28274868808cf Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.252 Dynamic signature dropped 2026-05-27T09:46:42.252 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9acd6f44d0a5dc27b7e9545c2c0b44de61dfec8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79ace9039cac84724e766e24baa16bf9d10f1eb8 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:10 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fe4cc0c4301471b4465b29afc49e3d3ba5c63c87 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6dca9bcf0ef624ddf2255ff80fa8b54e534f455a Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fdfb84e8da3db2bfe48f9b33980922b3822e4879 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\802bcf3ce5f81f45c4ac89457aa380f5ce2abbe7 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:11 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\02f22476b69e010890690e660673f3a138e4c901 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b494fc5669fd2a4238dee0bb041dea6bffd7d43c Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c7d32f91ea4f76af22148b7769a3181f7aeb01e3 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:12 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f4ab2a9c683ea934bdbee30bf053c22f7c770503 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:13 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c925c2dd567e60bceda9a776410259afafb6b03b Dynamic Signature Compilation Timestamp:05-16-2026 06:43:13 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5b7ddb888bf025d93152687d97e626b9cfa157a3 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:11 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c9573f5cb16454f17257b40a9abfec5178e7afd0 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:13 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f7d89f2f2877df2502e3e3b5a5c8ab947d4961a1 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:13 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd8d945fdcaffea21960875672f66b7f7301a7fd Dynamic Signature Compilation Timestamp:05-16-2026 07:59:39 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\91cb1caddabbcd6c04753421191cd1bb6567a503 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.268 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ef582e22047da2f4e419011668efb0050d09d51 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46eeb3447a0bce7244e45146fbe57707794eb4a2 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fc8cb6186c12e33816e830e1f4dac1a6ce81d942 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fd4e2e1b8f443af3f364c27b65a196c5bef9cd0c Dynamic Signature Compilation Timestamp:05-16-2026 16:54:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\733dfe5a9f4818634f30a77e456f7c23d05885bd Dynamic Signature Compilation Timestamp:05-16-2026 16:54:46 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1e30fd0bf5ac373ed0b2f5c2a3e6940d13245940 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:46 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c60e9a0822572f9e63e6ed21341a2cda1de5ffaa Dynamic Signature Compilation Timestamp:05-16-2026 16:55:15 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31a5f79a9c83ff19cfae3cb9bb5fe6aa7251f737 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\190446bbd08cc17d92d9f5dd79b591eedfc209f3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2ba4ed1d071f40ec715cbb4c25e4ca100a827931 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:16 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8ec5ac2fd4c957aa423d8c34ba9e9919976a2ab7 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8625148623f5d93480268e4436ca89622bf46b76 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\388feddf6bc2a66f5732586515c96cd551776c0b Dynamic Signature Compilation Timestamp:05-16-2026 16:55:17 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\89be32d907a34002866522e31bba2a50c8c9715d Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.283 Dynamic signature dropped 2026-05-27T09:46:42.283 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0edc1793a2aac7acf79e727189f168b8f2855658 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c01108b362e83d39d68cea384ee13bb1c900e578 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:18 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9b6122979e4917cb700856362556c9e310b1757 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0087a7287b7966dba7eb0218aabc795930bf2a50 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2244730e6ee94b3cb2191e0ea6f6c39117e9621a Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\13e7f0abfc03363de822e25b874131a852159e49 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:19 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\81e2d66d502659d38b8a47f352246d8bd261d460 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:20 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\deeba5fb36d2a8fbcf2718babaf4dd6b11dc7144 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:20 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7f33c3c8acadf6416204bed290232ffb089049f Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f44d9c3b1b30441b9e93df69d4ce0becca7c18a1 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eda4f675e4a5f0d7af8d7c5f03611c58700c519c Dynamic Signature Compilation Timestamp:05-16-2026 16:55:21 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2910defc42cc3760f831993cdf9424b505a43a58 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ff9725cd7464adb6e561fe066695dfd6d2465e25 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a953f2a7dd11f745dc91c55617266b5b9fe22fd Dynamic Signature Compilation Timestamp:05-16-2026 16:55:22 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\566787fd21d3d84a98c97724dc770648d7a69360 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\72bdc1e1c354f8d96e3b2dc737e4a3704b212044 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48d32e388a1de406dc93a6336f3cdf084a5830cc Dynamic Signature Compilation Timestamp:05-16-2026 16:55:23 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\47ac7524ffc09f594db57320d916d2d53f1d50d3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3a2b648963bec7a7cb4cd6e997379c2ccb020bbe Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\db67e05983f91c1258577588c561f4f577287092 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52763bfdf065042ede80ef01b0279751d7ecb78b Dynamic Signature Compilation Timestamp:05-16-2026 16:55:24 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82c05a575526cd775aaf75b3bf178ace6ef380f4 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.299 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\09250b9efb569978b4a94d1850e070e3ae7cdab8 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\46b4c6c393f6e6c1da4a0831aff5ec5ce3ddfc83 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:25 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f6c8a014fee610dc20b4b14bd8c14a2a533fcb44 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:26 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\292f74f5118db944cef626af4eefba8434087045 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:27 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9f1db4af7a0dafc0bea3ee9a1e30c453d298811e Dynamic Signature Compilation Timestamp:05-16-2026 16:55:30 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\969773405919d3b4877dfd75df65667b2a5df40a Dynamic Signature Compilation Timestamp:05-16-2026 16:55:31 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f709d21b0327ed6b35a302bc8fcd3ac18cb76ff5 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8e58d073de98d1b97992b62b26863a45cd033ad4 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1636d2d532c72cfb7369883307425bebe993a60 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:33 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fd0285ebbb374069f48aac53b9be2b848bacef0d Dynamic Signature Compilation Timestamp:05-16-2026 16:55:33 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\50e01aa05539acb79b5a427d4b2ab69d5c5bff1e Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b997e14a8dc0d7b1d53e76481bae21d74c5be2e0 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3fcdd6f5d0e8c719e9b6a47c92440667f84cd437 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:34 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4fc4aec0cff04ff08adb45b459cd72d3a0f4a8b2 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:35 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8632ba51d90f89b9284efa3d5447941237348cb3 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:35 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.315 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dc1fc611768cf7680c21f779c40a149ac06f2f59 Dynamic Signature Compilation Timestamp:05-16-2026 16:55:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.330 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b846e63ce5663ce3237be2a90a5d7fa7b4d9cbce Dynamic Signature Compilation Timestamp:05-16-2026 16:55:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T09:46:42.330 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7af41c3371bc9e99c425770ea2bb2833a8183555 Dynamic Signature Compilation Timestamp:05-18-2026 18:17:39 Persistence Type:Duration Time remaining:288000000 2026-05-27T09:46:42.346 Dynamic signature dropped 2026-05-27T09:46:42.346 MpWriteUupSignatureVersion 1.449.681.0, hr = 0 2026-05-27T09:46:42.346 [SigStatUpd] CSignatureStatus: Changed to DUE_TRY_1 2026-05-27T09:46:42.346 [SigStatUpd] CSignatureStatus: Triggering signature update... 2026-05-27T09:46:42.377 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-27T09:46:42.377 [SigStatUpd] CSignatureStatus: Signature update triggered! 2026-05-27T09:46:42.377 [SigStatUpd] CSignatureStatus: UpdateWaitTimer #1 scheduled 2026-05-27T09:46:42.377 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-27T09:46:42.408 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:46:42.408 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-27T09:46:42.408 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-27T09:46:42.408 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T09:46:42.455 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-27T09:46:42.455 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,1,0 Proc:0,1,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:1 AsyncQMissed:0 AsyncQTotalSent:196 AsyncQCurrent:626 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2720 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14525 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3030 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-27T09:46:42.455 [Plugin] Initializing RTP plugin state... 2026-05-27T09:46:42.455 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-27T09:46:42.455 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963} 2026-05-27T09:46:42.455 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:46:42.455 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:46:42.455 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:46:42.455 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T09:46:42.455 MdCoreSvc is supported in this platform and OS 2026-05-27T09:46:42.455 Engine loaded! 2026-05-27T09:46:42.455 [DLP] Create FeatureControlState instance 2026-05-27T09:46:42.455 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-27T09:46:42.455 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-27T09:46:42.471 RegisterSModeChangeListener: hr = 0x1 2026-05-27T09:46:42.471 RegisterHybridModeChangeListener: hr = 0 2026-05-27T09:46:42.502 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8460] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8484]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T09:46:42.502 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-27T09:46:42.502 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T09:46:42.533 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-27T09:46:42.533 [SigReleaseHb] Initialized with Stage 0 2026-05-27T09:46:42.533 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-27T09:46:42.533 [SCC][CID=32250_5856] Initializing ... 2026-05-27T09:46:42.533 [SCC][CID=32250_5856] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-27T09:46:42.533 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-27T09:46:42.533 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-27T09:46:42.565 [NRI] Stopping NIS service ... 2026-05-27T09:46:42.565 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-27T09:46:42.565 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.449.681.0 AV Signature Version: 1.449.681.0 ************************************************************ 2026-05-27T09:46:42.580 Resource usage Monitoring is enabled 2026-05-27T09:46:42.580 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-27T09:46:42.580 Job Notification: New process added to job (4904) 2026-05-27T09:46:42.674 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8704] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8768]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T09:46:42.690 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-27T09:46:42.690 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-27T09:46:42.705 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T09:46:42.705 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T09:46:42.705 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T09:46:42.705 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:46:42.705 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:46:42.705 [RTP] Generating the base plugin configuration ... 2026-05-27T09:46:42.705 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-27T09:46:42.705 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:46:42.705 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-27T09:46:42.721 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-27T09:46:42.721 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:46:42.721 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-27T09:46:42.721 [RTP] [RTP] StartCommunication 0x000001B094AF2CC0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-27T09:46:42.736 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-27T09:46:42.783 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\Windows.System.Launcher.dll 2026-05-27T09:46:42.955 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-27T09:46:42.955 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-27T09:46:42.955 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-27T09:46:43.033 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-27T09:46:43.111 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:43.471 Job Notification: New process added to job (9196) 2026-05-27T09:46:43.471 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-27T09:46:43.518 Job Notification: New process added to job (7444) 2026-05-27T09:46:43.565 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:9196] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7444]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T09:46:43.565 Bm signature throttled:0x00002db31bed458f 2026-05-27T09:46:44.643 [AutoPurge] Cleanup Routine tasks have started. 2026-05-27T09:46:44.658 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-05-27T09:46:44.658 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-27T09:46:44.658 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-27-2026 09:46:44 2026-05-27T09:46:44.690 [AutoPurge] Verification Routine tasks have started. 2026-05-27T09:46:44.690 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-27-2026 09:46:44ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T09:46:44.690 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-27T09:46:44.690 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-27T09:46:44.690 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-27T09:46:44.690 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-27T09:46:44.690 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-27T09:46:44.705 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-27T09:46:44.971 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-27T09:46:44.971 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-27T09:46:45.002 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-27T09:46:45.361 Job Notification: New process added to job (9432) 2026-05-27T09:46:45.361 Task(GetDeviceTicket -AccessKey CE843D7B-78D8-1B9E-7FBB-9904D69A2AA0 ) launched as network service 2026-05-27T09:46:45.705 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:46:45.705 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:46:45.705 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-27T09:46:45.705 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-27T09:46:45.705 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-27T09:46:45.861 Job Notification: Process exited from job (9432) 2026-05-27T09:46:46.393 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-27T09:46:46.408 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-27T09:46:46.408 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:46:46.408 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:46:46.408 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-27T09:46:46.408 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:46:46.408 [RTP] No config change detected. Not updating plugin configuration. 2026-05-27T09:46:46.408 [RTP] No config changes found. No configuration switch. 2026-05-27T09:46:46.408 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-27T09:46:46.408 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:46:46.408 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:46:46.408 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-27T09:46:46.408 [RTP] No config change detected. Not updating plugin configuration. 2026-05-27T09:46:46.408 [RTP] No config changes found. No configuration switch. 2026-05-27T09:46:46.408 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-27T09:46:46.408 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:46.408 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T09:46:46.408 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:46:46.408 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:46:46.408 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T09:46:46.408 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-27T09:46:46.408 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-27T09:46:46.424 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:46.424 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:46.424 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:46.971 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-05-27T09:46:46.971 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T09:46:46.971 [Cloud] Queued cloud request. 2026-05-27T09:46:46.971 [Cloud] Dequeued cloud request. 2026-05-27T09:46:46.986 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T09:46:47.635 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-05-27T09:46:47.635 [Cloud] End of cloud request. 2026-05-27T09:46:48.228 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:46:48.291 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-27T09:46:48.307 [AutoPurge] Verification Routine tasks have ended. 2026-05-27T09:46:49.158 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:46:49.158 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:46:49.158 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-05-27T09:46:49.158 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-27T09:46:49.158 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-05-27T09:46:51.111 [RTP] 1 newly mounted volumes accumulated, forcing a config update ... 2026-05-27T09:46:51.111 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:46:51.111 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:46:51.111 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-27T09:46:51.111 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-27T09:46:51.111 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-27T09:46:51.127 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-05-27T09:47:20.575 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3163, FileId: 0x8800000000fbb2, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:47:35.171 Process scan (poststartupscan) started. 2026-05-27T09:47:35.171 Process scan (poststartupscan) completed. 2026-05-27T09:47:46.283 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.074.0420.0001\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4259, FileId: 0x9b000000004b97, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:48:17.674 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-05-27T09:48:23.455 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5178, FileId: 0xe50000000103eb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:48:24.659 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 5546 units 2026-05-27T09:48:28.049 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\713C4789-87A1-4828-944E-D255122EF4633bb0.1dcedbddf27a5b6 2026-05-27T09:48:30.252 Verifying engine and signature files (source: 0) ... 2026-05-27T09:48:30.252 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpengine.dll] due to PPL. 2026-05-27T09:48:30.252 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasbase.vdm]. File not in cache (0x1) 2026-05-27T09:48:31.018 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasbase.vdm] 2026-05-27T09:48:31.018 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-27T09:48:31.034 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasdlta.vdm] 2026-05-27T09:48:31.034 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavbase.vdm]. File not in cache (0x1) 2026-05-27T09:48:31.471 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavbase.vdm] 2026-05-27T09:48:31.471 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-27T09:48:31.502 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavdlta.vdm] 2026-05-27T09:48:31.721 [Engine] IsHybridMode: 0 2026-05-27T09:48:31.721 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-27T09:48:31.736 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3EBACC38152AB85E586C23D079F4AEBA25612494.bin): 0x00000002 2026-05-27T09:48:31.736 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3EBACC38152AB85E586C23D079F4AEBA25612494.bin) 2026-05-27T09:48:31.736 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-27T09:48:31.736 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-27T09:48:31.736 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-27T09:48:31.736 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-05-27T09:48:33.846 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T09:48:33.846 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T09:48:33.846 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-27T09:48:43.955 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-27T09:48:43.955 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-27T09:48:43.971 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFA608F5810, lRefCount: 5, hr=0 2026-05-27T09:48:43.971 [Engine] New active engine 00007FFA0AEE5810 replacing engine 00007FFA608F5810. Number of active engines: 2 2026-05-27T09:48:43.971 EngineInit:Global ASOC is enabled 2026-05-27T09:48:43.971 EngineInit:ASOO is enabled for developer volumes 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.065 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:48:44.080 MpWriteUupSignatureVersion 1.451.125.0, hr = 0 2026-05-27T09:48:44.080 [SigStatUpd] CSignatureStatus: back to good 2026-05-27T09:48:44.080 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-27T09:48:44.111 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-27T09:48:44.111 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:48:44.111 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-27T09:48:44.111 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-27T09:48:44.111 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T09:48:44.158 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-27T09:48:44.158 [Plugin] Initializing RTP plugin state... 2026-05-27T09:48:44.158 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎27‎-‎2026 11:46:42 Last Perf:‎05‎-‎27‎-‎2026 11:46:42 First RTP Scan:‎05‎-‎27‎-‎2026 11:46:42 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2026 Misses:2999 BM Queue:0,215,0 Proc:0,120,0 File:0,151,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,2,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5309 Pending:0 RegSize:308070 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:14270988 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:8506 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:26381 TotalHits:15449 InstanceCacheInserts:352 InstanceCacheUpdates:0 InstanceCacheDeletes:41 InstanceCacheHits:0 InstanceCacheMisses:12498 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:5ms (808/152) Success: 152, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-27T09:48:44.158 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-27T09:48:44.158 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C} 2026-05-27T09:48:44.158 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963}\mpasbase.vdm in use, hr=0x80070020 2026-05-27T09:48:44.158 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T09:48:44.174 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:48:44.174 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-27T09:48:44.205 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC7FFF0D-753E-467E-BEB6-208570DCE335} removed 2026-05-27T09:48:44.205 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.205 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.205 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.205 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.205 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-27-2026 09:48:44 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-27-2026 09:48:44 2026-05-27T09:48:44.205 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-27T09:48:44.205 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-27T09:48:44.205 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:48:44.221 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.221 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.221 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.221 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T09:48:44.221 MdCoreSvc is supported in this platform and OS Signature updated on 05-27-2026 09:48:44 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.451.125.0 AV Signature Version: 1.451.125.0 ************************************************************ 2026-05-27T09:48:44.221 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-27T09:48:44.221 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\713C4789-87A1-4828-944E-D255122EF4633bb0.1dcedbddf27a5b6 2026-05-27T09:48:44.315 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-27T09:48:44.315 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-27T09:48:44.608 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-27T09:48:44.608 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-27T09:48:44.608 [KSL] Leaving CKSLEngine::EnableKsl(0). Signature updated via MicrosoftUpdateServer on 05-27-2026 09:48:44 ************************************************************ 2026-05-27T09:48:44.692 Job Notification: Process exited from job (9196) 2026-05-27T09:48:44.705 Job Notification: Process exited from job (7444) 2026-05-27T09:48:45.158 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T09:48:45.158 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T09:48:45.158 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T09:48:45.158 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:48:45.158 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:48:45.158 [Engine] Engine 00007FFA608F5810 no longer in use. Number of active engines: 1 2026-05-27T09:48:45.158 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:48:45.158 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-27T09:48:45.299 ProcessImageName: explorer.exe, Pid: 9140, TotalTime: 4845, Count: 143, MaxTime: 1437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 5% 2026-05-27T09:48:45.299 ProcessImageName: dllhost.exe, Pid: 11312, TotalTime: 2974, Count: 90, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\9V85I3X3NW_35, EstimatedImpact: 44% 2026-05-27T09:48:45.299 ProcessImageName: AsPowerBar.exe, Pid: 2236, TotalTime: 2271, Count: 18, MaxTime: 796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 24% 2026-05-27T09:48:45.299 ProcessImageName: DipAwayMode.exe, Pid: 8596, TotalTime: 2159, Count: 30, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 6% 2026-05-27T09:48:45.299 ProcessImageName: MOM.exe, Pid: 11620, TotalTime: 2024, Count: 29, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 54% 2026-05-27T09:48:45.299 ProcessImageName: OneDriveUpdaterService.exe, Pid: 14832, TotalTime: 1858, Count: 4, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 12% 2026-05-27T09:48:45.299 ProcessImageName: AISuite3.exe, Pid: 8544, TotalTime: 1632, Count: 22, MaxTime: 765, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 3% 2026-05-27T09:48:45.299 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6312, TotalTime: 1502, Count: 42, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\OneDrive.Sync.Service.dll, EstimatedImpact: 21% 2026-05-27T09:48:45.299 ProcessImageName: websockify.exe, Pid: 11636, TotalTime: 945, Count: 18, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 28% 2026-05-27T09:48:45.299 ProcessImageName: TeamViewer_Service.exe, Pid: 4856, TotalTime: 787, Count: 19, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\update.exe, EstimatedImpact: 0% 2026-05-27T09:48:45.299 ProcessImageName: WmiPrvSE.exe, Pid: 2228, TotalTime: 495, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf->(UTF-16LE), EstimatedImpact: 29% 2026-05-27T09:48:45.299 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 7560, TotalTime: 408, Count: 60, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\ListSync\settings\NucleusUpdateRingConfig.json, EstimatedImpact: 6% 2026-05-27T09:48:45.299 ProcessImageName: FileCoAuth.exe, Pid: 12488, TotalTime: 273, Count: 16, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileSyncSessions.dll, EstimatedImpact: 3% 2026-05-27T09:48:45.299 ProcessImageName: svchost.exe, Pid: 12580, TotalTime: 263, Count: 5, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT4BBC.tmp, EstimatedImpact: 0% 2026-05-27T09:48:45.299 ProcessImageName: TeamViewer.exe, Pid: 5128, TotalTime: 243, Count: 14, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Profiles\fkvp51kw.dev-edition-default\prefs.js, EstimatedImpact: 3% 2026-05-27T09:48:45.346 [Engine] RSIG_UNLOADENGINE, 00007FFA608F5810, err=0x0 2026-05-27T09:48:45.362 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D55AC2A-7583-476A-A7CA-00534E598963} removed 2026-05-27T09:48:46.221 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T09:48:46.221 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T09:48:46.221 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T09:48:48.033 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5321, FileId: 0x47000000011380, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0xcd098c58 2026-05-27T09:48:55.289 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T09:48:55.289 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T09:48:55.289 [Cloud] Queued cloud request. 2026-05-27T09:48:55.289 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T09:48:55.289 [Cloud] Dequeued cloud request. 2026-05-27T09:48:55.289 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T09:48:55.971 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e1072994edac52bd4582de6876be5dadb14207a0 Dynamic Signature Compilation Timestamp:05-27-2026 09:48:54 Persistence Type:Duration Time remaining:864000000 2026-05-27T09:48:55.971 [Cloud] End of cloud request. 2026-05-27T09:48:55.971 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T09:48:56.283 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files\TeamViewer\update.exe` is 5750 units 2026-05-27T09:48:56.487 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:49:05.893 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5597, FileId: 0xfe00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:05.893 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5596, FileId: 0x8700000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5599, FileId: 0x8a00000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5603, FileId: 0x10000000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:05.955 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5602, FileId: 0x8b00000000fbaf, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:05.971 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5600, FileId: 0xff00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.424 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5650, FileId: 0x10b00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5652, FileId: 0xcf000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5657, FileId: 0x10d00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.440 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5659, FileId: 0x10e00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.455 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5653, FileId: 0x10c00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.455 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5656, FileId: 0xd0000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.455 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5663, FileId: 0x11000000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.455 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5661, FileId: 0xd2000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.549 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5676, FileId: 0x11200000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.549 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5678, FileId: 0xd7000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5679, FileId: 0x11400000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5674, FileId: 0xd5000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5677, FileId: 0x11300000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5680, FileId: 0xd8000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.643 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5686, FileId: 0x11800000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:06.690 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5685, FileId: 0xdb000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:07.330 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5766, FileId: 0x11b00000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:07.330 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5765, FileId: 0x11900000000f7fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:08.346 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5839, FileId: 0xe0000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:08.346 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5841, FileId: 0xe1000000012a75, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:08.346 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #5840, FileId: 0x27000000012aeb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:09.429 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\be1fc803-8918-41e2-9811-048d62207436. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #5917, FileId: 0x8f00000000762e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:49:38.862 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-05-27T09:49:39.627 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-05-27T09:49:43.768 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:9120:134243489810482448) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:49:43.768 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:10956:134243489813060188) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:49:43.768 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:6800:134243489809926410) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:50:55.658 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #7520, FileId: 0x5e0000000296a6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:50:59.298 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:15060:134243490590883575) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:51:21.346 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:5424:134243490810932824) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:51:42.346 Bm signature throttled:0x00002db31bed458f 2026-05-27T09:51:42.533 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T09:51:46.877 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7879, FileId: 0x4e00000002971a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:51:47.502 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:4656:134243491071582150) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:52:18.284 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:12292:134243491372778644) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:52:32.533 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8433, FileId: 0xb00000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:32.533 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8434, FileId: 0x27000000033422, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:32.533 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8432, FileId: 0x24000000033422, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:32.549 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8431, FileId: 0x23000000033422, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:32.940 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\d07b954d-224f-4b16-b90a-63129e768d38. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #8459, FileId: 0xa10000000012fb, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:33.080 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8460, FileId: 0x33000000033422, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.049 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj39060F994. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9108, FileId: 0x1d000000033737, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.096 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDA381B91F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9109, FileId: 0x1e000000033737, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.096 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8A6FC99BA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9110, FileId: 0x1f000000033737, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.213 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB9955B9EB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9114, FileId: 0x1700000003377a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.244 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj052BD098E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9117, FileId: 0x1a000000033738, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:46.909 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj55A6A3950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9145, FileId: 0x1d000000033738, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:47.193 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB5FA29985. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9154, FileId: 0x21000000033738, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:47.224 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDD5F8E9DB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9155, FileId: 0x160000000337fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:47.232 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0A5DCA9A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9156, FileId: 0x170000000337fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:52:49.642 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #9242, FileId: 0x270000000336bd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:53:00.518 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9553, FileId: 0x31000000033701, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:53:00.627 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9559, FileId: 0x1b000000033706, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:53:00.721 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9563, FileId: 0x1a000000033715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0xb95e7900 2026-05-27T09:53:09.534 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:15056:134243491893518094) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:53:44.033 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-27T09:54:00.862 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #11283, FileId: 0x2c000000036a48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:54:11.433 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #11419, FileId: 0xa0000000376f9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:54:11.734 [RTP] [Mini-filter] OpenWithoutRead notification (1032, 10004, \Device\HarddiskVolume3\Windows\System32\WindowsPowerShell\v1.0\powershell.exe) sent successfully. 2026-05-27T09:54:18.717 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:10868:134243492576809380) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 05-27-2026 09:55:09 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 05/27/2026 09:55:09.769044200 UTC (14484 ms since boot) 2026-05-27T09:55:09.768 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-05-27T09:55:09.768 WARNING: the previous service shutdown was not expected. 2026-05-27T09:55:09.783 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:55:09.783 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:55:09.814 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260527-095509-00000003-fffffffeffffffff.bin ... 2026-05-27T09:55:09.908 [WPP] Trace session started - MpWppTracing-20260527-095509-00000003-fffffffeffffffff.bin 2026-05-27T09:55:09.908 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-05-27T09:55:09.908 [RbM] Rollback manager succesfully initialized. 2026-05-27T09:55:09.908 [RbM] Rollback manager EnableRollbackManager called. 2026-05-27T09:55:09.924 [RbM] Rollback manager EnableRollbackManager completed. 2026-05-27T09:55:09.924 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-05-27T09:55:09.924 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-05-27T09:55:09.924 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-05-27T09:55:09.924 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-05-27T09:55:09.924 MdCoreSvc is supported in this platform and OS 2026-05-27T09:55:09.924 MdCoreSvc is supported in this platform and OS 2026-05-27T09:55:09.924 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-27T09:55:09.924 [PlatUpd] Starting MdCoreSvc service 2026-05-27T09:55:09.986 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-05-27T09:55:14.097 [PlatUpd] MpAddMpUxRegistration succeeded 2026-05-27T09:55:14.097 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-05-27T09:55:14.097 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-05-27T09:55:14.097 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-05-27T09:55:14.097 [PlatUpd] CSP platform update started 2026-05-27T09:55:14.097 [PlatUpd] Defender MDM CSP platform update not required 2026-05-27T09:55:14.097 [PlatUpd] WMI/PS provider platform update started 2026-05-27T09:55:14.097 [PlatUpd] WMI/PS provider platform update not required 2026-05-27T09:55:14.097 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-05-27T09:55:14.097 MdCoreSvc is supported in this platform and OS 2026-05-27T09:55:14.097 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-05-27T09:55:14.097 [PlatUpd] Starting MdCoreSvc service 2026-05-27T09:55:14.097 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-05-27T09:55:14.097 [TS] Troubleshooting mode is not available! 2026-05-27T09:55:14.097 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-27T09:55:14.097 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-05-27T09:55:14.112 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-05-27T09:55:14.112 [Service] Enabling AutoLoggers ... 2026-05-27T09:55:14.112 [Service] Enabling AMSI registration ... 2026-05-27T09:55:14.112 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-05-27T09:55:14.128 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 47364 Number of invalid entries is 0 Number of inserts issued is 1590969 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6555 Number of lookups is 108656717 Number of lookup misses is 5217080 Number of fast lookup misses is 55361489 Number of false fast lookups is 5217075 Number of invalidations is 737077 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-05-27T09:55:14.128 Verifying license file... 2026-05-27T09:55:14.128 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-05-27T09:55:14.143 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-05-27T09:55:14.143 Loaded module#0 MpComServer. 2026-05-27T09:55:14.143 Loaded module#1 StartupPolicies. 2026-05-27T09:55:14.143 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-05-27T09:55:14.143 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-27T09:55:14.143 COM server initialized successfully. 2026-05-27T09:55:14.159 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-05-27T09:55:14.175 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-05-27T09:55:14.175 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-05-27T09:55:14.190 [RTP] [RTP] FilterCommunicator object 0x000001B8F02A0F10 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-27T09:55:14.190 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-05-27T09:55:14.190 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:55:14.190 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:55:14.190 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-05-27T09:55:14.190 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-27T09:55:14.190 [RTP] [RTP] FilterCommunicator object 0x000001B8F02A1120 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-27T09:55:14.190 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-05-27T09:55:14.190 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-05-27T09:55:14.190 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-05-27T09:55:14.190 [RTP] [RTP] StartCommunication 0x000001B8F02A0F10 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-05-27T09:55:14.190 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-05-27T09:55:14.190 [init][RTP] RTPPlugin initialization completed 2026-05-27T09:55:14.190 OS boot count = 2 2026-05-27T09:55:14.190 OS Install = 0 2026-05-27T09:55:14.206 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-05-27T09:55:14.206 [KSL] Entering CKSLEngine::Initialize. 2026-05-27T09:55:14.206 [KSL] Leaving CKSLEngine::Initialize(0). 2026-05-27T09:55:14.206 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-05-27T09:55:14.206 [KSL] MpInstallKslD: hr=0x1 2026-05-27T09:55:14.206 [KSL] MpRegisterKslD: hr=0 2026-05-27T09:55:14.222 [KSL] MpStartKslD: hr=0 2026-05-27T09:55:14.222 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-27T09:55:14.222 Loading engine... 2026-05-27T09:55:14.237 Verifying engine and signature files (source: 1) ... 2026-05-27T09:55:14.237 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpengine.dll] due to PPL. 2026-05-27T09:55:14.237 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasbase.vdm] (file in cache) 2026-05-27T09:55:14.237 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasdlta.vdm] (file in cache) 2026-05-27T09:55:14.237 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavbase.vdm] (file in cache) 2026-05-27T09:55:14.237 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpavdlta.vdm] (file in cache) 2026-05-27T09:55:14.268 [Engine] IsHybridMode: 0 2026-05-27T09:55:14.268 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-27T09:55:14.284 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-3EBACC38152AB85E586C23D079F4AEBA25612494.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-27T09:55:18.175 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-27T09:55:18.175 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-27T09:55:18.175 [Engine] New active engine 00007FF95B375810 (no old engine). Number of active engines: 1 2026-05-27T09:55:18.190 EngineInit:Global ASOC is enabled 2026-05-27T09:55:18.190 EngineInit:ASOO is enabled for developer volumes 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:55:18.253 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.268 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T09:55:18.284 MpWriteUupSignatureVersion 1.451.125.0, hr = 0 2026-05-27T09:55:18.284 [SigStatUpd] CSignatureStatus: back to good 2026-05-27T09:55:18.284 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-27T09:55:18.300 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-27T09:55:18.300 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T09:55:18.300 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-27T09:55:18.300 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-27T09:55:18.300 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T09:55:18.315 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-27T09:55:18.315 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2128 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12410 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2293 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-27T09:55:18.315 [Plugin] Initializing RTP plugin state... 2026-05-27T09:55:18.315 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-27T09:55:18.315 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C} 2026-05-27T09:55:18.315 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:55:18.315 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:55:18.315 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T09:55:18.315 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T09:55:18.315 MdCoreSvc is supported in this platform and OS 2026-05-27T09:55:18.315 Engine loaded! 2026-05-27T09:55:18.315 [DLP] Create FeatureControlState instance 2026-05-27T09:55:18.331 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-05-27T09:55:18.331 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-05-27T09:55:18.331 RegisterSModeChangeListener: hr = 0x1 2026-05-27T09:55:18.331 RegisterHybridModeChangeListener: hr = 0 2026-05-27T09:55:18.331 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-05-27T09:55:18.331 [SigReleaseHb] Initialized with Stage 0 2026-05-27T09:55:18.331 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-05-27T09:55:18.331 [SCC][CID=23046_5304] Initializing ... 2026-05-27T09:55:18.331 [SCC][CID=23046_5304] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-05-27T09:55:18.347 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-27T09:55:18.347 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-27T09:55:18.347 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T09:55:18.347 [NRI] Stopping NIS service ... 2026-05-27T09:55:18.347 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-05-27T09:55:18.347 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.451.125.0 AV Signature Version: 1.451.125.0 ************************************************************ 2026-05-27T09:55:18.347 Resource usage Monitoring is enabled 2026-05-27T09:55:18.347 Job Notification: New process added to job (4556) 2026-05-27T09:55:18.347 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-05-27T09:55:18.425 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-27T09:55:18.425 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-05-27T09:55:18.425 Job Notification: New process added to job (7872) 2026-05-27T09:55:18.425 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T09:55:18.425 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T09:55:18.425 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T09:55:18.425 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T09:55:18.425 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T09:55:18.425 [RTP] Generating the base plugin configuration ... 2026-05-27T09:55:18.425 [RTP] Path exclusion changed, new size in bytes: 2 2026-05-27T09:55:18.425 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:55:18.425 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-05-27T09:55:18.425 Job Notification: New process added to job (7884) 2026-05-27T09:55:18.425 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-05-27T09:55:18.425 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T09:55:18.425 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-27T09:55:18.425 [RTP] [RTP] StartCommunication 0x000001B8F02A1120 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-05-27T09:55:18.440 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-05-27T09:55:18.440 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7872] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7884]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T09:55:18.440 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.LanguageExperiencePackde-DE_22000.46.238.0_neutral__8wekyb3d8bbwe\Windows\System32\de-DE\9af0ce5665838739da392dd6078738f6\Conhost.exe.mui 2026-05-27T09:55:18.518 Job Notification: Process exited from job (7872) 2026-05-27T09:55:18.518 Job Notification: Process exited from job (7884) 2026-05-27T09:55:18.518 [PlatUpd] WMI MOF schema validation completed successfully 2026-05-27T09:55:18.769 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T09:55:18.784 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-27T09:55:18.784 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-27T09:55:18.784 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-27T09:55:21.331 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:55:21.331 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:55:21.331 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-05-27T09:55:21.331 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-27T09:55:21.331 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-05-27T09:55:36.472 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-05-27T09:55:38.346 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-05-27T09:55:40.018 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-05-27T09:55:48.753 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:9272:134243493430552185) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:55:48.769 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:10444:134243493435517567) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:55:48.784 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:9632:134243493431280337) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:56:08.190 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2599, FileId: 0x240000000687e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:56:14.159 Process scan (poststartupscan) started. 2026-05-27T09:56:14.159 Process scan (poststartupscan) completed. 2026-05-27T09:56:14.690 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-27T09:56:14.706 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-27T09:56:17.469 [RTP] Duplicating the current plugin configuration object... 2026-05-27T09:56:17.469 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T09:56:17.469 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-05-27T09:56:17.470 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-27T09:56:17.470 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-05-27T09:56:21.836 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3189, FileId: 0x46000000075411, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:57:08.925 [RTP] [Mini-filter] OpenWithoutRead notification (6108, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-05-27T09:57:13.206 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T09:57:13.222 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T09:57:13.222 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T09:57:25.315 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:3796:134243494442985104) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:58:09.867 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.70\msedgewebview2.exe (PPID:13660:134243494896526787) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-05-27T09:59:32.300 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\GEEK.EXE-30F57974.pf. Process: \Device\HarddiskVolume3\Users\ITHAN\Desktop\geek.exe, Status: 0xc000004b, State: 0, ScanRequest #12750, FileId: 0x1e0000000243c9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:59:33.768 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\update[1].txt. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\geek64.exe, Status: 0xc0000001, State: 0, ScanRequest #12791, FileId: 0xc00000000104af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T09:59:43.581 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.581 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.581 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.581 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.597 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.612 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T09:59:43.628 Engine:Process 12356 will be fully monitored because of injection from C:\Program Files\Mozilla Firefox\firefox.exe 2026-05-27T10:00:18.222 [RbM] Setting Last known good engine candidate. hr = 0 2026-05-27T10:00:18.346 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T10:00:36.956 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #12991, FileId: 0x43000000041d55, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:05:00.128 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-05-27T10:05:00.128 [RTP] Duplicating the current plugin configuration object... 2026-05-27T10:05:00.128 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T10:05:00.128 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\Users\desktop.ini 2026-05-27T10:05:00.128 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-27T10:05:00.128 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-27T10:05:00.128 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-27T10:05:00.612 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\$RECYCLE.BIN\S-1-5-21-3855297717-2871178096-3121473446-1002\desktop.ini 2026-05-27T10:05:18.331 Timer callback: Initializating/verifying scheduled tasks ... 2026-05-27T10:05:18.331 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-05-27T10:05:18.362 Job Notification: New process added to job (6164) 2026-05-27T10:05:18.378 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-05-27T10:05:18.378 Aggressive catchup quick scan threshold: 7462882117875 / 25920000000000 2026-05-27T10:05:18.378 Job Notification: New process added to job (7748) 2026-05-27T10:05:18.393 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:6164] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7748]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T10:05:18.456 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 53535541(ms) from now at 02:57 (00:57 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-27T10:05:18.487 Job Notification: New process added to job (8064) 2026-05-27T10:05:18.487 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-05-27T10:05:18.487 Job Notification: New process added to job (4076) 2026-05-27T10:05:18.503 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:8064] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4076]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-05-27T10:05:18.893 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-27T10:05:18.893 [RTP] Duplicating the current plugin configuration object... 2026-05-27T10:05:18.893 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T10:05:18.893 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-27T10:05:18.893 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T10:05:18.893 [RTP] No config change detected. Not updating plugin configuration. 2026-05-27T10:05:18.893 [RTP] No config changes found. No configuration switch. 2026-05-27T10:05:18.893 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-27T10:05:34.407 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\D35624B4-8914-4BEC-A3D9-651E9EA4EE17ccc.1dcedc05ada2b59 2026-05-27T10:05:34.503 Verifying engine and signature files (source: 0) ... 2026-05-27T10:05:34.503 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpengine.dll] due to PPL. 2026-05-27T10:05:34.503 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpasbase.vdm] (file in cache) 2026-05-27T10:05:34.503 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-27T10:05:34.566 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpasdlta.vdm] 2026-05-27T10:05:34.566 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpavbase.vdm] (file in cache) 2026-05-27T10:05:34.566 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-27T10:05:34.644 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD}\mpavdlta.vdm] 2026-05-27T10:05:34.847 [Engine] IsHybridMode: 0 2026-05-27T10:05:34.847 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-27T10:05:34.847 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-682DF1254DF5BB1A945AACEDDAE298F47C1ED823.bin): 0x00000002 2026-05-27T10:05:34.847 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-682DF1254DF5BB1A945AACEDDAE298F47C1ED823.bin) 2026-05-27T10:05:34.847 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-27T10:05:34.847 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-27T10:05:34.847 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-27T10:05:34.847 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-27T10:05:45.581 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-27T10:05:45.581 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-27T10:05:45.597 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF95B375810, lRefCount: 5, hr=0 2026-05-27T10:05:45.597 [Engine] New active engine 00007FF941615810 replacing engine 00007FF95B375810. Number of active engines: 2 2026-05-27T10:05:45.597 EngineInit:Global ASOC is enabled 2026-05-27T10:05:45.597 EngineInit:ASOO is enabled for developer volumes 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.659 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T10:05:45.675 MpWriteUupSignatureVersion 1.451.126.0, hr = 0 2026-05-27T10:05:45.675 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-05-27T10:05:45.690 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-05-27T10:05:45.690 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-05-27T10:05:45.690 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-05-27T10:05:45.690 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-05-27T10:05:45.690 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T10:05:45.722 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-05-27T10:05:45.722 [Plugin] Initializing RTP plugin state... 2026-05-27T10:05:45.722 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-05-27T10:05:45.722 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎05‎-‎27‎-‎2026 11:55:18 Last Perf:‎05‎-‎27‎-‎2026 11:55:18 First RTP Scan:‎05‎-‎27‎-‎2026 11:55:18 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2346 Misses:10576 BM Queue:0,368,0 Proc:0,262,0 File:0,337,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:13469 Pending:0 RegSize:308276 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:23597397 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6559 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:32002 TotalHits:22009 InstanceCacheInserts:509 InstanceCacheUpdates:0 InstanceCacheDeletes:139 InstanceCacheHits:5 InstanceCacheMisses:15782 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (864/243) Success: 243, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-05-27T10:05:45.722 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F571085C-56DF-4240-ACF3-7022D7F79CCD} 2026-05-27T10:05:45.722 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C}\mpasbase.vdm in use, hr=0x80070020 2026-05-27T10:05:45.722 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{898AAF8C-7B44-4E3C-95C3-60EA3E5E7B77} removed 2026-05-27T10:05:45.722 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:05-27-2026 10:05:45 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-27-2026 10:05:45 2026-05-27T10:05:45.722 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-05-27T10:05:45.722 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-05-27T10:05:45.722 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T10:05:45.722 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-05-27T10:05:45.722 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-05-27T10:05:45.722 MdCoreSvc is supported in this platform and OS Signature updated on 05-27-2026 10:05:45 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.451.126.0 AV Signature Version: 1.451.126.0 ************************************************************ 2026-05-27T10:05:45.737 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-05-27T10:05:45.737 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\D35624B4-8914-4BEC-A3D9-651E9EA4EE17ccc.1dcedc05ada2b59 2026-05-27T10:05:45.800 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-05-27T10:05:45.815 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 05-27-2026 10:05:45 ************************************************************ 2026-05-27T10:05:45.831 Job Notification: Process exited from job (8064) 2026-05-27T10:05:45.847 Job Notification: Process exited from job (4076) 2026-05-27T10:05:45.909 Job Notification: Process exited from job (6164) 2026-05-27T10:05:45.909 Job Notification: Process exited from job (7748) 2026-05-27T10:05:46.159 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T10:05:46.159 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T10:05:46.159 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T10:05:46.159 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T10:05:46.159 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T10:05:46.175 [Engine] Engine 00007FF95B375810 no longer in use. Number of active engines: 1 2026-05-27T10:05:46.175 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T10:05:46.175 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-05-27T10:05:46.175 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-05-27T10:05:46.175 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-05-27T10:05:46.175 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-05-27T10:05:46.268 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 22267, Count: 43, MaxTime: 4890, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 40% 2026-05-27T10:05:46.268 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 7355, Count: 170, MaxTime: 1328, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 1% 2026-05-27T10:05:46.268 ProcessImageName: geek64.exe, Pid: 4708, TotalTime: 3712, Count: 51, MaxTime: 1437, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\OneDriveSetup.exe, EstimatedImpact: 5% 2026-05-27T10:05:46.268 ProcessImageName: AsPowerBar.exe, Pid: 14220, TotalTime: 2413, Count: 18, MaxTime: 953, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 38% 2026-05-27T10:05:46.268 ProcessImageName: DipAwayMode.exe, Pid: 7692, TotalTime: 2166, Count: 15, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 4% 2026-05-27T10:05:46.268 ProcessImageName: TeamViewer.exe, Pid: 7584, TotalTime: 2157, Count: 68, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 15% 2026-05-27T10:05:46.268 ProcessImageName: MOM.exe, Pid: 12640, TotalTime: 1929, Count: 31, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 41% 2026-05-27T10:05:46.268 ProcessImageName: dllhost.exe, Pid: 10220, TotalTime: 1708, Count: 62, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\9V85I3X3NW_35, EstimatedImpact: 35% 2026-05-27T10:05:46.268 ProcessImageName: AISuite3.exe, Pid: 7708, TotalTime: 1461, Count: 23, MaxTime: 625, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 4% 2026-05-27T10:05:46.268 ProcessImageName: websockify.exe, Pid: 12848, TotalTime: 866, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\_ssl.pyd, EstimatedImpact: 45% 2026-05-27T10:05:46.268 ProcessImageName: TeamViewer_Service.exe, Pid: 4472, TotalTime: 669, Count: 6, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 12% 2026-05-27T10:05:46.268 ProcessImageName: WhatsApp.Root.exe, Pid: 11224, TotalTime: 271, Count: 34, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\OneSettings\SCCInstallService.json, EstimatedImpact: 1% 2026-05-27T10:05:46.268 ProcessImageName: FileCoAuth.exe, Pid: 12060, TotalTime: 271, Count: 23, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-05-27T10:05:46.268 ProcessImageName: backgroundTaskHost.exe, Pid: 4740, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1779875481, EstimatedImpact: 34% 2026-05-27T10:05:46.284 [Engine] RSIG_UNLOADENGINE, 00007FF95B375810, err=0x0 2026-05-27T10:05:46.300 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{408F1E3E-EFDB-4CA1-9D84-889FB5055C1C} removed 2026-05-27T10:05:47.737 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:05:47.737 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:05:47.737 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:06:14.164 Process scan (postsignatureupdatescan) started. 2026-05-27T10:06:18.809 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-05-27T10:06:33.669 Process scan (postsignatureupdatescan) completed. 2026-05-27T10:07:36.581 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF3EEF198B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14240, FileId: 0x20000000011b0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:36.581 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7C6D34982. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14241, FileId: 0x3e00000000fbbb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:36.581 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE32BED9EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14237, FileId: 0x1f000000011b0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:36.628 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF53273934. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14246, FileId: 0x21000000011b0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:36.659 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj27C0D39F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14249, FileId: 0x22000000011b0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:37.211 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5CF382907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14298, FileId: 0x2a0000000129fa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:37.274 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C2CE3984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14310, FileId: 0x8f000000012a05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:37.305 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj22FB80970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14326, FileId: 0x90000000012a05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:37.321 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj00B8F79A6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14327, FileId: 0x91000000012a05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:51.175 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14530, FileId: 0x10e000000004582, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:51.253 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14532, FileId: 0x2f000000006719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:07:51.331 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14538, FileId: 0x60000000010b12, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:08:51.487 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14544, FileId: 0x114000000004582, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:10:27.628 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\fb6911234\fb6911234\TOSHIBA-ExternalUSB3-0-01\Breitbandmessung.lnk 2026-05-27T10:10:39.909 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #14809, FileId: 0x49400000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:10:45.659 [RbM] Setting Last known good engine candidate. hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0x2f9ef1ae 2026-05-27T10:14:19.362 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:14:19.362 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:14:19.362 [Cloud] Queued cloud request. 2026-05-27T10:14:19.362 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:14:19.362 [Cloud] Dequeued cloud request. 2026-05-27T10:14:19.362 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:14:19.972 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7b3f1ad566e7c7267a624b0184187fc1e8179276 Dynamic Signature Compilation Timestamp:05-27-2026 10:14:18 Persistence Type:Duration Time remaining:288000000 2026-05-27T10:14:19.972 [Cloud] End of cloud request. 2026-05-27T10:14:19.972 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T10:14:20.472 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0xcde079c7 2026-05-27T10:14:37.034 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:14:37.034 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:14:37.034 [Cloud] Queued cloud request. 2026-05-27T10:14:37.034 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:14:37.034 [Cloud] Dequeued cloud request. 2026-05-27T10:14:37.034 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:14:37.487 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1ed8c81f5464460171b54c123d7f3f952c6de461 Dynamic Signature Compilation Timestamp:05-27-2026 10:14:36 Persistence Type:Duration Time remaining:288000000 2026-05-27T10:14:37.487 [Cloud] End of cloud request. 2026-05-27T10:14:37.487 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T10:14:38.003 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0xcf6e93ce 2026-05-27T10:14:41.878 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:14:41.878 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:14:41.878 [Cloud] Queued cloud request. 2026-05-27T10:14:41.878 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:14:41.878 [Cloud] Dequeued cloud request. 2026-05-27T10:14:41.878 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:14:42.409 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\05df45b2e71827fd5ab24388568aa0c243890ff9 Dynamic Signature Compilation Timestamp:05-27-2026 10:14:41 Persistence Type:Duration Time remaining:288000000 2026-05-27T10:14:42.409 [Cloud] End of cloud request. 2026-05-27T10:14:42.409 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T10:14:42.925 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0xd24d8122 2026-05-27T10:14:51.253 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:14:51.253 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:14:51.253 [Cloud] Queued cloud request. 2026-05-27T10:14:51.253 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:14:51.253 [Cloud] Dequeued cloud request. 2026-05-27T10:14:51.253 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:14:51.940 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\da5dfb00059e4383b305dee74e12745f4392faab Dynamic Signature Compilation Timestamp:05-27-2026 10:14:50 Persistence Type:Duration Time remaining:288000000 2026-05-27T10:14:51.940 [Cloud] End of cloud request. 2026-05-27T10:14:51.940 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T10:14:52.440 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0x75bea492 2026-05-27T10:15:05.519 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:15:05.519 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:15:05.519 [Cloud] Queued cloud request. 2026-05-27T10:15:05.519 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:15:05.519 [Cloud] Dequeued cloud request. 2026-05-27T10:15:05.519 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:15:05.941 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\36c09f1d251c55a1e55677b4d0525019b9e04851 Dynamic Signature Compilation Timestamp:05-27-2026 10:15:04 Persistence Type:Duration Time remaining:288000000 2026-05-27T10:15:05.941 [Cloud] End of cloud request. 2026-05-27T10:15:05.941 RTSD:RTSD recieved, rescanning impacted resources 2026-05-27T10:15:06.456 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00002FE771898D97, sigsha=f5ad8a41a2152c9c042f233d085f9a954e0131d7, cached=false, source=2, resourceid=0x9818efad 2026-05-27T10:15:22.347 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-05-27T10:15:22.347 [Cloud] Start of cloud request. Passive mode: 0 2026-05-27T10:15:22.347 [Cloud] Queued cloud request. 2026-05-27T10:15:22.347 [Cloud] MpEngineCloudRequest(). hr = 0 2026-05-27T10:15:22.347 [Cloud] Dequeued cloud request. 2026-05-27T10:15:22.347 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-05-27T10:15:22.753 [Cloud] End of cloud request. 2026-05-27T10:15:22.753 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\WSH Shell\shortcut.vbs. status=0x40070000, statusex=0x200210, threatid=0x80000000, sigseq=0x2fe771898d97 2026-05-27T10:15:23.268 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T10:15:23.331 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T10:17:51.394 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15536, FileId: 0x11000000036b35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:17:51.409 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15538, FileId: 0x2100000008fc36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:18:03.315 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #15643, FileId: 0x2200000008f917, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:28:28.425 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #18117, FileId: 0x5100000000b883, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:28:34.785 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-27T10:28:34.785 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-27T10:28:34.801 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-27T10:28:34.801 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-27T10:28:34.801 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-27T10:28:34.801 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:ECA4CB53-EDDE-4F46-8E79-D2949D404C25, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-27T10:28:34.801 Scheduled scan with Id ECA4CB53-EDDE-4F46-8E79-D2949D404C25 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-27T10:28:34.801 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-27T10:28:34.801 [SFC] System file cache build is not needed (already completed) 2026-05-27T10:28:34.910 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-05-27T10:28:34.926 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libaudiobargraph_a_plugin.dll", hr=0x0 2026-05-27T10:28:35.176 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\misc\libgnutls_plugin.dll", hr=0x0 2026-05-27T10:28:35.301 Engine:Setting original file name "grb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\grb.rs.mui", hr=0x0 2026-05-27T10:28:35.441 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_pl-pl_4e97c380224fe5bf\pl-pl_bitlockertogo.exe.mui", hr=0x0 2026-05-27T10:28:35.488 Engine:Setting original file name "powershell.exe" for "c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-05-27T10:28:35.613 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.22000.1_de-de_f2163101a039bd0d\rdpsign.exe.mui", hr=0x0 2026-05-27T10:28:35.785 Engine:Setting original file name "atiuxpag.dll" for "c:\windows\system32\atiuxp64.dll", hr=0x0 2026-05-27T10:28:35.863 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_synch_l1_1_0.dll", hr=0x0 2026-05-27T10:28:36.269 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libextract_plugin.dll", hr=0x0 2026-05-27T10:28:36.801 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x0 2026-05-27T10:28:36.801 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:28:36.816 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:28:36.816 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:28:36.816 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-27T10:28:37.051 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:37.144 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_smem_plugin.dll", hr=0x0 2026-05-27T10:28:37.441 Engine:Setting original file name "bluetooth.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\665dc8659816c4b74a6b6286f2d19fbf\bthprops.cpl.mui", hr=0x0 2026-05-27T10:28:38.024 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-05-27T10:28:38.446 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-05-27T10:28:38.571 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-05-27T10:28:38.602 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-05-27T10:28:38.618 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1426.11910.dll", hr=0x800710da 2026-05-27T10:28:39.118 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-05-27T10:28:39.196 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-05-27T10:28:39.352 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-27T10:28:39.368 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-05-27T10:28:39.758 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-05-27T10:28:39.805 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-05-27T10:28:39.868 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-05-27T10:28:40.040 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-05-27T10:28:40.227 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-05-27T10:28:40.399 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-05-27T10:28:40.571 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-27T10:28:40.571 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:40.618 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-05-27T10:28:40.712 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-05-27T10:28:40.774 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-05-27T10:28:41.180 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-05-27T10:28:41.462 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-05-27T10:28:41.493 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-05-27T10:28:41.883 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-05-27T10:28:42.071 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-05-27T10:28:42.633 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:42.665 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-27T10:28:42.743 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:43.118 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-27T10:28:43.243 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-27T10:28:43.477 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-05-27T10:28:43.712 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-05-27T10:28:43.790 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-05-27T10:28:43.805 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-05-27T10:28:43.852 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-27T10:28:44.102 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-05-27T10:28:44.180 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-27T10:28:44.321 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-05-27T10:28:44.446 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-05-27T10:28:44.998 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-05-27T10:28:45.014 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-05-27T10:28:45.311 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-27T10:28:45.373 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-05-27T10:28:45.811 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.gamingapp_2605.1001.12.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-05-27T10:28:45.967 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-05-27T10:28:46.092 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-05-27T10:28:46.092 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-05-27T10:28:46.092 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-05-27T10:28:46.186 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-05-27T10:28:46.279 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-05-27T10:28:46.404 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-05-27T10:28:46.779 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-05-27T10:28:47.029 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-05-27T10:28:47.061 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:47.076 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-05-27T10:28:47.123 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-05-27T10:28:47.154 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\nmhproxy.exe", hr=0x0 2026-05-27T10:28:47.264 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-27T10:28:47.342 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-05-27T10:28:47.373 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-05-27T10:28:47.451 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-05-27T10:28:47.717 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\systemresources\themecpl.dll.mun", hr=0x800710da 2026-05-27T10:28:47.889 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-05-27T10:28:47.904 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-05-27T10:28:48.108 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:48.154 Engine:Setting original file name "riched20_standalone.dll" for "c:\program files\windowsapps\microsoft.windowsnotepad_11.2512.29.0_x64__8wekyb3d8bbwe\notepad\riched20.dll", hr=0x800710da 2026-05-27T10:28:48.217 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-05-27T10:28:48.842 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-05-27T10:28:48.998 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-05-27T10:28:48.998 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-05-27T10:28:49.061 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-27T10:28:49.342 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-05-27T10:28:49.358 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-05-27T10:28:49.686 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-05-27T10:28:49.779 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-05-27T10:28:49.795 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-05-27T10:28:49.904 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-05-27T10:28:49.920 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-05-27T10:28:49.951 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-05-27T10:28:50.358 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-05-27T10:28:50.404 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-27T10:28:50.529 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-05-27T10:28:50.561 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-05-27T10:28:50.717 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-05-27T10:28:50.873 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-05-27T10:28:50.936 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-05-27T10:28:51.029 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-05-27T10:28:51.154 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-05-27T10:28:51.451 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:51.717 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-05-27T10:28:51.764 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-05-27T10:28:51.779 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-05-27T10:28:51.858 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:52.311 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:52.404 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:52.904 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-05-27T10:28:52.951 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-05-27T10:28:53.108 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-05-27T10:28:53.201 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-05-27T10:28:53.248 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-05-27T10:28:53.264 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-05-27T10:28:53.654 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-05-27T10:28:53.733 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-05-27T10:28:53.826 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-05-27T10:28:53.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-05-27T10:28:53.936 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-05-27T10:28:54.045 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-05-27T10:28:54.186 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-05-27T10:28:54.311 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-05-27T10:28:54.389 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-05-27T10:28:54.404 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-05-27T10:28:54.420 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-05-27T10:28:54.654 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-05-27T10:28:54.670 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-05-27T10:28:54.831 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-05-27T10:28:55.346 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-05-27T10:28:55.628 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-05-27T10:28:55.690 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-05-27T10:28:56.128 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-05-27T10:28:56.206 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-05-27T10:28:56.268 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-05-27T10:28:56.378 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-05-27T10:28:56.487 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-05-27T10:28:56.503 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-05-27T10:28:56.659 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-05-27T10:28:56.893 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-05-27T10:28:56.893 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-05-27T10:28:57.112 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-05-27T10:28:57.237 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-05-27T10:28:57.581 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-05-27T10:28:57.690 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-05-27T10:28:57.831 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-05-27T10:28:58.174 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11020.20001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-05-27T10:28:58.253 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-05-27T10:28:58.284 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-05-27T10:28:58.440 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-05-27T10:28:58.456 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-27T10:28:58.581 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-05-27T10:28:58.643 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-05-27T10:28:58.815 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-05-27T10:28:58.924 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-05-27T10:28:58.924 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:28:59.206 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-05-27T10:28:59.487 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-05-27T10:28:59.518 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-05-27T10:28:59.612 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-27T10:28:59.721 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-05-27T10:29:00.018 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-05-27T10:29:00.128 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-27T10:29:00.159 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-05-27T10:29:00.284 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:29:00.862 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-05-27T10:29:01.003 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-05-27T10:29:01.112 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-05-27T10:29:01.503 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-05-27T10:29:01.534 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-05-27T10:29:01.550 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-05-27T10:29:01.878 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-05-27T10:29:02.175 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-05-27T10:29:02.206 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-05-27T10:29:02.362 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-05-27T10:29:02.534 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-05-27T10:29:02.550 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-05-27T10:29:02.784 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-05-27T10:29:03.550 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-05-27T10:29:03.831 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-05-27T10:29:04.159 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-27T10:29:04.659 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-05-27T10:29:04.722 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-05-27T10:29:04.737 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-05-27T10:29:04.815 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-05-27T10:29:05.237 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x800710da 2026-05-27T10:29:05.456 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-05-27T10:29:05.628 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-05-27T10:29:05.722 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-05-27T10:29:05.753 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-05-27T10:29:05.925 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-05-27T10:29:06.112 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-05-27T10:29:06.143 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-27T10:29:06.331 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:29:06.456 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-05-27T10:29:06.675 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-05-27T10:29:06.800 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-05-27T10:29:06.909 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-05-27T10:29:07.190 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-05-27T10:29:07.237 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-05-27T10:29:07.331 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-05-27T10:29:08.222 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-05-27T10:29:08.675 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-05-27T10:29:08.722 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-27T10:29:08.815 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-05-27T10:29:08.847 Engine:Setting original file name "digsig32.dll" for "c:\program files\microsoft office\root\office16\exsec32.dll", hr=0x800710da 2026-05-27T10:29:09.597 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-05-27T10:29:10.372 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-05-27T10:29:10.450 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-05-27T10:29:10.669 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-05-27T10:29:10.934 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-05-27T10:29:10.981 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-05-27T10:29:11.403 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-05-27T10:29:11.497 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-05-27T10:29:11.575 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-05-27T10:29:11.622 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-05-27T10:29:11.763 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-05-27T10:29:12.294 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-05-27T10:29:12.591 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-05-27T10:29:12.684 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-05-27T10:29:12.731 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-05-27T10:29:13.450 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-27T10:29:13.856 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-05-27T10:29:14.028 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-05-27T10:29:14.341 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-05-27T10:29:14.481 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-05-27T10:29:14.841 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-05-27T10:29:14.856 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-05-27T10:29:14.919 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-05-27T10:29:15.075 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-05-27T10:29:15.169 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-05-27T10:29:15.278 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-05-27T10:29:15.388 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-05-27T10:29:15.419 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-05-27T10:29:15.434 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-05-27T10:29:15.481 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-05-27T10:29:15.497 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-05-27T10:29:15.825 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-27T10:29:15.841 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-05-27T10:29:15.888 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-27T10:29:16.044 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-05-27T10:29:16.184 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-05-27T10:29:16.481 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-05-27T10:29:16.809 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-05-27T10:29:17.122 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-05-27T10:29:17.278 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-05-27T10:29:17.684 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\systemresources\moricons.dll.mun", hr=0x800710da 2026-05-27T10:29:17.716 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2605.1001.12.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-05-27T10:29:18.028 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-05-27T10:29:18.278 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-05-27T10:29:18.669 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-05-27T10:29:18.856 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-05-27T10:29:19.278 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-05-27T10:29:19.388 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-05-27T10:29:19.466 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-05-27T10:29:19.481 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-05-27T10:29:19.497 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-05-27T10:29:19.575 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-05-27T10:29:19.970 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-05-27T10:29:19.970 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-05-27T10:29:20.720 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-05-27T10:29:20.861 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-05-27T10:29:21.595 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-05-27T10:29:21.611 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-05-27T10:29:21.939 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-05-27T10:29:22.001 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-05-27T10:29:22.064 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-05-27T10:29:22.533 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-05-27T10:29:22.642 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-05-27T10:29:23.079 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-05-27T10:29:23.501 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-05-27T10:29:23.564 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-05-27T10:29:23.829 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-05-27T10:29:24.158 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-05-27T10:29:24.283 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-05-27T10:29:24.314 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-05-27T10:29:24.595 Engine:Setting original file name "WebInstaller.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrocef\singleclientservicesupdater.exe", hr=0x800710da 2026-05-27T10:29:24.642 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-05-27T10:29:24.736 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-05-27T10:29:24.767 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-05-27T10:29:24.876 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-05-27T10:29:25.001 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-05-27T10:29:25.267 Engine:Setting original file name "Microsoft.Management.Deployment.OutOfProc.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\microsoft.management.deployment.dll", hr=0x800710da 2026-05-27T10:29:25.298 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-05-27T10:29:25.345 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-05-27T10:29:26.236 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-05-27T10:29:26.579 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-05-27T10:29:26.689 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:29:26.829 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-05-27T10:29:27.392 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-05-27T10:29:27.517 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-05-27T10:29:27.564 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-05-27T10:29:27.626 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-05-27T10:29:27.720 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-05-27T10:29:27.736 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:29:27.908 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-05-27T10:29:28.001 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-05-27T10:29:28.142 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-05-27T10:29:28.204 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-05-27T10:29:28.329 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-05-27T10:29:28.470 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-05-27T10:29:28.829 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-05-27T10:29:28.939 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-05-27T10:29:29.142 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-05-27T10:29:29.439 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-05-27T10:29:29.548 Engine:Setting original file name "PUB6INTL.DLL" for "c:\program files\microsoft office\root\office16\pub6intl.common.dll", hr=0x800710da 2026-05-27T10:29:30.021 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-05-27T10:29:30.115 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-05-27T10:29:30.479 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-05-27T10:29:30.963 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-05-27T10:29:31.370 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-05-27T10:29:31.448 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-05-27T10:29:31.479 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-05-27T10:29:31.838 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-05-27T10:29:31.995 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-05-27T10:29:32.135 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-05-27T10:29:32.885 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-05-27T10:29:33.198 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-05-27T10:29:33.229 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-05-27T10:29:33.307 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-05-27T10:29:33.323 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-05-27T10:29:33.370 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-05-27T10:29:33.979 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-05-27T10:29:34.041 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-05-27T10:29:34.120 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-05-27T10:29:34.479 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-05-27T10:29:34.510 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-05-27T10:29:34.901 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-05-27T10:29:34.963 Engine:Setting original file name "Microsoft(r) DirectX for Windows(r) - Out Of Band" for "c:\program files (x86)\microsoft\edgewebview\application\148.0.3967.70\dxil.dll", hr=0x800710da 2026-05-27T10:29:35.010 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-05-27T10:29:35.073 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-05-27T10:29:35.088 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-05-27T10:29:35.213 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2605.45031.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-05-27T10:29:35.276 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-05-27T10:29:35.916 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-05-27T10:29:36.182 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-05-27T10:29:36.291 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-05-27T10:29:36.354 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-05-27T10:29:36.651 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-05-27T10:29:36.776 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-05-27T10:29:37.182 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-05-27T10:29:37.182 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-05-27T10:29:37.198 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-05-27T10:29:37.479 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-05-27T10:29:37.760 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-05-27T10:29:37.885 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-05-27T10:29:38.120 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-05-27T10:29:38.260 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-05-27T10:29:38.370 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-05-27T10:29:38.401 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-05-27T10:29:38.463 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-05-27T10:29:39.526 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-05-27T10:29:39.666 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-05-27T10:29:39.729 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-05-27T10:29:39.948 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-05-27T10:29:39.995 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-05-27T10:29:40.104 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-05-27T10:29:40.182 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-05-27T10:29:40.370 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-05-27T10:29:40.401 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-05-27T10:29:40.432 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-05-27T10:29:40.620 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-05-27T10:29:40.666 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-05-27T10:29:40.776 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-05-27T10:29:40.807 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-05-27T10:29:40.823 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-05-27T10:29:41.166 OriginalFileName Maintenance::9781 files in Moac, 7 skipped (cached), 12 filename set 2026-05-27T10:29:41.166 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-27T10:29:45.719 Engine:Triggered AR EMS scan 2026-05-27T10:29:45.719 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.734 Engine:EMS scan for process: svchost pid: 964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.750 Engine:EMS scan for process: svchost pid: 688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.766 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.766 Engine:EMS scan for process: svchost pid: 1188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.781 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.781 Engine:EMS scan for process: svchost pid: 1380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.797 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.797 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.797 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.812 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.812 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.812 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.828 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.828 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.828 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.844 Engine:EMS scan for process: svchost pid: 1984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.844 Engine:EMS scan for process: svchost pid: 1108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.859 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.859 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.859 Engine:EMS scan for process: svchost pid: 2132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.859 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.875 Engine:EMS scan for process: svchost pid: 2376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.875 Engine:EMS scan for process: svchost pid: 2428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.891 Engine:EMS scan for process: svchost pid: 2436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.891 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.891 Engine:EMS scan for process: svchost pid: 2464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.891 Engine:EMS scan for process: svchost pid: 2644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.891 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.906 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.906 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.922 Engine:EMS scan for process: svchost pid: 3044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.922 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.937 Engine:EMS scan for process: svchost pid: 3140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.937 Engine:EMS scan for process: svchost pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.937 Engine:EMS scan for process: svchost pid: 3596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.953 Engine:EMS scan for process: svchost pid: 3732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.953 Engine:EMS scan for process: svchost pid: 3756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.969 Engine:EMS scan for process: svchost pid: 3840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.969 Engine:EMS scan for process: svchost pid: 3288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.969 Engine:EMS scan for process: svchost pid: 2936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.984 Engine:EMS scan for process: svchost pid: 4132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:45.984 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.000 Engine:EMS scan for process: svchost pid: 4192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.000 Engine:EMS scan for process: svchost pid: 4428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.016 Engine:EMS scan for process: svchost pid: 4440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.016 Engine:EMS scan for process: svchost pid: 4480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.031 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.031 Engine:EMS scan for process: svchost pid: 4800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.031 Engine:EMS scan for process: svchost pid: 5820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.047 Engine:EMS scan for process: dllhost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.047 Engine:EMS scan for process: svchost pid: 5900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.047 Engine:EMS scan for process: svchost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.062 Engine:EMS scan for process: svchost pid: 6232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.062 Engine:EMS scan for process: svchost pid: 6088, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.078 Engine:EMS scan for process: svchost pid: 7324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.078 Engine:EMS scan for process: svchost pid: 7432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.094 Engine:EMS scan for process: svchost pid: 7468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.094 Engine:EMS scan for process: svchost pid: 7824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.109 Engine:EMS scan for process: svchost pid: 2928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.109 Engine:EMS scan for process: explorer pid: 8236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.187 Engine:EMS scan for process: svchost pid: 8420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.187 Engine:EMS scan for process: svchost pid: 8556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.203 Engine:EMS scan for process: svchost pid: 8872, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.203 Engine:EMS scan for process: svchost pid: 8980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.203 Engine:EMS scan for process: svchost pid: 9024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.203 Engine:EMS scan for process: svchost pid: 9568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.219 Engine:EMS scan for process: dllhost pid: 10220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.219 Engine:EMS scan for process: svchost pid: 9408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.234 Engine:EMS scan for process: svchost pid: 14300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.234 Engine:EMS scan for process: svchost pid: 12120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.234 Engine:EMS scan for process: svchost pid: 6756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.250 Engine:EMS scan for process: svchost pid: 9032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.250 Engine:EMS scan for process: svchost pid: 1608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.266 Engine:EMS scan for process: svchost pid: 8368, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.266 Engine:EMS scan for process: svchost pid: 13996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.281 Engine:EMS scan for process: svchost pid: 6592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.281 Engine:EMS scan for process: svchost pid: 772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.281 Engine:EMS scan for process: svchost pid: 7840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.297 Engine:EMS scan for process: svchost pid: 11232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.297 Engine:EMS scan for process: svchost pid: 13852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.312 Engine:EMS scan for process: svchost pid: 8032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.312 Engine:EMS scan for process: svchost pid: 12548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:29:46.312 Engine:EMS scan for process: svchost pid: 8968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:30:28.345 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T10:31:32.082 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-05-27T10:31:32.082 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-05-27T10:31:32.082 [RTP] Duplicating the current plugin configuration object... 2026-05-27T10:31:32.082 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T10:31:32.082 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-05-27T10:31:32.082 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-05-27T10:31:32.082 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-05-27T10:31:33.315 RPC Rundown called on ScanID: ECA4CB53-EDDE-4F46-8E79-D2949D404C25 2026-05-27T10:31:33.315 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:ECA4CB53-EDDE-4F46-8E79-D2949D404C25. bRemoveFromList(ClientKilled):1 2026-05-27T10:31:33.315 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ECA4CB53-EDDE-4F46-8E79-D2949D404C25 2026-05-27T10:31:33.315 QuickScan:ScanID:ECA4CB53-EDDE-4F46-8E79-D2949D404C25: User scan error=000003e3 2026-05-27T10:31:33.331 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ECA4CB53-EDDE-4F46-8E79-D2949D404C25 2026-05-27T10:31:33.331 QuickScan:ScanID:ECA4CB53-EDDE-4F46-8E79-D2949D404C25: Quick scan aborted by callback after end stage 2026-05-27T10:31:33.331 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ECA4CB53-EDDE-4F46-8E79-D2949D404C25 2026-05-27T10:31:33.331 OnDemandScanWorker: Scan Cancelled! scanId:ECA4CB53-EDDE-4F46-8E79-D2949D404C25, hr = 0x80508018 2026-05-27T10:31:35.331 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:31:35.331 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:31:35.331 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:39:23.981 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:D1531A88-8797-4F95-BEBF-C57F134DAF93, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-27T10:39:23.981 Scheduled scan with Id D1531A88-8797-4F95-BEBF-C57F134DAF93 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-27T10:39:23.981 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-27T10:39:23.981 [SFC] System file cache build is not needed (already completed) 2026-05-27T10:39:25.996 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22144, FileId: 0x7f000000013011, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:39:25.996 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:39:26.012 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:39:26.012 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:39:28.809 Engine:Triggered AR EMS scan 2026-05-27T10:39:28.824 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.840 Engine:EMS scan for process: svchost pid: 964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.856 Engine:EMS scan for process: svchost pid: 688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.871 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.871 Engine:EMS scan for process: svchost pid: 1188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.887 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.887 Engine:EMS scan for process: svchost pid: 1380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.887 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.887 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.903 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.903 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.903 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.918 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.918 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.918 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.918 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.934 Engine:EMS scan for process: svchost pid: 1984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.934 Engine:EMS scan for process: svchost pid: 1108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.949 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.949 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.949 Engine:EMS scan for process: svchost pid: 2132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.949 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.965 Engine:EMS scan for process: svchost pid: 2376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.965 Engine:EMS scan for process: svchost pid: 2428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.965 Engine:EMS scan for process: svchost pid: 2436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.981 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.981 Engine:EMS scan for process: svchost pid: 2464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.981 Engine:EMS scan for process: svchost pid: 2644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.981 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.996 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:28.996 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.012 Engine:EMS scan for process: svchost pid: 3044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.012 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.012 Engine:EMS scan for process: svchost pid: 3140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.028 Engine:EMS scan for process: svchost pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.028 Engine:EMS scan for process: svchost pid: 3596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.028 Engine:EMS scan for process: svchost pid: 3732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.043 Engine:EMS scan for process: svchost pid: 3756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.043 Engine:EMS scan for process: svchost pid: 3840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.059 Engine:EMS scan for process: svchost pid: 3288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.059 Engine:EMS scan for process: svchost pid: 2936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.074 Engine:EMS scan for process: svchost pid: 4132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.074 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.090 Engine:EMS scan for process: svchost pid: 4192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.090 Engine:EMS scan for process: svchost pid: 4428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.106 Engine:EMS scan for process: svchost pid: 4440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.106 Engine:EMS scan for process: svchost pid: 4480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.121 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.121 Engine:EMS scan for process: svchost pid: 4800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.137 Engine:EMS scan for process: svchost pid: 5820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.137 Engine:EMS scan for process: dllhost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.137 Engine:EMS scan for process: svchost pid: 5900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.153 Engine:EMS scan for process: svchost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.153 Engine:EMS scan for process: svchost pid: 6232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.168 Engine:EMS scan for process: svchost pid: 6088, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.168 Engine:EMS scan for process: svchost pid: 7324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.184 Engine:EMS scan for process: svchost pid: 7432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.199 Engine:EMS scan for process: svchost pid: 7468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.199 Engine:EMS scan for process: svchost pid: 7824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.215 Engine:EMS scan for process: svchost pid: 2928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.231 Engine:EMS scan for process: explorer pid: 8236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.309 Engine:EMS scan for process: svchost pid: 8420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.309 Engine:EMS scan for process: svchost pid: 8556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.309 Engine:EMS scan for process: svchost pid: 8872, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.324 Engine:EMS scan for process: svchost pid: 8980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.324 Engine:EMS scan for process: svchost pid: 9024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.324 Engine:EMS scan for process: svchost pid: 9568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.340 Engine:EMS scan for process: dllhost pid: 10220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.340 Engine:EMS scan for process: svchost pid: 9408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.356 Engine:EMS scan for process: svchost pid: 14300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.356 Engine:EMS scan for process: svchost pid: 12120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.356 Engine:EMS scan for process: svchost pid: 6756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.356 Engine:EMS scan for process: svchost pid: 9032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.387 Engine:EMS scan for process: svchost pid: 1608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.387 Engine:EMS scan for process: svchost pid: 13996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.403 Engine:EMS scan for process: svchost pid: 7840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.403 Engine:EMS scan for process: svchost pid: 13852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.418 Engine:EMS scan for process: svchost pid: 12548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.418 Engine:EMS scan for process: svchost pid: 3820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:39:29.418 Engine:EMS scan for process: svchost pid: 6192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:41:41.199 RPC Rundown called on ScanID: D1531A88-8797-4F95-BEBF-C57F134DAF93 2026-05-27T10:41:41.199 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:D1531A88-8797-4F95-BEBF-C57F134DAF93. bRemoveFromList(ClientKilled):1 2026-05-27T10:41:41.199 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:D1531A88-8797-4F95-BEBF-C57F134DAF93 2026-05-27T10:41:41.199 QuickScan:ScanID:D1531A88-8797-4F95-BEBF-C57F134DAF93: User scan error=000003e3 2026-05-27T10:41:41.215 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:D1531A88-8797-4F95-BEBF-C57F134DAF93 2026-05-27T10:41:41.215 QuickScan:ScanID:D1531A88-8797-4F95-BEBF-C57F134DAF93: Quick scan aborted by callback after end stage 2026-05-27T10:41:41.215 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:D1531A88-8797-4F95-BEBF-C57F134DAF93 2026-05-27T10:41:41.215 OnDemandScanWorker: Scan Cancelled! scanId:D1531A88-8797-4F95-BEBF-C57F134DAF93, hr = 0x80508018 2026-05-27T10:41:43.222 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:41:43.222 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:41:43.237 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:45:33.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T10:52:06.727 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:BF40419A-857A-4561-8E49-EA51A6704982, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-27T10:52:06.727 Scheduled scan with Id BF40419A-857A-4561-8E49-EA51A6704982 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-27T10:52:06.743 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-27T10:52:06.743 [SFC] System file cache build is not needed (already completed) 2026-05-27T10:52:07.993 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #28084, FileId: 0x41000000035865, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T10:52:08.727 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:52:08.743 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:52:08.743 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:52:11.622 Engine:Triggered AR EMS scan 2026-05-27T10:52:11.638 Engine:EMS scan for process: lsass pid: 756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.653 Engine:EMS scan for process: svchost pid: 964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.669 Engine:EMS scan for process: svchost pid: 688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.685 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.685 Engine:EMS scan for process: svchost pid: 1188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.700 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.700 Engine:EMS scan for process: svchost pid: 1380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.716 Engine:EMS scan for process: svchost pid: 1396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.716 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.716 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.716 Engine:EMS scan for process: svchost pid: 1436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.731 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.731 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.731 Engine:EMS scan for process: svchost pid: 1632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.731 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.747 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.747 Engine:EMS scan for process: svchost pid: 1984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.747 Engine:EMS scan for process: svchost pid: 1108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.763 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.763 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.763 Engine:EMS scan for process: svchost pid: 2132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.763 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2436, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2448, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.778 Engine:EMS scan for process: svchost pid: 2644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.794 Engine:EMS scan for process: svchost pid: 2688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.794 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.794 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.794 Engine:EMS scan for process: svchost pid: 3044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.810 Engine:EMS scan for process: svchost pid: 1100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.810 Engine:EMS scan for process: svchost pid: 3140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.810 Engine:EMS scan for process: svchost pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.825 Engine:EMS scan for process: svchost pid: 3596, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.825 Engine:EMS scan for process: svchost pid: 3732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.825 Engine:EMS scan for process: svchost pid: 3756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.841 Engine:EMS scan for process: svchost pid: 3840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.841 Engine:EMS scan for process: svchost pid: 3288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.841 Engine:EMS scan for process: svchost pid: 2936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.856 Engine:EMS scan for process: svchost pid: 4132, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.856 Engine:EMS scan for process: svchost pid: 4160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.872 Engine:EMS scan for process: svchost pid: 4192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.872 Engine:EMS scan for process: svchost pid: 4428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.888 Engine:EMS scan for process: svchost pid: 4440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.888 Engine:EMS scan for process: svchost pid: 4480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.888 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.903 Engine:EMS scan for process: svchost pid: 4800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.903 Engine:EMS scan for process: svchost pid: 5820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.919 Engine:EMS scan for process: dllhost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.919 Engine:EMS scan for process: svchost pid: 5900, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.919 Engine:EMS scan for process: svchost pid: 5888, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.935 Engine:EMS scan for process: svchost pid: 6232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.935 Engine:EMS scan for process: svchost pid: 7324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.935 Engine:EMS scan for process: svchost pid: 7432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.950 Engine:EMS scan for process: svchost pid: 7468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.950 Engine:EMS scan for process: svchost pid: 7824, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.966 Engine:EMS scan for process: svchost pid: 2928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:11.966 Engine:EMS scan for process: explorer pid: 8236, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.028 Engine:EMS scan for process: svchost pid: 8420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.028 Engine:EMS scan for process: svchost pid: 8556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.028 Engine:EMS scan for process: svchost pid: 8872, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.044 Engine:EMS scan for process: svchost pid: 8980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.044 Engine:EMS scan for process: svchost pid: 9024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.044 Engine:EMS scan for process: svchost pid: 9568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.044 Engine:EMS scan for process: dllhost pid: 10220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.060 Engine:EMS scan for process: svchost pid: 9408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.060 Engine:EMS scan for process: svchost pid: 14300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.060 Engine:EMS scan for process: svchost pid: 12120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.060 Engine:EMS scan for process: svchost pid: 6756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.075 Engine:EMS scan for process: svchost pid: 9032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.091 Engine:EMS scan for process: svchost pid: 1608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.091 Engine:EMS scan for process: svchost pid: 13996, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.106 Engine:EMS scan for process: svchost pid: 7840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.122 Engine:EMS scan for process: svchost pid: 12548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.122 Engine:EMS scan for process: svchost pid: 988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.122 Engine:EMS scan for process: svchost pid: 3748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:52:12.138 Engine:EMS scan for process: svchost pid: 1748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-05-27T10:54:42.204 QuickScan:ScanID:BF40419A-857A-4561-8E49-EA51A6704982: Quick scan finished with error 0 2026-05-27T10:54:42.719 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-27T10:54:42.719 [RTP] Duplicating the current plugin configuration object... 2026-05-27T10:54:42.719 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T10:54:42.719 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-27T10:54:42.719 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T10:54:42.719 [RTP] No config change detected. Not updating plugin configuration. 2026-05-27T10:54:42.719 [RTP] No config changes found. No configuration switch. 2026-05-27T10:54:42.719 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-27T10:54:44.219 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:54:44.235 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T10:54:44.235 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T10:55:18.338 [RbM] Audited automatic rollback of Platform 0x4001265b80007 --> 0x4001265a40006. hr = 0 2026-05-27T11:00:38.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T11:03:31.314 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #29081, FileId: 0x17a000000002311, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T11:03:34.830 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:34.908 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:35.486 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:35.642 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:35.783 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:35.783 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-05-27T11:03:47.950 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys 2026-05-27T11:03:48.731 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys 2026-05-27T11:15:43.339 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T11:30:48.341 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T11:45:53.331 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T12:00:58.331 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T12:05:45.601 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 26753, Count: 229, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T12:05:45.601 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T12:05:45.601 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T12:05:45.601 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T12:05:45.601 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T12:05:45.601 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T12:05:45.601 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T12:05:45.601 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 259, Count: 13, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T12:05:45.601 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T12:05:45.601 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 210, Count: 23, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T12:05:45.601 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 197, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T12:05:45.601 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 3% 2026-05-27T12:05:45.601 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 6% 2026-05-27T12:05:45.601 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T12:05:45.601 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T12:05:45.601 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T12:05:45.601 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T12:05:45.601 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T12:05:45.601 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T12:05:45.601 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T12:05:45.601 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T12:05:45.601 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T12:05:45.601 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T12:05:45.601 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T12:05:45.601 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T12:05:45.601 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T12:05:45.601 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T12:05:45.601 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T12:05:45.601 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T12:05:45.601 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T12:05:45.601 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T12:05:45.601 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T12:16:03.343 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T12:31:08.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T12:46:13.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T13:01:18.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T13:16:23.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T13:31:28.331 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T13:46:33.343 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T13:55:05.693 [AutoPurge] Verification Routine tasks have started. 2026-05-27T13:55:05.693 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-05-27T13:55:05.693 [AutoPurge] Cleanup Routine tasks have started. 2026-05-27T13:55:05.708 [AutoPurge] Routine task for Cache Maintenance has started. 2026-05-27T13:55:05.708 [AutoPurge] Routine task for Cache Maintenance ... 2026-05-27T13:55:05.708 [AutoPurge] Routine task for MpSFCBuild ... 2026-05-27T13:55:05.708 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-05-27T13:55:05.708 [AutoPurge] MpSignalMaintenanceMode ... 2026-05-27T13:55:05.708 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-05-27T13:55:05.724 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:80B391F0-1BFB-4711-9C56-8BE0C5B25DD5, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-05-27T13:55:05.724 Scheduled scan with Id 80B391F0-1BFB-4711-9C56-8BE0C5B25DD5 configured CPU priority: normal (LowCpuPriority: 0) 2026-05-27T13:55:05.724 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-05-27T13:55:05.724 [SFC] System file cache build is not needed (already completed) 2026-05-27T13:55:05.724 QuickScan:ScanID:80B391F0-1BFB-4711-9C56-8BE0C5B25DD5: Quick Scan skipped since it already ran during the past 7 days 2026-05-27T13:55:05.724 QuickScan:ScanID:80B391F0-1BFB-4711-9C56-8BE0C5B25DD5: Quick scan finished with error 1223 2026-05-27T13:55:05.724 OnDemandScanWorker: Scan Cancelled! scanId:80B391F0-1BFB-4711-9C56-8BE0C5B25DD5, hr = 0x80508018 2026-05-27T13:55:05.724 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) !ERROR Begin Quick Scan Scan ID:{80B391F0-1BFB-4711-9C56-8BE0C5B25DD5} Scan Source:1 Start Time:05-27-2026 13:55:05 Unsuccessful Scan Return Code:1223 ************************************************************ 2026-05-27T13:55:05.724 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-05-27T13:55:05.724 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:05-27-2026 13:55:05 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:05-27-2026 13:55:05 2026-05-27T13:55:05.739 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-05-27T13:55:05.739 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-05-27T13:55:05.739 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-05-27T13:55:05.739 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-05-27T13:55:05.739 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-05-27T13:55:05.739 [AutoPurge] Cleanup Routine tasks have ended. 2026-05-27T13:55:05.864 EnsureProtectedFolderAcls(), hr = 0x0 2026-05-27T13:55:05.864 [AutoPurge] MpReinforceServiceAcls: 0 2026-05-27T13:55:05.896 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-05-27T13:55:05.896 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-05-27T13:55:05.911 [AutoPurge] Verification Routine tasks have ended. 2026-05-27T13:55:07.728 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T13:55:07.744 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T13:55:07.744 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T13:55:09.744 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T13:55:09.744 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-05-27T13:55:09.744 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-05-27T13:55:18.873 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-05-27T13:55:18.889 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 32 2026-05-27T13:55:18.889 [RTP] Duplicating the current plugin configuration object... 2026-05-27T13:55:18.889 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T13:55:18.889 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 2 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 4096 2026-05-27T13:55:18.889 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 4 2026-05-27T13:55:18.889 [RTP] No config change detected. Not updating plugin configuration. 2026-05-27T13:55:18.889 [RTP] No config changes found. No configuration switch. 2026-05-27T13:55:18.889 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 8 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 16 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 1024 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 2048 2026-05-27T13:55:18.889 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T13:55:18.889 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-05-27T13:55:18.889 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-05-27T13:55:18.889 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-05-27T13:55:18.889 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-05-27T13:55:18.889 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-05-27T13:55:18.889 [RTP] [RtpConfig] Config change detected, type: 64 2026-05-27T13:55:18.889 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T13:55:18.889 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T13:55:18.905 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-05-27T13:55:18.967 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 46542697(ms) from now at 04:51 (02:51 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-05-27T13:55:21.467 [RTP] Duplicating the current plugin configuration object... 2026-05-27T13:55:21.467 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-05-27T13:55:21.467 [RTP] Updating plugin configuration due to recent config changes (0x41e) ... 2026-05-27T13:55:21.467 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-05-27T13:55:21.467 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x208 2026-05-27T14:01:38.337 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T14:05:45.611 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 27831, Count: 230, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T14:05:45.611 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T14:05:45.611 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T14:05:45.611 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T14:05:45.611 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T14:05:45.611 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T14:05:45.611 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 319, Count: 17, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T14:05:45.611 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T14:05:45.611 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 210, Count: 24, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T14:05:45.611 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 197, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T14:05:45.611 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 3% 2026-05-27T14:05:45.611 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 6% 2026-05-27T14:05:45.611 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T14:05:45.611 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T14:05:45.611 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T14:05:45.611 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T14:05:45.611 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T14:05:45.611 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T14:05:45.611 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T14:05:45.611 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T14:05:45.611 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T14:05:45.611 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T14:05:45.611 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T14:05:45.611 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T14:05:45.611 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T14:05:45.611 ProcessImageName: dllhost.exe, Pid: 2740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T14:05:45.611 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: sihost.exe, Pid: 7376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T14:05:45.611 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T14:05:45.611 ProcessImageName: brynhildr.exe, Pid: 4116, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-27T14:16:43.333 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T14:31:48.332 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T14:46:53.335 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T14:54:40.593 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33236, FileId: 0x2e6000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.609 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33233, FileId: 0x2e5000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.609 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33238, FileId: 0xc40000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.609 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33237, FileId: 0x2e7000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.624 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33241, FileId: 0x2ea000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.624 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33244, FileId: 0x2eb000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.624 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33245, FileId: 0x2ec000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.640 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33247, FileId: 0xcb0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.640 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33242, FileId: 0xc60000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.640 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33250, FileId: 0xcc0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:40.655 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33248, FileId: 0x2ef000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:41.015 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33280, FileId: 0x2f2000000004c66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:41.015 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #33279, FileId: 0xce0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T14:54:41.030 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\131bdcf2-6e15-4aff-af92-9d3cb12cbe59. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #33282, FileId: 0x3700000000f197, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T15:01:58.332 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T15:17:03.330 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T15:32:08.343 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T15:47:13.339 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T15:56:05.731 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #33947, FileId: 0x24000000033ca9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:02:18.338 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T16:05:45.612 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 27831, Count: 230, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T16:05:45.612 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T16:05:45.612 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T16:05:45.612 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T16:05:45.612 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T16:05:45.612 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T16:05:45.612 ProcessImageName: firefox.exe, Pid: 960, TotalTime: 526, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 39% 2026-05-27T16:05:45.612 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 334, Count: 19, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 2436, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T16:05:45.612 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 212, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T16:05:45.612 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T16:05:45.612 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 6% 2026-05-27T16:05:45.612 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T16:05:45.612 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T16:05:45.612 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T16:05:45.612 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T16:05:45.612 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T16:05:45.612 ProcessImageName: FileCoAuth.exe, Pid: 12312, TotalTime: 76, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-27.1555.12312.2.aodl, EstimatedImpact: 1% 2026-05-27T16:05:45.612 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T16:05:45.612 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T16:05:45.612 ProcessImageName: SDXHelper.exe, Pid: 848, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F53DA52-0896-40C3-BEA1-65DD4BDF51E6, EstimatedImpact: 10% 2026-05-27T16:05:45.612 ProcessImageName: dasHost.exe, Pid: 5260, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T16:05:45.612 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T16:05:45.612 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T16:05:45.612 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T16:05:45.612 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 30, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T16:05:45.612 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T16:05:45.612 ProcessImageName: dllhost.exe, Pid: 2740, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T16:05:45.612 ProcessImageName: backgroundTaskHost.exe, Pid: 14096, TotalTime: 15, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1779875504, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: sihost.exe, Pid: 7376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T16:05:45.612 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T16:05:45.612 ProcessImageName: brynhildr.exe, Pid: 4116, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-27T16:17:23.339 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T16:32:28.331 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T16:47:33.333 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T16:49:05.014 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34613, FileId: 0x1f00000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.014 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34615, FileId: 0x2000000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.014 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34617, FileId: 0xd40000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.014 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34614, FileId: 0xd20000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.014 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34618, FileId: 0x2200000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.030 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34621, FileId: 0xd70000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.030 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34619, FileId: 0xd50000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.030 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34623, FileId: 0xd80000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.030 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34624, FileId: 0x2600000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.046 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34627, FileId: 0xdb0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.046 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34622, FileId: 0x2400000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.046 Bm signature throttled:0x000045b3435c1067 2026-05-27T16:49:05.046 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34629, FileId: 0xdc0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.061 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34628, FileId: 0x2900000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.483 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #34665, FileId: 0xde0000000130e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T16:49:05.499 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\318e656c-b42c-4c91-ab2c-f8431ec8cec5. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #34667, FileId: 0x3d00000000ee68, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T17:02:38.337 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T17:17:43.342 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T17:32:48.342 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T17:47:53.328 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T18:02:58.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T18:05:45.617 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 27831, Count: 230, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T18:05:45.617 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T18:05:45.617 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T18:05:45.617 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T18:05:45.617 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T18:05:45.617 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T18:05:45.617 ProcessImageName: firefox.exe, Pid: 960, TotalTime: 526, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 39% 2026-05-27T18:05:45.617 ProcessImageName: firefox.exe, Pid: 9300, TotalTime: 496, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 63% 2026-05-27T18:05:45.617 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 349, Count: 21, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 2436, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T18:05:45.617 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 212, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T18:05:45.617 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T18:05:45.617 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 6% 2026-05-27T18:05:45.617 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T18:05:45.617 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T18:05:45.617 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T18:05:45.617 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T18:05:45.617 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T18:05:45.617 ProcessImageName: FileCoAuth.exe, Pid: 12312, TotalTime: 76, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-27.1555.12312.2.aodl, EstimatedImpact: 1% 2026-05-27T18:05:45.617 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T18:05:45.617 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T18:05:45.617 ProcessImageName: SDXHelper.exe, Pid: 848, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F53DA52-0896-40C3-BEA1-65DD4BDF51E6, EstimatedImpact: 10% 2026-05-27T18:05:45.617 ProcessImageName: dasHost.exe, Pid: 5260, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T18:05:45.617 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T18:05:45.617 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T18:05:45.617 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T18:05:45.617 ProcessImageName: dllhost.exe, Pid: 2740, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T18:05:45.617 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T18:05:45.617 ProcessImageName: backgroundTaskHost.exe, Pid: 14096, TotalTime: 15, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1779875504, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: sihost.exe, Pid: 7376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T18:05:45.617 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T18:05:45.617 ProcessImageName: brynhildr.exe, Pid: 4116, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-27T18:18:03.334 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T18:33:08.336 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T18:48:13.341 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T19:03:18.328 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T19:18:22.208 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T19:33:27.205 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T19:48:32.198 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T20:03:37.206 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T20:05:44.483 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 27831, Count: 230, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T20:05:44.483 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T20:05:44.483 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T20:05:44.483 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T20:05:44.483 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T20:05:44.483 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T20:05:44.483 ProcessImageName: firefox.exe, Pid: 960, TotalTime: 526, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 39% 2026-05-27T20:05:44.483 ProcessImageName: firefox.exe, Pid: 9300, TotalTime: 496, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 63% 2026-05-27T20:05:44.483 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 349, Count: 21, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 2436, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T20:05:44.483 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 212, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T20:05:44.483 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T20:05:44.483 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 6% 2026-05-27T20:05:44.483 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T20:05:44.483 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T20:05:44.483 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T20:05:44.483 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T20:05:44.483 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T20:05:44.483 ProcessImageName: FileCoAuth.exe, Pid: 12312, TotalTime: 76, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-27.1555.12312.2.aodl, EstimatedImpact: 1% 2026-05-27T20:05:44.483 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T20:05:44.483 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T20:05:44.483 ProcessImageName: SDXHelper.exe, Pid: 848, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F53DA52-0896-40C3-BEA1-65DD4BDF51E6, EstimatedImpact: 10% 2026-05-27T20:05:44.483 ProcessImageName: dasHost.exe, Pid: 5260, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T20:05:44.483 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T20:05:44.483 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T20:05:44.483 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T20:05:44.483 ProcessImageName: dllhost.exe, Pid: 2740, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T20:05:44.483 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T20:05:44.483 ProcessImageName: backgroundTaskHost.exe, Pid: 14096, TotalTime: 15, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1779875504, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T20:05:44.483 ProcessImageName: sihost.exe, Pid: 7376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: brynhildr.exe, Pid: 4116, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-27T20:05:44.483 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T20:18:42.201 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T20:33:47.197 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T20:48:52.205 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T21:03:57.207 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T21:19:02.197 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T21:34:07.206 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T21:49:12.194 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T21:54:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37740, FileId: 0x44000000029752, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37741, FileId: 0x46000000029752, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37743, FileId: 0x3200000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37739, FileId: 0x2f00000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.110 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37738, FileId: 0x2d00000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.126 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37746, FileId: 0x4a000000029752, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.126 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37748, FileId: 0x3600000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.142 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37747, FileId: 0x3500000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.142 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37751, FileId: 0x4d000000029752, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.142 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37753, FileId: 0x3900000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.157 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37752, FileId: 0x4e000000029752, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.579 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #37788, FileId: 0x3b00000003301b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:54:40.579 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\536c7a9c-742a-4388-a075-c1115cba47a8. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #37790, FileId: 0xe400000000c8fc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T21:56:05.682 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #37813, FileId: 0x36000000035a6f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-05-27T22:04:17.195 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T22:05:44.486 ProcessImageName: explorer.exe, Pid: 8236, TotalTime: 27831, Count: 230, MaxTime: 4781, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: Everything.exe, Pid: 5288, TotalTime: 7884, Count: 21, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 9% 2026-05-27T22:05:44.486 ProcessImageName: SrTasks.exe, Pid: 5360, TotalTime: 4635, Count: 689, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{9d5a5433-c6c1-463f-b0e8-1bee9810c874}_OnDiskSnapshotProp, EstimatedImpact: 11% 2026-05-27T22:05:44.486 ProcessImageName: AcroCEF.exe, Pid: 7960, TotalTime: 3603, Count: 175, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 28% 2026-05-27T22:05:44.486 ProcessImageName: setup.exe, Pid: 13916, TotalTime: 2942, Count: 355, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.83\copilot_overlay_unscaled_images.pak, EstimatedImpact: 45% 2026-05-27T22:05:44.486 ProcessImageName: taskhostw.exe, Pid: 13880, TotalTime: 1458, Count: 27, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\GastroTouch\Kasse.exe, EstimatedImpact: 7% 2026-05-27T22:05:44.486 ProcessImageName: sdiagnhost.exe, Pid: 7036, TotalTime: 785, Count: 48, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 30% 2026-05-27T22:05:44.486 ProcessImageName: WmiPrvSE.exe, Pid: 4520, TotalTime: 739, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys, EstimatedImpact: 92% 2026-05-27T22:05:44.486 ProcessImageName: firefox.exe, Pid: 960, TotalTime: 526, Count: 52, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 39% 2026-05-27T22:05:44.486 ProcessImageName: firefox.exe, Pid: 9300, TotalTime: 496, Count: 44, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 63% 2026-05-27T22:05:44.486 ProcessImageName: firefox.exe, Pid: 7008, TotalTime: 481, Count: 43, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 61% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 364, Count: 23, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: backgroundTaskHost.exe, Pid: 572, TotalTime: 360, Count: 49, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 12% 2026-05-27T22:05:44.486 ProcessImageName: PhoneExperienceHost.exe, Pid: 14084, TotalTime: 241, Count: 23, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: AdobeCollabSync.exe, Pid: 13816, TotalTime: 225, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Adobe\GrowthSDK\Production\SingleClientMini_2026-05-27.log, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 2436, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: FileCoAuth.exe, Pid: 8132, TotalTime: 214, Count: 12, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-shm, EstimatedImpact: 3% 2026-05-27T22:05:44.486 ProcessImageName: Everything.exe, Pid: 7344, TotalTime: 212, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: taskhostw.exe, Pid: 4768, TotalTime: 212, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_b47ba04e-004d-4df9-bfb5-9f906c23ccbc\DiagPackage.diagpkg, EstimatedImpact: 75% 2026-05-27T22:05:44.486 ProcessImageName: SDXHelper.exe, Pid: 3444, TotalTime: 198, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\3B9F9235-DFD1-4071-AB70-EC39407E849A, EstimatedImpact: 5% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 868, TotalTime: 195, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\29bb2efd6b4ead6de8ae6acef3720250cad66e63\content.phf, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: Acrobat.exe, Pid: 12436, TotalTime: 181, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 10% 2026-05-27T22:05:44.486 ProcessImageName: ngentask.exe, Pid: 7572, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: SDXHelper.exe, Pid: 8680, TotalTime: 166, Count: 15, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\OsfTaskengine.dll, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: taskhostw.exe, Pid: 11068, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 65% 2026-05-27T22:05:44.486 ProcessImageName: ngentask.exe, Pid: 9196, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log->(UTF-8), EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: wscript.exe, Pid: 6056, TotalTime: 136, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\.lnk, EstimatedImpact: 2% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 688, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: ngentask.exe, Pid: 8768, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log->(UTF-8), EstimatedImpact: 6% 2026-05-27T22:05:44.486 ProcessImageName: ngentask.exe, Pid: 7664, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 7% 2026-05-27T22:05:44.486 ProcessImageName: Everything.exe, Pid: 13924, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\Everything\Everything-1.4.1.1026.x86\Everything.ini, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: MicrosoftEdge_X64_148.0.3967.83_148.0.3967.70.exe, Pid: 7648, TotalTime: 93, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{32CF1B00-43C9-4EE0-B128-C349EDD327F0}\EDGEMITMP_6EC0D.tmp\setup.exe, EstimatedImpact: 54% 2026-05-27T22:05:44.486 ProcessImageName: AggregatorHost.exe, Pid: 5344, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: SecurityHealthHost.exe, Pid: 12736, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 9% 2026-05-27T22:05:44.486 ProcessImageName: mshta.exe, Pid: 7224, TotalTime: 77, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\_Down\Entwickler\adsitest\ADSITEST.HTA, EstimatedImpact: 23% 2026-05-27T22:05:44.486 ProcessImageName: FileCoAuth.exe, Pid: 12312, TotalTime: 76, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-27.1555.12312.2.aodl, EstimatedImpact: 1% 2026-05-27T22:05:44.486 ProcessImageName: OfficeC2RClient.exe, Pid: 13700, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\FDC968A1-FE47-4900-9A14-8589C46C1A51, EstimatedImpact: 3% 2026-05-27T22:05:44.486 ProcessImageName: OfficeC2RClient.exe, Pid: 6364, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1239.log->(UTF-16LE), EstimatedImpact: 2% 2026-05-27T22:05:44.486 ProcessImageName: SDXHelper.exe, Pid: 848, TotalTime: 75, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\2F53DA52-0896-40C3-BEA1-65DD4BDF51E6, EstimatedImpact: 10% 2026-05-27T22:05:44.486 ProcessImageName: dasHost.exe, Pid: 5260, TotalTime: 75, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: AcroCEF.exe, Pid: 10356, TotalTime: 61, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 7% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 1028, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgecrxedge_BITS_11368_1795575008\BIT7691.tmp, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: , Pid: 4, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy7\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 7% 2026-05-27T22:05:44.486 ProcessImageName: taskhostw.exe, Pid: 8264, TotalTime: 46, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-05-27T22:05:44.486 ProcessImageName: tzsync.exe, Pid: 7316, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 10% 2026-05-27T22:05:44.486 ProcessImageName: Acrobat.exe, Pid: 12708, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 3% 2026-05-27T22:05:44.486 ProcessImageName: SDXHelper.exe, Pid: 4944, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 9% 2026-05-27T22:05:44.486 ProcessImageName: OfficeC2RClient.exe, Pid: 11180, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260527-1252.log->(UTF-16LE), EstimatedImpact: 1% 2026-05-27T22:05:44.486 ProcessImageName: dllhost.exe, Pid: 2740, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: FileCoAuth.exe, Pid: 13756, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-27.2155.13756.1.aodl, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: taskhostw.exe, Pid: 2680, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 6% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 2116, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: dllhost.exe, Pid: 1880, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-DBD9083D.pf, EstimatedImpact: 27% 2026-05-27T22:05:44.486 ProcessImageName: backgroundTaskHost.exe, Pid: 14096, TotalTime: 15, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1779875504, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 4084, TotalTime: 15, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Settings\rest_information, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: AdobeARM.exe, Pid: 10308, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\AdobeARM.log, EstimatedImpact: 2% 2026-05-27T22:05:44.486 ProcessImageName: sihost.exe, Pid: 7376, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: DismHost.exe, Pid: 8488, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\COMPONENTS{1c2b59a0-c5f5-11eb-bacb-000d3a96488e}.TM.blf, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 8612, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: brynhildr.exe, Pid: 4116, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-05-27T22:05:44.486 ProcessImageName: svchost.exe, Pid: 9032, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-05-27T22:19:22.198 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-05-27T22:28:52.803 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\B6C8A20E-F129-476C-9F99-60CDF1AC6FDE1264.1dcee28319326d8 2026-05-27T22:28:52.897 Verifying engine and signature files (source: 0) ... 2026-05-27T22:28:52.897 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpengine.dll] due to PPL. 2026-05-27T22:28:52.897 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasbase.vdm]. File not in cache (0x1) 2026-05-27T22:28:53.647 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasbase.vdm] 2026-05-27T22:28:53.647 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasdlta.vdm]. File not in cache (0x1) 2026-05-27T22:28:53.662 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasdlta.vdm] 2026-05-27T22:28:53.662 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavbase.vdm]. File not in cache (0x1) 2026-05-27T22:28:53.990 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavbase.vdm] 2026-05-27T22:28:53.990 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavdlta.vdm]. File not in cache (0x1) 2026-05-27T22:28:54.006 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavdlta.vdm] 2026-05-27T22:28:54.162 [Engine] IsHybridMode: 0 2026-05-27T22:28:54.162 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-05-27T22:28:54.178 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-E4BBB49880B436592F30675DDBCBEAC723526FDE.bin): 0x00000002 2026-05-27T22:28:54.178 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-E4BBB49880B436592F30675DDBCBEAC723526FDE.bin) 2026-05-27T22:28:54.178 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-05-27T22:28:54.178 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-05-27T22:28:54.178 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-05-27T22:28:54.178 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-05-27T22:29:04.120 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-05-27T22:29:04.120 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-05-27T22:29:04.135 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF941615810, lRefCount: 5, hr=0 2026-05-27T22:29:04.135 [Engine] New active engine 00007FF8EA905810 replacing engine 00007FF941615810. Number of active engines: 2 2026-05-27T22:29:04.151 EngineInit:Global ASOC is enabled 2026-05-27T22:29:04.151 EngineInit:ASOO is enabled for developer volumes 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\700631d79a4043f2ddab3f75dc9273935e1271bb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:32 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e3d8a1441791fe5e02f1dcc2dd94eda1246935f9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aa3835be3cd34c86c8332069f8dcc81e85a79fa3 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4920cb535e221ffa67374bc2fb08498e9e8e936f Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ec6aee504b7eb02c8e9a5e25e789deb226c5661 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:33 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9344e8c9ae5df45178d69f5b9e342dfbc834fbc6 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:34 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0ed48d3bb57537187624d3851cd2fa34a70d936e Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aee3ff2524f840dca96093738193552c6e7c6031 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\45a5e391e3acd890913727b4dbb975d6e8dbc0ed Dynamic Signature Compilation Timestamp:05-17-2026 21:14:35 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1b15fc3decc03b218771dbcb980a581cbae36965 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1692fcd8b62163cda4132db290fd9de05b62463c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\195a8502beb59977b82871d8971d66843694cda8 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5185fc71333cafeec50b9eb45d78c9fa1f13b30a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:36 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ed9c83d9b05625fc88f3e7f7b345a85a90449f9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e366330c187e53acc5a021d87969e7518e0f28c5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14a8cdfd91cbee2e811d92ff356d429b52437ea7 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:37 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c9289b2c45cfb5c8990a9407fa934b688966a4da Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1aa8d90d892e5c627fd9279a2360fa5b6d1205b9 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\155ae337503bb8b2887c919f239f3dd8f055abbb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:38 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3cc83a1589e17cc4e019e2c7342cae1192853064 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\57eed4124d719dfe55851c60ced4e26dbe946d5a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7272ed020e12b0f9d534786a444934e73872210c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:39 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\873979922b9d6fb730a45a9c7e6202912e1c100c Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c6f26e1ea587cc11601d7a49cb2c43e31c0c8667 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\81505909cbb6b4428a417e2bc9a357ad28274752 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9841f4907f73e443e1bf44a848bdcf2170f94663 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:40 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3b0d7ad5c34ca5223c0fa8ba506dc3689e7a6817 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79e1ea606b699373172403915d08534ae908cd71 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5dd76d166cb13da77fd71a766a4f294dfb23e4e5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:41 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bdc7c98d8d3d1f69b8482ede4a759c42da412510 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\596714896c9717bd375ffee7d7e4a9c7fc296b6f Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0925e94c853ba3cb7bfa7d21240cda996d430382 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:42 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dc85cfb6b79799f4415895d5bc0c048e25a30eef Dynamic Signature Compilation Timestamp:05-17-2026 21:14:43 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\73a10524f17963af5d336f5aafbaae49454f0a17 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:43 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\66ce980165356f11f96804458fae9194e5e35ed8 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d5d83b14bfb5b3e22797f1a99a62c3d823946233 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\678aeacff04a71a8f774591d075e31972c06188d Dynamic Signature Compilation Timestamp:05-17-2026 21:14:44 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.214 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5d6151aa5ca0d2fba9be7f7531463620fa6e3fa5 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:45 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ea7af7767baa95a31e8b10fdd611b7018fedca90 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:45 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\438b93891dae4b8cf1dd050e4e8cdae5024b7993 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:46 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\25fb2d54ea7c19802f50fd9f634aa18ce85de2ea Dynamic Signature Compilation Timestamp:05-17-2026 21:14:47 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b74f9ad5a63b2a3fa8114cdb06524219cfd1a12 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:47 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a9010938da4d363f740b430be498f54ad458ff6 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:48 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7357c85e7c67ad901dc7f5a442a91c3ba6406edd Dynamic Signature Compilation Timestamp:05-17-2026 21:14:48 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f0f76d264a06a04f67226f1202d45acdfaa0ab73 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9da814708472011535a48906efa569139aaa5d55 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bf96115a1b694c95b264a9a2af0439c94eac69fb Dynamic Signature Compilation Timestamp:05-17-2026 21:14:49 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a3770e92eb814c4a47fd605b9fba31555d630ff1 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b5ae341569e89e34a13473b54aa9416e0d076339 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\817b0c69240fcf09e1022604ba969ce5154094b7 Dynamic Signature Compilation Timestamp:05-17-2026 21:14:50 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75dd06fb7d1a88c7f088b360e0380f83e1e6090a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:51 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2dc6a970d21a0900d93eef4617b0c3bace225c2a Dynamic Signature Compilation Timestamp:05-17-2026 21:14:51 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\be8ef088743863606974206a51643cd26774d2fe Dynamic Signature Compilation Timestamp:05-17-2026 21:14:52 Persistence Type:Duration Time remaining:50065408 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7b3f1ad566e7c7267a624b0184187fc1e8179276 Dynamic Signature Compilation Timestamp:05-27-2026 10:14:18 Persistence Type:Duration Time remaining:288000000 2026-05-27T22:29:04.229 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1ed8c81f5464460171b54c123d7f3f952c6de461 Dynamic Signature Compilation Timestamp:05-27-2026 10:14:36 Persistence Type:Duration Time remaining:288000000 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 06-03-2026 14:08:13 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 06/03/2026 14:08:13.534815600 UTC (17250 ms since boot) 2026-06-03T14:08:13.552 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-06-03T14:08:13.557 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:08:13.557 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:08:13.597 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260603-140813-00000003-fffffffeffffffff.bin ... 2026-06-03T14:08:13.618 [WPP] Trace session started - MpWppTracing-20260603-140813-00000003-fffffffeffffffff.bin 2026-06-03T14:08:13.623 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-06-03T14:08:13.623 [RbM] Rollback manager succesfully initialized. 2026-06-03T14:08:13.623 [RbM] Rollback manager EnableRollbackManager called. 2026-06-03T14:08:13.627 [RbM] Rollback manager EnableRollbackManager completed. 2026-06-03T14:08:13.627 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 2026-06-03T14:08:13.632 MpWriteUupPlatformVersion 4.18.26040.7, hr = 0 2026-06-03T14:08:13.632 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-06-03T14:08:13.632 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-06-03T14:08:13.632 MdCoreSvc is supported in this platform and OS 2026-06-03T14:08:13.632 MdCoreSvc is supported in this platform and OS 2026-06-03T14:08:13.632 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-03T14:08:13.632 [PlatUpd] Starting MdCoreSvc service 2026-06-03T14:08:13.667 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0" 2026-06-03T14:08:17.588 [PlatUpd] MpAddMpUxRegistration succeeded 2026-06-03T14:08:17.588 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-06-03T14:08:17.588 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-06-03T14:08:17.588 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-06-03T14:08:17.588 [PlatUpd] CSP platform update started 2026-06-03T14:08:17.588 [PlatUpd] Defender MDM CSP platform update not required 2026-06-03T14:08:17.588 [PlatUpd] WMI/PS provider platform update started 2026-06-03T14:08:17.588 [PlatUpd] WMI/PS provider platform update not required 2026-06-03T14:08:17.588 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-06-03T14:08:17.588 MdCoreSvc is supported in this platform and OS 2026-06-03T14:08:17.588 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-03T14:08:17.588 [PlatUpd] Starting MdCoreSvc service 2026-06-03T14:08:17.588 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-06-03T14:08:17.588 [TS] Troubleshooting mode is not available! 2026-06-03T14:08:17.588 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-03T14:08:17.588 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-06-03T14:08:17.603 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-06-03T14:08:17.603 [Service] Enabling AutoLoggers ... 2026-06-03T14:08:17.603 [Service] Enabling AMSI registration ... 2026-06-03T14:08:17.603 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-06-03T14:08:17.619 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 48195 Number of invalid entries is 0 Number of inserts issued is 1592339 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6569 Number of lookups is 108781484 Number of lookup misses is 5224871 Number of fast lookup misses is 55423725 Number of false fast lookups is 5224866 Number of invalidations is 737610 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-06-03T14:08:17.619 Verifying license file... 2026-06-03T14:08:17.619 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\msmplics.dll] (file in cache) 2026-06-03T14:08:17.635 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-06-03T14:08:17.635 Loaded module#0 MpComServer. 2026-06-03T14:08:17.635 Loaded module#1 StartupPolicies. 2026-06-03T14:08:17.635 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-03T14:08:17.635 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-03T14:08:17.635 COM server initialized successfully. 2026-06-03T14:08:17.650 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-06-03T14:08:17.666 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll ... 2026-06-03T14:08:17.666 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mprtp.dll] due to PPL. 2026-06-03T14:08:17.682 [RTP] [RTP] FilterCommunicator object 0x000001F18E662840 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-03T14:08:17.682 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-06-03T14:08:17.682 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:08:17.682 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:08:17.682 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-06-03T14:08:17.682 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-03T14:08:17.682 [RTP] [RTP] FilterCommunicator object 0x000001F18E674000 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-03T14:08:17.682 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-06-03T14:08:17.682 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-06-03T14:08:17.682 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-06-03T14:08:17.682 [RTP] [RTP] StartCommunication 0x000001F18E662840 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-03T14:08:17.682 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\mpnirtp.dll does not exist. 2026-06-03T14:08:17.682 [init][RTP] RTPPlugin initialization completed 2026-06-03T14:08:17.682 OS boot count = 2 2026-06-03T14:08:17.682 OS Install = 0 2026-06-03T14:08:17.697 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-06-03T14:08:17.697 [KSL] Entering CKSLEngine::Initialize. 2026-06-03T14:08:17.697 [KSL] Leaving CKSLEngine::Initialize(0). 2026-06-03T14:08:17.697 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-06-03T14:08:17.697 [KSL] MpInstallKslD: hr=0x1 2026-06-03T14:08:17.697 [KSL] MpRegisterKslD: hr=0 2026-06-03T14:08:17.697 [KSL] MpStartKslD: hr=0 2026-06-03T14:08:17.697 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-03T14:08:17.697 Loading engine... 2026-06-03T14:08:17.713 Verifying engine and signature files (source: 1) ... 2026-06-03T14:08:17.713 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpengine.dll] due to PPL. 2026-06-03T14:08:17.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasbase.vdm] (file in cache) 2026-06-03T14:08:17.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasdlta.vdm] (file in cache) 2026-06-03T14:08:17.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavbase.vdm] (file in cache) 2026-06-03T14:08:17.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpavdlta.vdm] (file in cache) 2026-06-03T14:08:17.760 [Engine] IsHybridMode: 0 2026-06-03T14:08:17.760 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-03T14:08:17.775 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-E4BBB49880B436592F30675DDBCBEAC723526FDE.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-03T14:08:21.900 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-03T14:08:21.900 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableSmsEmsOnArm64_MpRamp hr=0x8007007b IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-06-03T14:08:21.900 [Engine] New active engine 00007FFD19535810 (no old engine). Number of active engines: 1 2026-06-03T14:08:21.916 EngineInit:Global ASOC is enabled 2026-06-03T14:08:21.916 EngineInit:ASOO is enabled for developer volumes 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:21.994 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4fd8ae0a7639264673f037e77087205bb4b64dea Dynamic Signature Compilation Timestamp:05-01-2026 15:18:43 Persistence Type:Duration Time remaining:150196224 2026-06-03T14:08:21.994 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4991d789daca1a1932ecfdc25e32e26f34f58f99 Dynamic Signature Compilation Timestamp:05-01-2026 16:56:31 Persistence Type:Duration Time remaining:150196224 2026-06-03T14:08:21.994 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\154375187a0360914290e556900cfdd4009cdf88 Dynamic Signature Compilation Timestamp:05-01-2026 23:00:10 Persistence Type:Duration Time remaining:150196224 2026-06-03T14:08:21.994 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6fc60f1e8a73b748b8b4b2652b29d0e684dc7fcc Dynamic Signature Compilation Timestamp:05-01-2026 23:00:13 Persistence Type:Duration Time remaining:150196224 2026-06-03T14:08:22.010 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e1072994edac52bd4582de6876be5dadb14207a0 Dynamic Signature Compilation Timestamp:05-27-2026 09:48:54 Persistence Type:Duration Time remaining:864000000 2026-06-03T14:08:22.010 MpWriteUupSignatureVersion 1.451.132.0, hr = 0 2026-06-03T14:08:22.010 [SigStatUpd] CSignatureStatus: Changed to DUE_TRY_1 2026-06-03T14:08:22.010 [SigStatUpd] CSignatureStatus: Triggering signature update... 2026-06-03T14:08:22.057 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-06-03T14:08:22.057 [SigStatUpd] CSignatureStatus: Signature update triggered! 2026-06-03T14:08:22.057 [SigStatUpd] CSignatureStatus: UpdateWaitTimer #1 scheduled 2026-06-03T14:08:22.057 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-03T14:08:22.057 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7632] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7640]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:08:22.072 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-03T14:08:22.072 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:08:22.072 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-03T14:08:22.072 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-03T14:08:22.072 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-03T14:08:22.103 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-03T14:08:22.103 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2752 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2195 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12723 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2504 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-03T14:08:22.103 [Plugin] Initializing RTP plugin state... 2026-06-03T14:08:22.103 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-03T14:08:22.103 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8} 2026-06-03T14:08:22.103 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:22.103 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:22.103 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:22.103 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:22.103 MdCoreSvc is supported in this platform and OS 2026-06-03T14:08:22.103 Engine loaded! 2026-06-03T14:08:22.103 [DLP] Create FeatureControlState instance 2026-06-03T14:08:22.103 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-06-03T14:08:22.103 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-06-03T14:08:22.103 RegisterSModeChangeListener: hr = 0x1 2026-06-03T14:08:22.103 RegisterHybridModeChangeListener: hr = 0 2026-06-03T14:08:22.119 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-06-03T14:08:22.119 [SigReleaseHb] Initialized with Stage 0 2026-06-03T14:08:22.119 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-06-03T14:08:22.119 [SCC][CID=25843_5620] Initializing ... 2026-06-03T14:08:22.119 [SCC][CID=25843_5620] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-06-03T14:08:22.135 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-03T14:08:22.135 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-03T14:08:22.135 [NRI] Stopping NIS service ... 2026-06-03T14:08:22.135 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-06-03T14:08:22.135 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26040.8 AS Signature Version: 1.451.132.0 AV Signature Version: 1.451.132.0 ************************************************************ 2026-06-03T14:08:22.135 Resource usage Monitoring is enabled 2026-06-03T14:08:22.135 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-03T14:08:22.135 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-06-03T14:08:22.135 Job Notification: New process added to job (4796) 2026-06-03T14:08:22.166 Job Notification: New process added to job (7740) 2026-06-03T14:08:22.166 Job Notification: New process added to job (7748) 2026-06-03T14:08:22.166 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7740] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7748]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:08:22.213 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-06-03T14:08:22.213 Job Notification: New process added to job (7800) 2026-06-03T14:08:22.213 Job Notification: New process added to job (7808) 2026-06-03T14:08:22.228 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:7800] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7808]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:08:22.275 [PlatUpd] WMI MOF schema validation completed successfully 2026-06-03T14:08:22.275 Job Notification: Process exited from job (7740) 2026-06-03T14:08:22.275 Job Notification: Process exited from job (7748) 2026-06-03T14:08:22.275 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-03T14:08:22.275 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-03T14:08:22.291 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-03T14:08:22.291 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-03T14:08:22.291 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-03T14:08:22.291 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:08:22.291 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:08:22.291 [RTP] Generating the base plugin configuration ... 2026-06-03T14:08:22.291 [RTP] Path exclusion changed, new size in bytes: 2 2026-06-03T14:08:22.291 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:08:22.291 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-06-03T14:08:22.291 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-06-03T14:08:22.291 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:08:22.291 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-03T14:08:22.291 [RTP] [RTP] StartCommunication 0x000001F18E674000 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-03T14:08:22.307 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-06-03T14:08:22.338 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-06-03T14:08:22.557 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-03T14:08:22.557 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-03T14:08:22.557 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-03T14:08:22.635 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:22.791 [AutoPurge] Verification Routine tasks have started. 2026-06-03T14:08:22.791 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-06-03T14:08:22.791 [AutoPurge] Cleanup Routine tasks have started.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-03T14:08:22.807 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-06-03T14:08:22.807 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-06-03T14:08:22.807 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:06-03-2026 14:08:22 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-03-2026 14:08:22 2026-06-03T14:08:22.838 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-06-03T14:08:22.838 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-06-03T14:08:22.838 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-06-03T14:08:22.838 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-06-03T14:08:22.838 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-06-03T14:08:22.838 [AutoPurge] Cleanup Routine tasks have ended. 2026-06-03T14:08:22.978 EnsureProtectedFolderAcls(), hr = 0x0 2026-06-03T14:08:22.978 [AutoPurge] MpReinforceServiceAcls: 0 2026-06-03T14:08:23.010 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-06-03T14:08:23.307 Job Notification: New process added to job (8068) 2026-06-03T14:08:23.307 Task(GetDeviceTicket -AccessKey 3E7F1F35-8E79-D661-46EA-DD2D752B636A ) launched as network service 2026-06-03T14:08:23.682 Job Notification: Process exited from job (8068) 2026-06-03T14:08:23.885 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-06-03T14:08:23.885 [Cloud] Start of cloud request. Passive mode: 0 2026-06-03T14:08:23.885 [Cloud] Queued cloud request. 2026-06-03T14:08:23.885 [Cloud] Dequeued cloud request. 2026-06-03T14:08:23.885 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-03T14:08:24.057 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-06-03T14:08:24.057 [Cloud] End of cloud request. 2026-06-03T14:08:24.088 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-06-03T14:08:24.088 [AutoPurge] Verification Routine tasks have ended. 2026-06-03T14:08:24.213 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-03T14:08:24.228 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 2 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 4096 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 4 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 8 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 16 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 2048 2026-06-03T14:08:24.228 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:24.228 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-03T14:08:24.228 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:08:24.228 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:08:24.228 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-03T14:08:24.228 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-03T14:08:24.228 [RTP] [RtpConfig] Config change detected, type: 64 2026-06-03T14:08:24.228 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:24.244 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:24.244 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:25.213 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:08:25.213 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:08:25.213 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-06-03T14:08:25.213 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:08:25.213 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-03T14:08:25.213 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-06-03T14:08:41.432 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\1E56E0C5-A634-41B1-A488-4DD40CFFA01A97c.1dcf36279729e95 2026-06-03T14:08:41.603 Verifying engine and signature files (source: 0) ... 2026-06-03T14:08:41.603 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpengine.dll] due to PPL. 2026-06-03T14:08:41.603 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm]. File not in cache (0x1) 2026-06-03T14:08:42.354 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm] 2026-06-03T14:08:42.354 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasdlta.vdm]. File not in cache (0x1) 2026-06-03T14:08:42.369 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasdlta.vdm] 2026-06-03T14:08:42.369 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm]. File not in cache (0x1) 2026-06-03T14:08:42.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm] 2026-06-03T14:08:42.713 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavdlta.vdm]. File not in cache (0x1) 2026-06-03T14:08:42.728 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavdlta.vdm] 2026-06-03T14:08:42.885 [Engine] IsHybridMode: 0 2026-06-03T14:08:42.885 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-03T14:08:42.885 Current mpengine.dll version(1.1.26050.11) is newer than mpengine_etw.dll version(1.1.26040.8). Updating C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll ... 2026-06-03T14:08:42.900 C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll updated. 2026-06-03T14:08:43.103 Job Notification: New process added to job (7492) 2026-06-03T14:08:43.103 Job Notification: New process added to job (6200) 2026-06-03T14:08:43.400 Job Notification: Process exited from job (7492) 2026-06-03T14:08:43.400 Job Notification: Process exited from job (6200) 2026-06-03T14:08:43.400 Job Notification: New process added to job (860) 2026-06-03T14:08:43.400 Job Notification: New process added to job (432) 2026-06-03T14:08:43.604 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-03T14:08:43.666 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-03T14:08:43.947 Job Notification: Process exited from job (860) 2026-06-03T14:08:43.947 Job Notification: Process exited from job (432) 2026-06-03T14:08:43.963 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-14A9729DB70DC04E7BE82B645A2C2A3E734F31DA.bin): 0x00000002 2026-06-03T14:08:43.963 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-14A9729DB70DC04E7BE82B645A2C2A3E734F31DA.bin) 2026-06-03T14:08:43.963 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-06-03T14:08:43.963 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-06-03T14:08:43.963 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-06-03T14:08:43.963 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-06-03T14:08:44.463 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-03T14:08:44.463 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-03T14:08:46.229 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:08:46.229 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:08:46.229 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-06-03T14:08:46.229 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-03T14:08:46.229 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-03T14:08:53.728 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-03T14:08:53.728 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_NisSrvWatchDogTimerFix hr=0x8007007b IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 2026-06-03T14:08:53.744 Engine upgrade detected 0x1000165b80008. Saving old engine files to last known good engine files ... 2026-06-03T14:08:53.744 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFD19535810, lRefCount: 7, hr=0 2026-06-03T14:08:53.744 [Engine] New active engine 00007FFD14B984C0 replacing engine 00007FFD19535810. Number of active engines: 2 2026-06-03T14:08:53.760 EngineInit:Global ASOC is enabled 2026-06-03T14:08:53.760 EngineInit:ASOO is enabled for developer volumes 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:08:53.822 MpWriteUupSignatureVersion 1.451.246.0, hr = 0 2026-06-03T14:08:53.822 [SigStatUpd] CSignatureStatus: back to good 2026-06-03T14:08:53.822 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-03T14:08:53.838 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-03T14:08:53.838 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:08:53.838 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-03T14:08:53.838 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-03T14:08:53.838 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-03T14:08:53.853 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-03T14:08:53.853 [Plugin] Initializing RTP plugin state... 2026-06-03T14:08:53.853 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-03T14:08:53.853 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎06‎-‎03‎-‎2026 16:08:22 Last Perf:‎06‎-‎03‎-‎2026 16:08:22 First RTP Scan:‎06‎-‎03‎-‎2026 16:08:22 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:383 Misses:591 BM Queue:0,10,0 Proc:0,10,0 File:0,4,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:998 Pending:0 RegSize:308276 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:922410 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2603 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:14946 TotalHits:1460 InstanceCacheInserts:16 InstanceCacheUpdates:0 InstanceCacheDeletes:16 InstanceCacheHits:0 InstanceCacheMisses:2961 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (42/13) Success: 13, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-03T14:08:53.853 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51} 2026-06-03T14:08:53.853 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-03T14:08:53.853 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8C278EF0-2C30-4781-9FBC-9884713EAA44} removed 2026-06-03T14:08:53.853 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8}\mpasbase.vdm in use, hr=0x80070020 2026-06-03T14:08:53.853 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.853 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.853 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.853 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.853 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:06-03-2026 14:08:53 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-03-2026 14:08:53 2026-06-03T14:08:53.869 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:08:53.869 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-03T14:08:53.869 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-03T14:08:53.869 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-03T14:08:53.869 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:08:53.869 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.869 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.869 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.869 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-03T14:08:53.869 MdCoreSvc is supported in this platform and OS Signature updated on 06-03-2026 14:08:53 Product Version: 4.18.26040.7 Service Version: 4.18.26040.7 Engine Version: 1.1.26050.11 AS Signature Version: 1.451.246.0 AV Signature Version: 1.451.246.0 ************************************************************ 2026-06-03T14:08:53.869 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-06-03T14:08:53.869 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\1E56E0C5-A634-41B1-A488-4DD40CFFA01A97c.1dcf36279729e95 2026-06-03T14:08:53.932 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-03T14:08:53.947 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 06-03-2026 14:08:53 ************************************************************ 2026-06-03T14:08:53.978 Job Notification: Process exited from job (7800) 2026-06-03T14:08:53.978 Job Notification: Process exited from job (7808) 2026-06-03T14:08:54.228 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-03T14:08:54.228 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-03T14:08:54.228 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-03T14:08:54.228 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:08:54.228 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:08:54.228 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:08:54.228 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-06-03T14:08:54.338 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-03T14:08:54.338 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-03T14:08:54.338 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-03T14:09:17.619 Process scan (postsignatureupdatescan) started. 2026-06-03T14:09:22.791 [Engine] Engine 00007FFD19535810 no longer in use. Number of active engines: 1 2026-06-03T14:09:22.869 ProcessImageName: taskhostw.exe, Pid: 7472, TotalTime: 1046, Count: 3, MaxTime: 1015, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 10% 2026-06-03T14:09:22.869 ProcessImageName: WmiPrvSE.exe, Pid: 3672, TotalTime: 390, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\basicrender.inf, EstimatedImpact: 19% 2026-06-03T14:09:22.869 ProcessImageName: MpSigStub.exe, Pid: 2428, TotalTime: 343, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\1E56E0C5-A634-41B1-A488-4DD40CFFA01A97c.1dcf36279729e95\mpengine.dll, EstimatedImpact: 100% 2026-06-03T14:09:22.869 ProcessImageName: wuauclt.exe, Pid: 7748, TotalTime: 186, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\SoftwareDistribution\Download\Install\AM_Engine_Patch_1.1.26040.8.exe, EstimatedImpact: 9% 2026-06-03T14:09:22.869 ProcessImageName: brynhildr.exe, Pid: 4432, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-03T14:09:22.900 [Engine] RSIG_UNLOADENGINE, 00007FFD19535810, err=0x0 2026-06-03T14:09:22.916 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75D4198-7AA2-4212-B5F8-EBCD7FCA4EA8} removed 2026-06-03T14:09:31.791 Process scan (postsignatureupdatescan) completed. 2026-06-03T14:10:16.697 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:10:16.697 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:10:16.697 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:13:22.119 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T14:13:27.706 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #1575, FileId: 0x7d00000003e43e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:13:31.113 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-03T14:13:32.831 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-03T14:13:42.159 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe (PPID:8784:134249696174632435) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-03T14:13:42.159 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe (PPID:9088:134249696179069205) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-03T14:13:42.175 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe (PPID:8848:134249696175198480) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-03T14:13:53.854 [RbM] Setting Last known good engine candidate. hr = 0 2026-06-03T14:14:01.148 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.078.0426.0002\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #3929, FileId: 0x5500000000d18a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:14:17.094 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-06-03T14:14:17.094 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:14:17.094 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:14:17.094 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-06-03T14:14:17.094 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-06-03T14:14:17.094 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-06-03T14:14:17.680 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-06-03T14:14:20.147 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-06-03T14:14:23.175 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-06-03T14:14:23.816 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-06-03T14:14:47.006 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb)` is 5296 units 2026-06-03T14:14:54.262 [RTP] [Mini-filter] OpenWithoutRead notification (5553, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-06-03T14:15:04.289 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-06-03T14:15:04.411 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb)` is 5281 units 2026-06-03T14:15:08.802 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #11661, FileId: 0x13000000000da01, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:15:15.294 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 5515 units 2026-06-03T14:15:17.588 Engine:Process C:\Windows\System32\svchost.exe (PPID:4456:134249692925211249) is tainted: TaintType:0x4. TaintReason:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe, EnableCfa:1 2026-06-03T14:15:17.588 Engine:Process C:\Windows\System32\svchost.exe originally tainted by: TaintType:0x8, TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x0dd27014 Internal signature match:subtype=Lowfi, sigseq=0x0000157EDBC612FC, sigsha=d5f1909a20fbb89ca049ea3ac446bcfd3acf514e, cached=false, source=2, resourceid=0xbeff8f81 2026-06-03T14:16:34.773 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14734, FileId: 0xba000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:34.774 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14735, FileId: 0x20b000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:34.889 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14729, FileId: 0xb9000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.480 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14776, FileId: 0xd000000000b974, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.481 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14778, FileId: 0x26300000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.485 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14777, FileId: 0x219000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.500 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14775, FileId: 0x218000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.532 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14786, FileId: 0x21f000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.535 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14784, FileId: 0x26800000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.540 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14790, FileId: 0x221000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.543 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14789, FileId: 0x26900000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.544 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14792, FileId: 0x26b00000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.579 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14794, FileId: 0x26e00000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.579 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14795, FileId: 0x225000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.582 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14788, FileId: 0x220000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.686 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #14807, FileId: 0x11400000000c01a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.827 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14827, FileId: 0x227000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.843 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14828, FileId: 0x228000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:35.861 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14826, FileId: 0x27100000000124f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:39.588 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\3555c099-3d6e-43f5-8048-71ae5faf4e43. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #15007, FileId: 0x4400000000edad, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:40.963 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #15010, FileId: 0x8a00000000c941, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:44.434 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15246, FileId: 0xb900000000747b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0x3761add5 2026-06-03T14:16:53.093 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\Other30324.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #15653, FileId: 0x128000000016a3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:53.178 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\Other30327.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #15659, FileId: 0x1a000000016ac6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:53.291 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\Other30327.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #15664, FileId: 0xb4000000016c43, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:53.438 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\UpdatedRdr30327.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #15668, FileId: 0x170000000016cca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:58.371 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2ED32B937. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15809, FileId: 0x98000000018e22, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:58.492 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj41C53A942. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15817, FileId: 0x44000000018e0c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:58.533 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF4B8B7900. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15822, FileId: 0x3e000000018d45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:58.596 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBE3531933. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15824, FileId: 0x5600000001860f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:58.656 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj152005935. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15826, FileId: 0x3f000000018d45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:59.371 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D6913906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15856, FileId: 0x5e00000001860f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:16:59.398 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCDF31A950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15859, FileId: 0x43000000018d45, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:00.858 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFC87E59EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15911, FileId: 0x9c000000018e22, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:02.181 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDD99029D2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15965, FileId: 0x5500000000f119, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:02.341 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11E02C9B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #15974, FileId: 0xc1000000018e44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:12.118 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16205, FileId: 0xd6000000004d8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:12.397 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16212, FileId: 0x3100000000cb27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:12.925 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #16224, FileId: 0x27000000017b54, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:17:53.851 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #16736, FileId: 0x3400000000cb27, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:18:13.425 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #21492, FileId: 0x1b0000000013c11, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:18:22.120 Timer callback: Initializating/verifying scheduled tasks ... 2026-06-03T14:18:22.120 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-06-03T14:18:22.230 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 37589600(ms) from now at 02:44 (00:44 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-06-03T14:18:22.239 Job Notification: New process added to job (12616) 2026-06-03T14:18:22.247 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-06-03T14:18:22.249 Job Notification: New process added to job (11828) 2026-06-03T14:18:22.262 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:12616] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11828]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:18:22.266 Aggressive catchup quick scan threshold: 6171755087616 / 25920000000000 2026-06-03T14:18:22.389 Job Notification: New process added to job (10092) 2026-06-03T14:18:22.393 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-06-03T14:18:22.397 Job Notification: New process added to job (9656) 2026-06-03T14:18:22.426 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe][Pid:10092] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:9656]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:18:22.798 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-03T14:18:22.799 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:18:22.799 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:18:22.799 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-06-03T14:18:22.799 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:18:22.799 [RTP] No config change detected. Not updating plugin configuration. 2026-06-03T14:18:22.799 [RTP] No config changes found. No configuration switch. 2026-06-03T14:18:22.799 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-06-03T14:18:31.879 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26179, FileId: 0x178000000002ad2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:18:49.760 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-06-03T14:18:49.761 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-06-03T14:18:49.761 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-06-03T14:18:49.761 [PlatUpd] Not purging last known good location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-06-03T14:18:49.761 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-06-03T14:18:49.776 [PlatUpd] Verified C:\Windows\SystemTemp\CE28505C-5FE6-4DD1-B429-1BAFEBC7C5F3\MpUpdate.dll. Calling MpUpdateStub(0) ... 2026-06-03T14:18:52.536 [PlatUpd] MpUpdateStub() succeeded. Stub DLL: C:\Windows\SystemTemp\CE28505C-5FE6-4DD1-B429-1BAFEBC7C5F3\MpUpdate.dll. 2026-06-03T14:18:52.536 [KSL] Entering CKSLEngine::DisableKSL. 2026-06-03T14:18:52.537 [KSL] Entering CKSLEngine::shutdownImpl. 2026-06-03T14:18:52.635 [KSL] Leaving CKSLEngine::shutdownImpl(0). 2026-06-03T14:18:52.635 [KSL] Leaving CKSLEngine::DisableKSL(0). 2026-06-03T14:18:52.636 [KSL] OnPlatformUpdate: hr=[0x8000000a] Type=[1] KslServiceExists=[1] KslActive=[1] KslState=[2] 2026-06-03T14:18:52.638 [PlatUpd] DlpActive 0, CopyAccActive 0, WdAiNisDrvPending 0 2026-06-03T14:18:52.638 [PlatUpd] PlatformUpdate is now allowed. Resuming platform update from C:\Windows\SystemTemp\CE28505C-5FE6-4DD1-B429-1BAFEBC7C5F3. 2026-06-03T14:18:52.638 [PlatUpd] NewLocation set to [C:\Windows\SystemTemp\CE28505C-5FE6-4DD1-B429-1BAFEBC7C5F3] to indicate we are in the middle of an update. 2026-06-03T14:18:52.662 Job Notification: New process added to job (10984) 2026-06-03T14:18:52.670 Task(-RestartService) launched as PPL process 2026-06-03T14:18:52.678 Job Notification: New process added to job (9384) -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 06-03-2026 14:18:56 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 06/03/2026 14:18:56.977073000 UTC (660703 ms since boot) 2026-06-03T14:18:56.983 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-06-03T14:18:56.985 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:18:56.985 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:18:56.994 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260603-141856-00000003-fffffffeffffffff.bin ... 2026-06-03T14:18:56.999 [WPP] Trace session started - MpWppTracing-20260603-141856-00000003-fffffffeffffffff.bin 2026-06-03T14:18:57.002 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-06-03T14:18:57.004 [RbM] Rollback manager succesfully initialized. 2026-06-03T14:18:57.004 [RbM] Rollback manager EnableRollbackManager called. 2026-06-03T14:18:57.006 [RbM] Rollback manager EnableRollbackManager completed. 2026-06-03T14:18:57.006 [PlatUpd] Stage 1 - Starting platform update from %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-06-03T14:18:59.594 [PlatUpd] Updated service binary of WdNisSvc from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\NisSrv.exe" 2026-06-03T14:18:59.597 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdBoot.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\Drivers\WdBoot.sys 2026-06-03T14:18:59.602 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdFilter.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\Drivers\WdFilter.sys 2026-06-03T14:18:59.605 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdNisDrv.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\Drivers\WdNisDrv.sys 2026-06-03T14:19:00.036 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdDevFlt.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\Drivers\WdDevFlt.sys 2026-06-03T14:19:02.955 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpOav.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpOav.dll" 2026-06-03T14:19:02.955 [PlatUpd] Updated SOFTWARE\WOW6432Node\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\X86\MpOav.dll" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\X86\MpOav.dll" 2026-06-03T14:19:02.970 [PlatUpd] MpAddMpUxRegistration succeeded 2026-06-03T14:19:02.970 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-06-03T14:19:02.970 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-06-03T14:19:02.970 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-06-03T14:19:02.970 [PlatUpd] CSP platform update started 2026-06-03T14:19:02.970 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{195B4D07-3DE2-4744-BBF2-D90121AE785B}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\DefenderCSP.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\DefenderCSP.dll" 2026-06-03T14:19:02.970 [PlatUpd] CSP version com.microsoft/1.3/MDM/Defender update not required. 2026-06-03T14:19:02.970 [PlatUpd] WMI/PS provider platform update started 2026-06-03T14:19:02.970 [PlatUpd] Powershell module update started: ConfigDefender 2026-06-03T14:19:02.986 [PlatUpd] Powershell module update completed: ConfigDefender 2026-06-03T14:19:02.986 [PlatUpd] Powershell module update started: ConfigDefenderPerformance 2026-06-03T14:19:02.989 [PlatUpd] Powershell module update completed: ConfigDefenderPerformance 2026-06-03T14:19:03.421 [PlatUpd] WMI repository update completed 2026-06-03T14:19:03.422 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{A7C452EF-8E9F-42EB-9F2B-245613CA0DC9}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26040.7-0\ProtectionManagement.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\ProtectionManagement.dll" 2026-06-03T14:19:03.422 [PlatUpd] Unload current WMI provider so that new instance can be loaded 2026-06-03T14:19:03.571 [PlatUpd] WMI/PS provider platform update completed 2026-06-03T14:19:03.571 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-06-03T14:19:03.572 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-06-03T14:19:03.572 MdCoreSvc is supported in this platform and OS 2026-06-03T14:19:03.572 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-03T14:19:03.572 [PlatUpd] Updated service binary of MDCoreSvc from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpDefenderCoreService.exe" 2026-06-03T14:19:03.572 [PlatUpd] Because we updated service binary, and MdCoreSvc service was already running, we need to restart the service 2026-06-03T14:19:04.720 [PlatUpd] Firewall rules updated for %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MsMpEng.exe 2026-06-03T14:19:04.720 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0): 10 items checked, 7 required update. hrMui: 0x1 hrEtw: 0 2026-06-03T14:19:04.720 [PlatUpd] Stage 1 - NewLocation updated from C:\Windows\SystemTemp\CE28505C-5FE6-4DD1-B429-1BAFEBC7C5F3 to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 to indicate we are in the middle of an update 2026-06-03T14:19:04.734 [PlatUpd] Stage 1 - Service binary path updated to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MsMpEng.exe". 2026-06-03T14:19:04.738 [PlatUpd] Stage 1 - Removed BlockedLocation [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0] to indicate we are loaded successfully. 2026-06-03T14:19:04.775 Task(-RestartService) launched as PPL process 2026-06-03T14:19:04.775 MpPostPlatformUpdate is requesting a service restart. We will abort the current service start -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 06-03-2026 14:19:05 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 06/03/2026 14:19:05.74993900 UTC (668796 ms since boot) 2026-06-03T14:19:05.080 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-06-03T14:19:05.083 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:19:05.083 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:19:05.096 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260603-141905-00000003-fffffffeffffffff.bin ... 2026-06-03T14:19:05.105 [WPP] Trace session started - MpWppTracing-20260603-141905-00000003-fffffffeffffffff.bin 2026-06-03T14:19:05.109 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-06-03T14:19:05.110 [RbM] Rollback manager succesfully initialized. 2026-06-03T14:19:05.110 [RbM] Rollback manager EnableRollbackManager called. 2026-06-03T14:19:05.113 [RbM] Rollback manager EnableRollbackManager completed. 2026-06-03T14:19:05.114 [PlatUpd] Stage 2 - Service started from new location. Removed NewLocation value: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 2026-06-03T14:19:05.137 [PlatUpd] [Catalog] Installed catalog file : C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\catalogs\MpExtDeps.cat as wd_mpextdeps.cat. 2026-06-03T14:19:05.138 [PlatUpd] Stage 2 - Updated BackupLocation to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-06-03T14:19:05.141 [PlatUpd] MpRemoveMpUxRegistration failed (Ignored). hr = 0x800401f0 2026-06-03T14:19:05.141 [RbM] Platform LKG candidate becoming LKG: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0. 2026-06-03T14:19:05.463 EnsureProtectedFolderAcls(), hr = 0x0 2026-06-03T14:19:05.466 [PlatUpd] Stage 2 - ReinforceServiceAcl (hr = 0) 2026-06-03T14:19:05.514 [PlatUpd] Stage 2 - Readded platform files to MOAC after ACL and Trust Label enforcement. hr=0 2026-06-03T14:19:05.515 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-06-03T14:19:10.495 [PlatUpd] MpAddMpUxRegistration succeeded 2026-06-03T14:19:10.496 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-06-03T14:19:10.496 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-06-03T14:19:10.496 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-06-03T14:19:10.496 [PlatUpd] CSP platform update started 2026-06-03T14:19:10.496 [PlatUpd] Defender MDM CSP platform update not required 2026-06-03T14:19:10.496 [PlatUpd] WMI/PS provider platform update started 2026-06-03T14:19:10.496 [PlatUpd] WMI/PS provider platform update not required 2026-06-03T14:19:10.496 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-06-03T14:19:10.497 MdCoreSvc is supported in this platform and OS 2026-06-03T14:19:10.497 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-03T14:19:10.497 [PlatUpd] Starting MdCoreSvc service 2026-06-03T14:19:10.498 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-06-03T14:19:10.507 [TS] Troubleshooting mode is not available! 2026-06-03T14:19:10.508 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-03T14:19:10.508 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-06-03T14:19:10.548 Service is asked to be reenabled. 2026-06-03T14:19:10.635 Task(-EnableService) launched as PPL process 2026-06-03T14:19:10.638 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-06-03T14:19:10.638 [Service] Enabling AutoLoggers ... 2026-06-03T14:19:10.640 [Service] Enabling AMSI registration ... 2026-06-03T14:19:10.640 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-06-03T14:19:10.649 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 48377 Number of invalid entries is 0 Number of inserts issued is 1592841 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6576 Number of lookups is 108818450 Number of lookup misses is 5227307 Number of fast lookup misses is 55446434 Number of false fast lookups is 5227302 Number of invalidations is 737926 Number of maintenance invalidations is 523576 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-06-03T14:19:10.649 Verifying license file... 2026-06-03T14:19:10.649 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll]. File not in cache (0x1) 2026-06-03T14:19:10.657 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll] 2026-06-03T14:19:10.679 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-06-03T14:19:10.680 Loaded module#0 MpComServer. 2026-06-03T14:19:10.680 Loaded module#1 StartupPolicies. 2026-06-03T14:19:10.681 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-03T14:19:10.682 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-03T14:19:10.691 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-06-03T14:19:10.703 COM server initialized successfully. 2026-06-03T14:19:10.704 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll ... 2026-06-03T14:19:10.704 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll] due to PPL. 2026-06-03T14:19:10.770 [RTP] [RTP] FilterCommunicator object 0x000002CA09525C40 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-03T14:19:10.775 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-03T14:19:10.775 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-03T14:19:10.775 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-03T14:19:10.776 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-03T14:19:10.776 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-06-03T14:19:10.776 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-06-03T14:19:10.776 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-06-03T14:19:10.776 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:19:10.776 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:19:10.776 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-06-03T14:19:10.776 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-03T14:19:10.776 [RTP] [RTP] FilterCommunicator object 0x000002CA094F3520 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-03T14:19:10.776 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-06-03T14:19:10.776 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-06-03T14:19:10.776 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-06-03T14:19:10.777 [RTP] [RTP] StartCommunication 0x000002CA09525C40 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-03T14:19:10.777 [init][RTP] RTPPlugin initialization completed 2026-06-03T14:19:10.777 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mpnirtp.dll does not exist. 2026-06-03T14:19:10.777 [init][NiRTP] NiRTPPlugin initialization completed 2026-06-03T14:19:10.777 OS boot count = 2 2026-06-03T14:19:10.777 OS Install = 0 2026-06-03T14:19:10.789 [ManagedAgent] HooksInitialize: starting 2026-06-03T14:19:10.791 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-06-03T14:19:10.791 [ManagedAgent] HooksInitialize: complete 2026-06-03T14:19:10.842 [init] MpAddMpUxRegistrationForToast succeeded 2026-06-03T14:19:10.847 [KSL] Entering CKSLEngine::Initialize. 2026-06-03T14:19:10.848 [KSL] Leaving CKSLEngine::Initialize(0). 2026-06-03T14:19:10.848 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-06-03T14:19:10.851 [KSL] MpInstallKslD: hr=0 2026-06-03T14:19:10.853 [KSL] MpRegisterKslD: hr=0 2026-06-03T14:19:10.858 [KSL] MpStartKslD: hr=0 2026-06-03T14:19:10.858 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-03T14:19:10.858 Loading engine... 2026-06-03T14:19:10.871 Verifying engine and signature files (source: 1) ... 2026-06-03T14:19:10.871 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpengine.dll] due to PPL. 2026-06-03T14:19:10.871 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm]. File not in cache (0x1) 2026-06-03T14:19:12.305 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm] 2026-06-03T14:19:12.305 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasdlta.vdm] (file in cache) 2026-06-03T14:19:12.305 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm]. File not in cache (0x1) 2026-06-03T14:19:12.818 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm] 2026-06-03T14:19:12.818 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavdlta.vdm] (file in cache) 2026-06-03T14:19:12.833 [Engine] IsHybridMode: 0 2026-06-03T14:19:12.833 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-03T14:19:12.847 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-59F7A723E8A6981DE5D2C2CF6D325878F61C4C15.bin): 0x00000002 2026-06-03T14:19:12.897 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-59F7A723E8A6981DE5D2C2CF6D325878F61C4C15.bin) 2026-06-03T14:19:12.897 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-06-03T14:19:12.897 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-06-03T14:19:12.897 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-06-03T14:19:12.897 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-03T14:19:26.181 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-03T14:19:26.182 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-06-03T14:19:26.188 [Engine] New active engine 00007FFCB5AA84C0 (no old engine). Number of active engines: 1 2026-06-03T14:19:26.194 EngineInit:Global ASOC is enabled 2026-06-03T14:19:26.194 EngineInit:ASOO is enabled for developer volumes 2026-06-03T14:19:26.286 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.288 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.289 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-03T14:19:26.293 MpWriteUupSignatureVersion 1.451.246.0, hr = 0 2026-06-03T14:19:26.295 [SigStatUpd] CSignatureStatus: back to good 2026-06-03T14:19:26.295 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-03T14:19:26.320 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-03T14:19:26.320 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-03T14:19:26.320 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-03T14:19:26.320 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-03T14:19:26.324 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-03T14:19:26.345 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-03T14:19:26.346 [Plugin] Initializing RTP plugin state... 2026-06-03T14:19:26.346 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:474 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:1159 TotalHits:0 InstanceCacheInserts:8 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:489 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-03T14:19:26.346 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-03T14:19:26.346 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51} 2026-06-03T14:19:26.347 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:19:26.347 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:19:26.347 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-03T14:19:26.347 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-03T14:19:26.349 MdCoreSvc is supported in this platform and OS 2026-06-03T14:19:26.349 MdCoreSvc is supported in this platform and OS 2026-06-03T14:19:26.349 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-03T14:19:26.349 [PlatUpd] Starting MdCoreSvc service 2026-06-03T14:19:26.350 Engine loaded! 2026-06-03T14:19:26.351 [DLP] Create FeatureControlState instance 2026-06-03T14:19:26.360 RegisterSModeChangeListener: hr = 0x1 2026-06-03T14:19:26.360 RegisterHybridModeChangeListener: hr = 0 2026-06-03T14:19:26.365 [PlatUpd] Updated install location from C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\ to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\ 2026-06-03T14:19:26.370 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-06-03T14:19:26.370 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-06-03T14:19:26.384 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-06-03T14:19:26.384 [SigReleaseHb] Initialized with Stage 0 2026-06-03T14:19:26.384 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-06-03T14:19:26.385 [SCC][CID=690109_13296] Initializing ... 2026-06-03T14:19:26.385 [SCC][CID=690109_13296] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-06-03T14:19:26.391 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-03T14:19:26.391 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-03T14:19:26.393 [NRI] Stopping NIS service ... 2026-06-03T14:19:26.393 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-06-03T14:19:26.393 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26050.11 AS Signature Version: 1.451.246.0 AV Signature Version: 1.451.246.0 ************************************************************ 2026-06-03T14:19:26.395 Resource usage Monitoring is enabled 2026-06-03T14:19:26.396 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-06-03T14:19:26.398 Job Notification: New process added to job (13020) 2026-06-03T14:19:26.435 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-03T14:19:26.563 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-03T14:19:26.565 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-03T14:19:26.571 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-03T14:19:26.571 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-03T14:19:26.572 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-03T14:19:26.572 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-03T14:19:26.572 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-03T14:19:26.572 [RTP] Generating the base plugin configuration ... 2026-06-03T14:19:26.572 [RTP] Path exclusion changed, new size in bytes: 2 2026-06-03T14:19:26.573 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:19:26.573 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-06-03T14:19:26.575 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-06-03T14:19:26.575 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:19:26.575 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-03T14:19:26.578 [RTP] [RTP] StartCommunication 0x000002CA094F3520 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-03T14:19:26.604 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-06-03T14:19:26.625 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll 2026-06-03T14:19:26.806 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-03T14:19:26.812 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-03T14:19:26.812 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-03T14:19:26.812 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-03T14:19:26.911 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-03T14:19:28.930 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:28.938 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:19:28.940 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:29.423 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:19:29.423 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:19:29.423 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-06-03T14:19:29.423 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-03T14:19:29.423 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-06-03T14:19:30.947 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:30.954 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:19:30.955 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:31.037 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\vhd+ISOs\ISO\caelinux2020lite.iso 2026-06-03T14:19:32.964 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:32.973 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:19:32.975 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:35.019 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:35.030 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:19:35.032 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:37.043 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:19:37.051 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:19:37.053 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:20:10.702 Process scan (poststartupscan) started. 2026-06-03T14:20:10.705 Process scan (poststartupscan) completed. 2026-06-03T14:20:11.226 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-03T14:20:11.236 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-03T14:20:13.778 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:20:13.778 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:20:13.778 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-06-03T14:20:13.779 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-03T14:20:13.779 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x6a68b239 2026-06-03T14:21:23.900 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO79D4.tmp` is 11531 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EEDC1FDAA, sigsha=957d8fbfe7987111d93ac432453760da86bb5a7d, cached=false, source=2, resourceid=0xd02f7333 2026-06-03T14:21:33.689 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B9892DF6-BCA0-49A9-957B-DA020EBDF5B8}\MicrosoftEdge_X64_148.0.3967.70.exe` is 9906 units 2026-06-03T14:22:15.737 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x7e98f821 2026-06-03T14:22:52.462 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOEC50.tmp` is 11843 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EEDC1FDAA, sigsha=957d8fbfe7987111d93ac432453760da86bb5a7d, cached=false, source=2, resourceid=0x0d04431b 2026-06-03T14:23:07.369 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\MicrosoftEdge_X64_148.0.3967.96.exe` is 9968 units Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x9b10a2b2 Internal signature match:subtype=Lowfi, sigseq=0x0000157E6DDC10C1, sigsha=78969d00342dc791c18821a826c371fb4295d915, cached=false, source=2, resourceid=0xed052e0a 2026-06-03T14:24:26.249 [RbM] Setting Last known good engine candidate. hr = 0 2026-06-03T14:24:26.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-06-03T14:24:48.446 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-06-03T14:24:48.446 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:24:48.446 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:24:48.446 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-06-03T14:24:48.446 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-06-03T14:24:48.448 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-06-03T14:24:48.536 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-06-03T14:24:49.375 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-06-03T14:24:50.145 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-06-03T14:25:09.218 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #4346, FileId: 0x1d50000000084cb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:25:11.620 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-06-03T14:25:12.895 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-06-03T14:25:12.990 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-06-03T14:25:27.328 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-06-03T14:25:27.328 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-06-03T14:25:27.328 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:25:27.328 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:25:27.328 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-06-03T14:25:27.328 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-06-03T14:25:27.329 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-06-03T14:25:28.163 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-06-03T14:26:37.521 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #7712, FileId: 0x3c000000010c1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:26:37.599 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #7715, FileId: 0x1800000003c348, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:27:13.191 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7731, FileId: 0x3e000000010c1b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:27:13.352 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7733, FileId: 0x3100000002b287, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000099E70D0F0E3C, sigsha=d485e65a81cc48c5eff27c34fa65b37d422dd64a, cached=false, source=5, resourceid=0x94183fae 2026-06-03T14:28:47.196 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5171 units 2026-06-03T14:28:47.490 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\VirtualBox Dropped Files\2026-06-03T14_28_39.662824800Z\Cameyo.exe->(EXEEmb)` is 5125 units 2026-06-03T14:29:26.383 Timer callback: Initializating/verifying scheduled tasks ... 2026-06-03T14:29:26.385 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-06-03T14:29:26.579 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 48472745(ms) from now at 05:57 (03:57 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-06-03T14:29:26.604 Job Notification: New process added to job (1560) 2026-06-03T14:29:26.621 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-06-03T14:29:26.624 Job Notification: New process added to job (11844) 2026-06-03T14:29:26.637 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:1560] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11844]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:29:26.812 Job Notification: New process added to job (4116) 2026-06-03T14:29:26.817 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-06-03T14:29:26.821 Job Notification: New process added to job (11832) 2026-06-03T14:29:26.831 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:4116] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11832]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-03T14:29:35.835 Job Notification: Process exited from job (4116) 2026-06-03T14:29:35.837 Job Notification: Process exited from job (11832) 2026-06-03T14:29:35.909 Job Notification: Process exited from job (1560) 2026-06-03T14:29:35.910 Job Notification: Process exited from job (11844) 2026-06-03T14:34:57.116 [RTP] [Mini-filter] OpenWithoutRead notification (3726, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-06-03T14:36:41.053 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:0E3775AC-6968-4BE8-96DD-89A1AAD20C53, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-06-03T14:36:41.053 Scheduled scan with Id 0E3775AC-6968-4BE8-96DD-89A1AAD20C53 configured CPU priority: normal (LowCpuPriority: 0) 2026-06-03T14:36:41.055 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-06-03T14:36:41.055 [SFC] System file cache build is not needed (already completed) 2026-06-03T14:36:41.674 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17794, FileId: 0xb600000001ac15, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:36:41.782 [AutoPurge] Routine task for Cache Maintenance has started. 2026-06-03T14:36:41.782 [AutoPurge] Routine task for Cache Maintenance ... 2026-06-03T14:36:41.782 [AutoPurge] Routine task for MpSFCBuild ... 2026-06-03T14:36:41.783 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-06-03T14:36:41.783 [AutoPurge] MpSignalMaintenanceMode ... 2026-06-03T14:36:41.797 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.844 Engine:EMS scan for process: svchost pid: 980, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.898 Engine:EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.905 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.924 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.961 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.978 Engine:EMS scan for process: svchost pid: 1256, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:41.990 Engine:EMS scan for process: svchost pid: 1340, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.001 Engine:EMS scan for process: svchost pid: 1348, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.007 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.012 Engine:EMS scan for process: svchost pid: 1464, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.023 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.027 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.036 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.044 Engine:EMS scan for process: svchost pid: 1616, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.051 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.057 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.070 Engine:EMS scan for process: svchost pid: 1992, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.082 Engine:EMS scan for process: svchost pid: 2004, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.089 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.096 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.115 Engine:EMS scan for process: svchost pid: 2188, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.125 Engine:EMS scan for process: svchost pid: 2304, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.137 Engine:EMS scan for process: svchost pid: 2412, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.142 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.149 Engine:EMS scan for process: svchost pid: 2488, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.154 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.158 Engine:EMS scan for process: svchost pid: 2624, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.164 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.170 Engine:EMS scan for process: svchost pid: 2708, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.177 Engine:EMS scan for process: svchost pid: 2748, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.184 Engine:EMS scan for process: svchost pid: 3064, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.190 Engine:EMS scan for process: svchost pid: 3036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.205 Engine:EMS scan for process: svchost pid: 3112, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.210 Engine:EMS scan for process: svchost pid: 3252, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.223 Engine:EMS scan for process: svchost pid: 3512, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.230 Engine:EMS scan for process: svchost pid: 3780, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.233 Engine:EMS scan for process: svchost pid: 3788, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.237 Engine:EMS scan for process: svchost pid: 3964, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.244 Engine:EMS scan for process: svchost pid: 4024, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.249 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.300 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.307 Engine:EMS scan for process: svchost pid: 4300, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.319 Engine:EMS scan for process: svchost pid: 4440, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.334 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.353 Engine:EMS scan for process: svchost pid: 4704, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.370 Engine:EMS scan for process: svchost pid: 4712, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.395 Engine:EMS scan for process: svchost pid: 4724, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.399 Engine:EMS scan for process: svchost pid: 4788, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.422 Engine:EMS scan for process: svchost pid: 5288, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.447 Engine:EMS scan for process: svchost pid: 5696, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.465 Engine:EMS scan for process: svchost pid: 5704, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.474 Engine:EMS scan for process: svchost pid: 5836, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.484 Engine:EMS scan for process: svchost pid: 5044, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.487 Engine:EMS scan for process: dllhost pid: 5692, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.491 Engine:EMS scan for process: svchost pid: 6412, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.494 Engine:EMS scan for process: svchost pid: 6348, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.503 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.514 Engine:EMS scan for process: svchost pid: 3508, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.523 Engine:EMS scan for process: svchost pid: 608, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.527 Engine:EMS scan for process: svchost pid: 2272, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.531 Engine:EMS scan for process: svchost pid: 4268, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.550 Engine:EMS scan for process: svchost pid: 4256, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.557 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.559 Bm signature throttled:0x00002db31bed458f 2026-06-03T14:36:42.585 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.592 Engine:EMS scan for process: svchost pid: 6832, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.605 Engine:EMS scan for process: explorer pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.762 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.767 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.777 Engine:EMS scan for process: svchost pid: 6564, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.781 Engine:EMS scan for process: svchost pid: 6852, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.808 Engine:EMS scan for process: dllhost pid: 8796, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.809 Bm signature throttled:0x00002db31bed458f 2026-06-03T14:36:42.813 Engine:EMS scan for process: svchost pid: 9456, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.822 Engine:EMS scan for process: svchost pid: 7424, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.829 Engine:EMS scan for process: svchost pid: 8048, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.853 Engine:EMS scan for process: svchost pid: 11400, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.857 Bm signature throttled:0x00002db31bed458f 2026-06-03T14:36:42.863 Engine:EMS scan for process: svchost pid: 9384, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.867 Engine:EMS scan for process: svchost pid: 10584, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.876 Engine:EMS scan for process: svchost pid: 5036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.882 Engine:EMS scan for process: svchost pid: 1780, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.886 Engine:EMS scan for process: svchost pid: 1796, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.893 Engine:EMS scan for process: svchost pid: 12540, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:42.898 Engine:EMS scan for process: svchost pid: 9060, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-06-03T14:36:43.087 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:36:43.108 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:36:43.109 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:37:03.380 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-03T14:38:10.838 Engine:Triggered AR EMS scan 2026-06-03T14:38:10.843 Engine:EMS scan for process: lsass pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.861 Engine:EMS scan for process: svchost pid: 980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.878 Engine:EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.881 Engine:EMS scan for process: svchost pid: 1044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.885 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.899 Engine:EMS scan for process: svchost pid: 1212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.906 Engine:EMS scan for process: svchost pid: 1256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.908 Engine:EMS scan for process: svchost pid: 1340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.914 Engine:EMS scan for process: svchost pid: 1348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.917 Engine:EMS scan for process: svchost pid: 1440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.919 Engine:EMS scan for process: svchost pid: 1464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.925 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.928 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.932 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.938 Engine:EMS scan for process: svchost pid: 1616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.941 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.945 Engine:EMS scan for process: svchost pid: 1716, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.949 Engine:EMS scan for process: svchost pid: 1992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.951 Engine:EMS scan for process: svchost pid: 2004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.954 Engine:EMS scan for process: svchost pid: 2056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.957 Engine:EMS scan for process: svchost pid: 2116, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.960 Engine:EMS scan for process: svchost pid: 2188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.964 Engine:EMS scan for process: svchost pid: 2304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.966 Engine:EMS scan for process: svchost pid: 2412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.968 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.971 Engine:EMS scan for process: svchost pid: 2488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.974 Engine:EMS scan for process: svchost pid: 2504, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.977 Engine:EMS scan for process: svchost pid: 2624, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.982 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.985 Engine:EMS scan for process: svchost pid: 2708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.988 Engine:EMS scan for process: svchost pid: 2748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.991 Engine:EMS scan for process: svchost pid: 3064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:10.995 Engine:EMS scan for process: svchost pid: 3036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.002 Engine:EMS scan for process: svchost pid: 3112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.007 Engine:EMS scan for process: svchost pid: 3252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.010 Engine:EMS scan for process: svchost pid: 3512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.016 Engine:EMS scan for process: svchost pid: 3780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.018 Engine:EMS scan for process: svchost pid: 3788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.022 Engine:EMS scan for process: svchost pid: 3964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.027 Engine:EMS scan for process: svchost pid: 4024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.031 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.056 Engine:EMS scan for process: svchost pid: 4224, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.059 Engine:EMS scan for process: svchost pid: 4300, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.062 Engine:EMS scan for process: svchost pid: 4440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.070 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.079 Engine:EMS scan for process: svchost pid: 4704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.089 Engine:EMS scan for process: svchost pid: 4712, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.093 Engine:EMS scan for process: svchost pid: 4724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.095 Engine:EMS scan for process: svchost pid: 4788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.101 Engine:EMS scan for process: svchost pid: 5288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.106 Engine:EMS scan for process: svchost pid: 5696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.113 Engine:EMS scan for process: svchost pid: 5704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.120 Engine:EMS scan for process: svchost pid: 5836, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.123 Engine:EMS scan for process: svchost pid: 5044, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.126 Engine:EMS scan for process: dllhost pid: 5692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.132 Engine:EMS scan for process: svchost pid: 6412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.135 Engine:EMS scan for process: svchost pid: 6348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.140 Engine:EMS scan for process: svchost pid: 3696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.145 Engine:EMS scan for process: svchost pid: 3508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.148 Engine:EMS scan for process: svchost pid: 608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.150 Engine:EMS scan for process: svchost pid: 2272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.153 Engine:EMS scan for process: svchost pid: 4268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.157 Engine:EMS scan for process: svchost pid: 4256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.164 Engine:EMS scan for process: svchost pid: 4640, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.176 Engine:EMS scan for process: svchost pid: 3676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.181 Engine:EMS scan for process: svchost pid: 6832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.187 Engine:EMS scan for process: explorer pid: 3600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.247 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.252 Engine:EMS scan for process: svchost pid: 4124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.257 Engine:EMS scan for process: svchost pid: 6564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.259 Engine:EMS scan for process: svchost pid: 6852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.264 Engine:EMS scan for process: dllhost pid: 8796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.267 Engine:EMS scan for process: svchost pid: 9456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.272 Engine:EMS scan for process: svchost pid: 7424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.278 Engine:EMS scan for process: svchost pid: 8048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.294 Engine:EMS scan for process: svchost pid: 11400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.299 Engine:EMS scan for process: svchost pid: 9384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.302 Engine:EMS scan for process: svchost pid: 10584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.307 Engine:EMS scan for process: svchost pid: 5036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.312 Engine:EMS scan for process: svchost pid: 1780, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.314 Engine:EMS scan for process: svchost pid: 1796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.318 Engine:EMS scan for process: svchost pid: 9060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.322 Engine:EMS scan for process: svchost pid: 2744, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:38:11.325 Engine:EMS scan for process: svchost pid: 6260, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-03T14:39:31.384 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T14:41:57.937 QuickScan:ScanID:9E3EE03C-95A6-205E-64D4-77DBBB4D8304: Quick scan finished with error 0 2026-06-03T14:41:58.027 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2620.102.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-06-03T14:41:58.073 Engine:Setting original file name "CertCli" for "c:\windows\system32\de-de\certcli.dll.mui", hr=0x800710da 2026-06-03T14:41:58.131 Engine:Setting original file name "powershell.exe" for "c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-06-03T14:41:58.586 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-06-03T14:41:59.154 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-06-03T14:41:59.488 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-06-03T14:41:59.583 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-06-03T14:41:59.601 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-06-03T14:41:59.627 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1426.11910.dll", hr=0x800710da 2026-06-03T14:42:00.051 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-06-03T14:42:00.114 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-06-03T14:42:00.667 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-03T14:42:00.677 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-06-03T14:42:00.841 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.outlookforwindows_1.2026.520.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-03T14:42:00.896 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-06-03T14:42:00.940 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-06-03T14:42:00.995 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-06-03T14:42:01.137 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:01.302 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-06-03T14:42:01.436 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-06-03T14:42:01.710 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-06-03T14:42:01.718 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:01.748 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-06-03T14:42:01.837 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-06-03T14:42:01.890 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-06-03T14:42:02.187 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-06-03T14:42:02.399 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-06-03T14:42:02.435 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:02.745 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-06-03T14:42:02.930 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-06-03T14:42:03.423 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:03.448 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:03.513 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:03.748 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-06-03T14:42:03.858 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-06-03T14:42:04.073 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-06-03T14:42:04.279 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-06-03T14:42:04.358 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-06-03T14:42:04.371 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-06-03T14:42:04.404 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:04.583 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-06-03T14:42:04.654 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-06-03T14:42:04.795 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-06-03T14:42:04.903 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-06-03T14:42:05.446 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-06-03T14:42:05.461 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-06-03T14:42:05.720 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-06-03T14:42:05.789 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-06-03T14:42:06.385 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-06-03T14:42:06.417 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-06-03T14:42:06.422 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:06.427 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-06-03T14:42:06.492 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-06-03T14:42:06.556 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-06-03T14:42:06.657 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-06-03T14:42:07.012 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-06-03T14:42:07.191 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-06-03T14:42:07.211 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:07.230 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2616.100.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-06-03T14:42:07.269 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-06-03T14:42:07.388 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-06-03T14:42:07.437 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-06-03T14:42:07.453 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-06-03T14:42:07.540 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\msteams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x800710da 2026-06-03T14:42:07.545 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-06-03T14:42:07.763 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-06-03T14:42:08.133 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-06-03T14:42:08.136 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-06-03T14:42:08.375 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-06-03T14:42:08.809 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-06-03T14:42:08.944 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:08.951 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-06-03T14:42:09.005 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-06-03T14:42:09.041 Engine:Setting original file name "msedgeupdate.dll" for "c:\program files (x86)\microsoft\edgeupdate\1.3.237.7\microsoftedgeupdateondemand.exe", hr=0x800710da 2026-06-03T14:42:09.251 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-06-03T14:42:09.260 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-06-03T14:42:09.480 Engine:Setting original file name "concrt140_app" for "c:\program files\windowsapps\microsoftteams_26135.501.4707.9551_x64__8wekyb3d8bbwe\concrt140_app.dll", hr=0x800710da 2026-06-03T14:42:09.541 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-06-03T14:42:09.616 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-06-03T14:42:09.622 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-06-03T14:42:09.695 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-06-03T14:42:09.705 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-06-03T14:42:09.741 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-06-03T14:42:10.118 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-06-03T14:42:10.168 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-03T14:42:10.255 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-06-03T14:42:10.291 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-06-03T14:42:10.431 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-06-03T14:42:10.564 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-06-03T14:42:10.618 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-06-03T14:42:10.652 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-06-03T14:42:10.786 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-06-03T14:42:11.275 Engine:Setting original file name "Common Diagnostics System SDK" for "c:\program files\windowsapps\microsoft.outlookforwindows_1.2026.520.0_x64__8wekyb3d8bbwe\cds.dll", hr=0x800710da 2026-06-03T14:42:11.329 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-06-03T14:42:11.371 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-06-03T14:42:11.382 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:11.441 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:11.815 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:11.901 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:12.067 Engine:Setting original file name "msedgeupdate.dll" for "c:\program files (x86)\microsoft\edgeupdate\1.3.237.7\psmachine.dll", hr=0x800710da 2026-06-03T14:42:12.236 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-06-03T14:42:12.279 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-06-03T14:42:12.435 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-06-03T14:42:12.547 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-06-03T14:42:12.588 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:12.602 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-06-03T14:42:12.914 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-06-03T14:42:12.994 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-06-03T14:42:13.066 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-06-03T14:42:13.146 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-06-03T14:42:13.162 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-06-03T14:42:13.251 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-06-03T14:42:13.375 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-06-03T14:42:13.473 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-06-03T14:42:13.537 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-06-03T14:42:13.556 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-06-03T14:42:13.566 Engine:Setting original file name "adobe_licensing_wf_helper.exe" for "c:\program files\adobe\acrobat dc\acrobat\ngl\cefworkflow\adobe_licensing_wf_helper_acro.exe", hr=0x800710da 2026-06-03T14:42:13.619 Engine:Setting original file name "vcomp140_app" for "c:\program files\windowsapps\microsoftteams_26135.501.4707.9551_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-06-03T14:42:13.776 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-06-03T14:42:13.782 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-06-03T14:42:13.946 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-06-03T14:42:14.402 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-06-03T14:42:14.625 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-06-03T14:42:14.680 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-06-03T14:42:15.032 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-06-03T14:42:15.100 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-06-03T14:42:15.156 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-06-03T14:42:15.248 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-06-03T14:42:15.352 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-06-03T14:42:15.368 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-06-03T14:42:15.556 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-06-03T14:42:15.712 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2620.102.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-06-03T14:42:15.719 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-06-03T14:42:15.926 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-06-03T14:42:16.046 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-06-03T14:42:16.135 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\msteams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-06-03T14:42:16.369 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-06-03T14:42:16.479 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-06-03T14:42:16.596 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-06-03T14:42:16.657 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.859.21.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:16.933 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11050.1001.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-06-03T14:42:16.992 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-06-03T14:42:17.028 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-06-03T14:42:17.146 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-06-03T14:42:17.158 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-06-03T14:42:17.280 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-06-03T14:42:17.335 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-06-03T14:42:17.487 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-06-03T14:42:17.578 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-06-03T14:42:17.582 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:17.834 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-06-03T14:42:18.093 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-06-03T14:42:18.286 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-06-03T14:42:18.327 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-03T14:42:18.429 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-06-03T14:42:18.860 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-06-03T14:42:18.939 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:18.958 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-06-03T14:42:19.407 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:20.030 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-06-03T14:42:20.141 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-06-03T14:42:20.238 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-06-03T14:42:20.586 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-06-03T14:42:20.609 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-06-03T14:42:20.632 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-06-03T14:42:20.901 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-06-03T14:42:21.140 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-06-03T14:42:21.176 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-06-03T14:42:21.300 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-06-03T14:42:21.520 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-06-03T14:42:21.531 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-06-03T14:42:21.757 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-06-03T14:42:21.920 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-06-03T14:42:21.940 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-06-03T14:42:22.034 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:22.430 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-06-03T14:42:22.488 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-06-03T14:42:22.512 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-06-03T14:42:22.582 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-06-03T14:42:22.904 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x800710da 2026-06-03T14:42:23.209 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-06-03T14:42:23.356 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-06-03T14:42:23.403 Engine:Setting original file name "msvcp140_atomic_wait_app" for "c:\program files\windowsapps\microsoftteams_26135.501.4707.9551_x64__8wekyb3d8bbwe\msvcp140_atomic_wait_app.dll", hr=0x800710da 2026-06-03T14:42:23.428 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-06-03T14:42:23.462 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-06-03T14:42:23.613 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-06-03T14:42:23.692 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-06-03T14:42:23.727 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-06-03T14:42:23.894 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:24.007 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-06-03T14:42:24.160 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-06-03T14:42:24.266 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-06-03T14:42:24.337 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-06-03T14:42:24.432 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-06-03T14:42:24.452 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-06-03T14:42:24.532 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-06-03T14:42:25.602 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-06-03T14:42:26.020 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-06-03T14:42:26.059 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-03T14:42:26.126 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-06-03T14:42:26.705 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-06-03T14:42:26.998 Engine:Setting original file name "vcamp140_app" for "c:\program files\windowsapps\msteams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-06-03T14:42:27.187 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-06-03T14:42:27.257 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-06-03T14:42:27.446 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-06-03T14:42:27.679 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-06-03T14:42:27.729 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-06-03T14:42:27.800 Engine:Setting original file name "Microsoft Cognitive Services Speech SDK" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2605.59121.0_x64__8wekyb3d8bbwe\microsoft.cognitiveservices.speech.extension.lu.dll", hr=0x800710da 2026-06-03T14:42:28.051 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-06-03T14:42:28.305 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-06-03T14:42:28.360 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-06-03T14:42:28.394 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-06-03T14:42:28.515 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-06-03T14:42:29.100 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-06-03T14:42:29.381 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-06-03T14:42:29.436 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-06-03T14:42:29.691 Engine:Setting original file name "SOA1000.DLL" for "c:\program files\microsoft office\updates\download\packagefiles\ae83010b-687a-4211-a254-d3fa30cd8454\root\office16\soa.dll", hr=0x800710da 2026-06-03T14:42:30.015 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-03T14:42:30.339 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-06-03T14:42:30.463 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-06-03T14:42:30.670 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:30.747 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:30.827 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-06-03T14:42:30.836 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:31.184 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-06-03T14:42:31.296 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-06-03T14:42:31.348 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-06-03T14:42:31.424 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-06-03T14:42:31.515 Engine:Setting original file name ".NET Host Policy - 8.0.27" for "c:\program files\windowsapps\microsoft.microsoftofficehub_19.2605.59121.0_x64__8wekyb3d8bbwe\shared\microsoft.netcore.app\8.0.27\hostpolicy.dll", hr=0x800710da 2026-06-03T14:42:31.523 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-06-03T14:42:31.543 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-06-03T14:42:31.553 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-06-03T14:42:31.596 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-06-03T14:42:31.605 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-06-03T14:42:31.845 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-03T14:42:31.853 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-06-03T14:42:31.897 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-06-03T14:42:32.023 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-06-03T14:42:32.145 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-06-03T14:42:32.349 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-06-03T14:42:32.595 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-06-03T14:42:32.833 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-06-03T14:42:32.973 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-06-03T14:42:33.051 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:33.447 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-06-03T14:42:33.568 Engine:Setting original file name "msvcp140_atomic_wait_app" for "c:\program files\windowsapps\msteams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msvcp140_atomic_wait_app.dll", hr=0x800710da 2026-06-03T14:42:33.724 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-06-03T14:42:33.783 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-06-03T14:42:34.016 Engine:Setting original file name "msvcp140_2_app" for "c:\program files\windowsapps\microsoftteams_26135.501.4707.9551_x64__8wekyb3d8bbwe\msvcp140_2_app.dll", hr=0x800710da 2026-06-03T14:42:34.058 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-06-03T14:42:34.354 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-06-03T14:42:34.421 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-06-03T14:42:34.466 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-06-03T14:42:34.486 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-06-03T14:42:34.493 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-06-03T14:42:34.553 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:34.845 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-06-03T14:42:34.857 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-06-03T14:42:35.427 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-06-03T14:42:35.507 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-06-03T14:42:36.094 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-06-03T14:42:36.110 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-06-03T14:42:36.299 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-06-03T14:42:36.359 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-06-03T14:42:36.417 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-06-03T14:42:37.068 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-06-03T14:42:37.162 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:37.304 Engine:Setting original file name "vcruntime140_1_app" for "c:\program files\windowsapps\microsoftteams_26135.501.4707.9551_x64__8wekyb3d8bbwe\vcruntime140_1_app.dll", hr=0x800710da 2026-06-03T14:42:37.363 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-06-03T14:42:37.558 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.outlookforwindows_1.2026.520.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-03T14:42:37.735 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-06-03T14:42:37.785 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-06-03T14:42:38.033 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-06-03T14:42:38.612 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-06-03T14:42:38.709 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-06-03T14:42:38.935 Engine:Setting original file name "WebInstaller.exe" for "c:\program files\adobe\acrobat dc\acrobat\acrocef\singleclientservicesupdater.exe", hr=0x800710da 2026-06-03T14:42:38.966 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-06-03T14:42:39.042 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:39.071 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-06-03T14:42:39.167 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v4.0.30319\accessibility.dll", hr=0x800710da 2026-06-03T14:42:39.258 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-06-03T14:42:39.469 Engine:Setting original file name "Microsoft.Management.Deployment.OutOfProc.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\microsoft.management.deployment.dll", hr=0x800710da 2026-06-03T14:42:39.505 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-06-03T14:42:39.538 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-06-03T14:42:40.192 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-06-03T14:42:40.505 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-06-03T14:42:40.629 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:40.761 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-06-03T14:42:41.224 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-06-03T14:42:41.331 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-06-03T14:42:41.379 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-06-03T14:42:41.405 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-06-03T14:42:41.470 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-06-03T14:42:41.489 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:41.616 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-06-03T14:42:41.663 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-06-03T14:42:41.778 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-06-03T14:42:41.842 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-06-03T14:42:41.953 Engine:Setting original file name "vcamp140_app" for "c:\program files\windowsapps\microsoft.gamingapp_2605.1001.14.0_x64__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-06-03T14:42:41.971 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-06-03T14:42:42.095 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-06-03T14:42:42.389 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-06-03T14:42:42.471 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-06-03T14:42:42.642 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-06-03T14:42:42.875 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-06-03T14:42:43.178 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-06-03T14:42:43.274 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:43.765 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-06-03T14:42:44.148 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-06-03T14:42:44.459 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-06-03T14:42:44.516 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-06-03T14:42:44.575 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-06-03T14:42:44.845 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-06-03T14:42:44.975 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-06-03T14:42:45.094 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-06-03T14:42:45.565 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-06-03T14:42:45.763 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-06-03T14:42:45.783 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-06-03T14:42:45.976 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:45.984 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-06-03T14:42:45.998 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-06-03T14:42:46.481 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-06-03T14:42:46.533 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-06-03T14:42:46.606 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-06-03T14:42:46.883 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-06-03T14:42:47.154 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.8_8000.859.21.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-03T14:42:47.176 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-06-03T14:42:47.251 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-06-03T14:42:47.302 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-06-03T14:42:47.321 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-06-03T14:42:47.443 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-06-03T14:42:48.176 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-06-03T14:42:48.416 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-06-03T14:42:48.421 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-06-03T14:42:48.471 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-06-03T14:42:48.680 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:48.794 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-06-03T14:42:49.119 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-06-03T14:42:49.123 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-06-03T14:42:49.128 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-06-03T14:42:49.442 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-06-03T14:42:49.669 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-06-03T14:42:49.790 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-06-03T14:42:49.996 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-06-03T14:42:50.083 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-06-03T14:42:50.177 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-06-03T14:42:50.212 Engine:Setting original file name "TWINUI.dll" for "c:\windows\winsxs\amd64_microsoft-windows-twinui_31bf3856ad364e35_10.0.22000.2538_none_ecbf26dcf11a684d\twinui.dll.mun", hr=0x800710da 2026-06-03T14:42:50.256 Engine:Setting original file name "fips" for "c:\program files\adobe\acrobat dc\acrobat\ossllibs\fips-adobe.dll", hr=0x800710da 2026-06-03T14:42:50.552 OriginalFileName Maintenance::9821 files in Moac, 224 skipped (cached), 2 filename set 2026-06-03T14:42:50.552 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-06-03T14:43:03.042 QuickScan:ScanID:0E3775AC-6968-4BE8-96DD-89A1AAD20C53: Quick scan finished with error 0 2026-06-03T14:43:03.562 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-03T14:43:03.562 [RTP] Duplicating the current plugin configuration object... 2026-06-03T14:43:03.562 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-03T14:43:03.562 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-06-03T14:43:03.562 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-03T14:43:03.562 [RTP] No config change detected. Not updating plugin configuration. 2026-06-03T14:43:03.562 [RTP] No config changes found. No configuration switch. 2026-06-03T14:43:03.562 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-06-03T14:43:05.062 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:43:05.069 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-03T14:43:05.071 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-03T14:44:48.161 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #19111, FileId: 0x11a0000000016fc, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:44:49.441 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-06-03T14:54:36.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T14:54:40.684 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20497, FileId: 0x107000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.686 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20500, FileId: 0x108000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.687 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20501, FileId: 0x8a000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.688 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20499, FileId: 0x89000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.688 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20503, FileId: 0x109000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.692 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20496, FileId: 0x106000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.692 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20504, FileId: 0x8b000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.695 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20505, FileId: 0x10a000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.697 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20498, FileId: 0x88000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.712 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20509, FileId: 0x10c000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.712 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20510, FileId: 0x8e000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.714 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20513, FileId: 0x8f000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.714 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20507, FileId: 0x10b000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.717 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20511, FileId: 0x10d000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.720 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20514, FileId: 0x90000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.730 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20516, FileId: 0x91000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.733 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20519, FileId: 0x93000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.733 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20518, FileId: 0x92000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.735 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20512, FileId: 0x10e000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.735 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20517, FileId: 0x110000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.737 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20520, FileId: 0x111000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:40.737 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #20521, FileId: 0x112000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T14:54:41.104 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13cefe48-4eb4-4d9e-a22f-53b88832b374. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #20555, FileId: 0xd60000000051c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T15:00:05.992 Bm signature throttled:0x00002db31bed458f 2026-06-03T15:09:41.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T15:24:46.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T15:33:38.706 Bm signature throttled:0x00002db31bed458f 2026-06-03T15:39:51.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T15:54:56.384 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T16:10:01.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T16:11:51.209 Bm signature throttled:0x00002db31bed458f 2026-06-03T16:15:28.573 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24223, FileId: 0xe00000000045e9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:19:26.188 ProcessImageName: svchost.exe, Pid: 11508, TotalTime: 24257, Count: 18, MaxTime: 11843, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOEC50.tmp, EstimatedImpact: 2% 2026-06-03T16:19:26.188 ProcessImageName: VirtualBoxVM.exe, Pid: 7076, TotalTime: 16442, Count: 26, MaxTime: 5125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\VirtualBox Dropped Files\2026-06-03T14_28_39.662824800Z\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: explorer.exe, Pid: 3600, TotalTime: 13470, Count: 133, MaxTime: 5171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2912, TotalTime: 10077, Count: 2, MaxTime: 9968, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\MicrosoftEdge_X64_148.0.3967.96.exe, EstimatedImpact: 17% 2026-06-03T16:19:26.188 ProcessImageName: VirtualBoxVM.exe, Pid: 3912, TotalTime: 8514, Count: 50, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 5% 2026-06-03T16:19:26.188 ProcessImageName: setup.exe, Pid: 2852, TotalTime: 7857, Count: 78, MaxTime: 4812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\msedge.dll, EstimatedImpact: 33% 2026-06-03T16:19:26.188 ProcessImageName: setup.exe, Pid: 12664, TotalTime: 3185, Count: 353, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\Locales\bs.pak, EstimatedImpact: 41% 2026-06-03T16:19:26.188 ProcessImageName: SrTasks.exe, Pid: 7144, TotalTime: 3000, Count: 388, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\Windows\System32\DriverStore\FileRepository\1394.inf_amd64_aee05b5c33eee9d2\1394.inf->(UTF-16LE), EstimatedImpact: 28% 2026-06-03T16:19:26.188 ProcessImageName: taskhostw.exe, Pid: 11060, TotalTime: 2721, Count: 25, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-03T16:19:26.188 ProcessImageName: VBoxSVC.exe, Pid: 11120, TotalTime: 2299, Count: 29, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: Integrator.exe, Pid: 12644, TotalTime: 2238, Count: 245, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.excelmui.msi.16.de-de.xml, EstimatedImpact: 9% 2026-06-03T16:19:26.188 ProcessImageName: VSSVC.exe, Pid: 6300, TotalTime: 1640, Count: 2, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-06-03T16:19:26.188 ProcessImageName: OfficeClickToRun.exe, Pid: 2428, TotalTime: 1311, Count: 37, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: AddInUtil.exe, Pid: 9380, TotalTime: 868, Count: 14, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 53% 2026-06-03T16:19:26.188 ProcessImageName: VirtualBox.exe, Pid: 10832, TotalTime: 723, Count: 70, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7z.exe, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: sdiagnhost.exe, Pid: 3420, TotalTime: 709, Count: 43, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T16:19:26.188 ProcessImageName: WmiPrvSE.exe, Pid: 7504, TotalTime: 709, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-03T16:19:26.188 ProcessImageName: wevtutil.exe, Pid: 10500, TotalTime: 702, Count: 2, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 63% 2026-06-03T16:19:26.188 ProcessImageName: Integrator.exe, Pid: 7256, TotalTime: 666, Count: 65, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: svchost.exe, Pid: 1464, TotalTime: 606, Count: 50, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\opushutil.exe, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: firefox.exe, Pid: 3772, TotalTime: 555, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 42% 2026-06-03T16:19:26.188 ProcessImageName: wevtutil.exe, Pid: 11100, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 86% 2026-06-03T16:19:26.188 ProcessImageName: powershell.exe, Pid: 10124, TotalTime: 477, Count: 31, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T16:19:26.188 ProcessImageName: VirtualBoxVM.exe, Pid: 5404, TotalTime: 300, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.22000.1761.cat, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: ngentask.exe, Pid: 10812, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: backgroundTaskHost.exe, Pid: 2716, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1780496358, EstimatedImpact: 3% 2026-06-03T16:19:26.188 ProcessImageName: ngentask.exe, Pid: 6544, TotalTime: 210, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: backgroundTaskHost.exe, Pid: 7976, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 5% 2026-06-03T16:19:26.188 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70.exe, Pid: 7796, TotalTime: 170, Count: 4, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B9892DF6-BCA0-49A9-957B-DA020EBDF5B8}\EDGEMITMP_E6231.tmp\setup.exe, EstimatedImpact: 1% 2026-06-03T16:19:26.188 ProcessImageName: taskhostw.exe, Pid: 3564, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 67% 2026-06-03T16:19:26.188 ProcessImageName: taskhostw.exe, Pid: 3728, TotalTime: 167, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_88e8fb3d-9ec6-4f24-9dfc-d3cc1155ae79\DiagPackage.diagpkg, EstimatedImpact: 39% 2026-06-03T16:19:26.188 ProcessImageName: ngentask.exe, Pid: 5880, TotalTime: 150, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96.exe, Pid: 13256, TotalTime: 109, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\EDGEMITMP_27F4F.tmp\setup.exe, EstimatedImpact: 51% 2026-06-03T16:19:26.188 ProcessImageName: AggregatorHost.exe, Pid: 5856, TotalTime: 107, Count: 4, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96_148.0.3967.83.exe, Pid: 7680, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{FAF845CD-61B0-47AA-827D-CE0A0A909AC0}\EDGEMITMP_7A785.tmp\setup.exe, EstimatedImpact: 52% 2026-06-03T16:19:26.188 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: spoolsv.exe, Pid: 3220, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\A35917FB-3745-4691-9EA8-F1FB29B7B68C\merged.gpd, EstimatedImpact: 32% 2026-06-03T16:19:26.188 ProcessImageName: dllhost.exe, Pid: 7904, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{56cbbacb-5d2e-4116-949a-06b0c13d7251}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-03T16:19:26.188 ProcessImageName: vc_redist.x64.exe, Pid: 11792, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{34830364-BEF3-4080-A8EE-58CD957529F0}\.ba\wixstdba.dll, EstimatedImpact: 22% 2026-06-03T16:19:26.189 ProcessImageName: vc_redist.x86.exe, Pid: 6988, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 30% 2026-06-03T16:19:26.189 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 9% 2026-06-03T16:19:26.189 ProcessImageName: RuntimeBroker.exe, Pid: 6908, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.down_data, EstimatedImpact: 7% 2026-06-03T16:19:26.189 ProcessImageName: OfficeClickToRun.exe, Pid: 13276, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: BackgroundTransferHost.exe, Pid: 12948, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.up_meta_secure, EstimatedImpact: 14% 2026-06-03T16:19:26.189 ProcessImageName: ngentask.exe, Pid: 3076, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 22% 2026-06-03T16:19:26.189 ProcessImageName: OfficeC2RClient.exe, Pid: 5500, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1815.log, EstimatedImpact: 2% 2026-06-03T16:19:26.189 ProcessImageName: taskhostw.exe, Pid: 10972, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 1% 2026-06-03T16:19:26.189 ProcessImageName: OfficeClickToRun.exe, Pid: 12744, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: PhoneExperienceHost.exe, Pid: 5712, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 8% 2026-06-03T16:19:26.189 ProcessImageName: AdobeCollabSync.exe, Pid: 10496, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: , Pid: 4, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 5% 2026-06-03T16:19:26.189 ProcessImageName: dllhost.exe, Pid: 5692, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: tzsync.exe, Pid: 13000, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 9% 2026-06-03T16:19:26.189 ProcessImageName: backgroundTaskHost.exe, Pid: 4896, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-06-03T16:19:26.189 ProcessImageName: svchost.exe, Pid: 3772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\ActionsServer.msix, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: svchost.exe, Pid: 8048, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 2604, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\pinning.db, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: sihost.exe, Pid: 5680, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk->[CMDEmbedded], EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: OfficeC2RClient.exe, Pid: 13268, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1636.log, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: brynhildr.exe, Pid: 4432, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-03T16:19:26.189 ProcessImageName: DismHost.exe, Pid: 3672, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-03T16:25:06.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T16:40:11.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T16:40:53.272 Bm signature throttled:0x00002db31bed458f 2026-06-03T16:49:05.331 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24435, FileId: 0x9a000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.332 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24438, FileId: 0x118000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.335 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24436, FileId: 0x117000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.338 Bm signature throttled:0x000045b3435c1067 2026-06-03T16:49:05.339 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24439, FileId: 0x9b000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.341 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24441, FileId: 0x9c000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.343 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24434, FileId: 0x115000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.345 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24444, FileId: 0x11b000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.348 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24443, FileId: 0x9d000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.350 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24446, FileId: 0x11c000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.350 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24442, FileId: 0x11a000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.353 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24445, FileId: 0x9e000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.356 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24448, FileId: 0x11d000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.378 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24449, FileId: 0xa0000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.380 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24454, FileId: 0x121000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.381 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24452, FileId: 0x11f000000002475, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.381 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24456, FileId: 0xa4000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.384 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24453, FileId: 0xa3000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:49:05.796 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\326e03b7-f2b6-4174-8060-f12006b10a9e. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #24490, FileId: 0xdd00000000abc6, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T16:54:37.075 Bm signature throttled:0x00002db31bed458f 2026-06-03T16:55:16.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T17:10:21.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T17:18:42.280 Bm signature throttled:0x00002db31bed458f 2026-06-03T17:25:26.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T17:40:31.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T17:44:32.263 Bm signature throttled:0x00002db31bed458f 2026-06-03T17:55:36.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T18:03:28.934 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #24873, FileId: 0x49500000000a9d8, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T18:05:57.527 Bm signature throttled:0x00002db31bed458f 2026-06-03T18:10:41.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T18:19:26.189 ProcessImageName: svchost.exe, Pid: 11508, TotalTime: 24257, Count: 18, MaxTime: 11843, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOEC50.tmp, EstimatedImpact: 2% 2026-06-03T18:19:26.189 ProcessImageName: VirtualBoxVM.exe, Pid: 7076, TotalTime: 16442, Count: 26, MaxTime: 5125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\VirtualBox Dropped Files\2026-06-03T14_28_39.662824800Z\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T18:19:26.189 ProcessImageName: explorer.exe, Pid: 3600, TotalTime: 13470, Count: 133, MaxTime: 5171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T18:19:26.189 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2912, TotalTime: 10077, Count: 2, MaxTime: 9968, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\MicrosoftEdge_X64_148.0.3967.96.exe, EstimatedImpact: 17% 2026-06-03T18:19:26.189 ProcessImageName: VirtualBoxVM.exe, Pid: 3912, TotalTime: 8514, Count: 50, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 5% 2026-06-03T18:19:26.189 ProcessImageName: setup.exe, Pid: 2852, TotalTime: 7857, Count: 78, MaxTime: 4812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\msedge.dll, EstimatedImpact: 33% 2026-06-03T18:19:26.189 ProcessImageName: setup.exe, Pid: 12664, TotalTime: 3185, Count: 353, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\Locales\bs.pak, EstimatedImpact: 41% 2026-06-03T18:19:26.190 ProcessImageName: SrTasks.exe, Pid: 7144, TotalTime: 3000, Count: 388, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\Windows\System32\DriverStore\FileRepository\1394.inf_amd64_aee05b5c33eee9d2\1394.inf->(UTF-16LE), EstimatedImpact: 28% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 11060, TotalTime: 2721, Count: 25, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-03T18:19:26.190 ProcessImageName: VBoxSVC.exe, Pid: 11120, TotalTime: 2299, Count: 29, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: Integrator.exe, Pid: 12644, TotalTime: 2238, Count: 245, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.excelmui.msi.16.de-de.xml, EstimatedImpact: 9% 2026-06-03T18:19:26.190 ProcessImageName: VSSVC.exe, Pid: 6300, TotalTime: 1640, Count: 2, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-06-03T18:19:26.190 ProcessImageName: SDXHelper.exe, Pid: 2032, TotalTime: 1620, Count: 165, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-06-03T18:19:26.190 ProcessImageName: OfficeClickToRun.exe, Pid: 2428, TotalTime: 1311, Count: 37, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: AddInUtil.exe, Pid: 9380, TotalTime: 868, Count: 14, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 53% 2026-06-03T18:19:26.190 ProcessImageName: VirtualBox.exe, Pid: 10832, TotalTime: 723, Count: 70, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7z.exe, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: svchost.exe, Pid: 1464, TotalTime: 712, Count: 58, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\opushutil.exe, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: sdiagnhost.exe, Pid: 3420, TotalTime: 709, Count: 43, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T18:19:26.190 ProcessImageName: WmiPrvSE.exe, Pid: 7504, TotalTime: 709, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-03T18:19:26.190 ProcessImageName: wevtutil.exe, Pid: 10500, TotalTime: 702, Count: 2, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 63% 2026-06-03T18:19:26.190 ProcessImageName: Integrator.exe, Pid: 7256, TotalTime: 666, Count: 65, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: firefox.exe, Pid: 3772, TotalTime: 555, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 42% 2026-06-03T18:19:26.190 ProcessImageName: wevtutil.exe, Pid: 11100, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 86% 2026-06-03T18:19:26.190 ProcessImageName: SDXHelper.exe, Pid: 10488, TotalTime: 480, Count: 11, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 16% 2026-06-03T18:19:26.190 ProcessImageName: powershell.exe, Pid: 10124, TotalTime: 477, Count: 31, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T18:19:26.190 ProcessImageName: firefox.exe, Pid: 8864, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05984, EstimatedImpact: 55% 2026-06-03T18:19:26.190 ProcessImageName: VirtualBoxVM.exe, Pid: 5404, TotalTime: 300, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.22000.1761.cat, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: ngentask.exe, Pid: 10812, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: backgroundTaskHost.exe, Pid: 2716, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1780496358, EstimatedImpact: 3% 2026-06-03T18:19:26.190 ProcessImageName: ngentask.exe, Pid: 6544, TotalTime: 210, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: backgroundTaskHost.exe, Pid: 7976, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 5% 2026-06-03T18:19:26.190 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70.exe, Pid: 7796, TotalTime: 170, Count: 4, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B9892DF6-BCA0-49A9-957B-DA020EBDF5B8}\EDGEMITMP_E6231.tmp\setup.exe, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 3564, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 67% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 3728, TotalTime: 167, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_88e8fb3d-9ec6-4f24-9dfc-d3cc1155ae79\DiagPackage.diagpkg, EstimatedImpact: 39% 2026-06-03T18:19:26.190 ProcessImageName: AggregatorHost.exe, Pid: 5856, TotalTime: 153, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: ngentask.exe, Pid: 5880, TotalTime: 150, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96.exe, Pid: 13256, TotalTime: 109, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\EDGEMITMP_27F4F.tmp\setup.exe, EstimatedImpact: 51% 2026-06-03T18:19:26.190 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96_148.0.3967.83.exe, Pid: 7680, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{FAF845CD-61B0-47AA-827D-CE0A0A909AC0}\EDGEMITMP_7A785.tmp\setup.exe, EstimatedImpact: 52% 2026-06-03T18:19:26.190 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 77, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: spoolsv.exe, Pid: 3220, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\A35917FB-3745-4691-9EA8-F1FB29B7B68C\merged.gpd, EstimatedImpact: 32% 2026-06-03T18:19:26.190 ProcessImageName: dllhost.exe, Pid: 7904, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{56cbbacb-5d2e-4116-949a-06b0c13d7251}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: vc_redist.x64.exe, Pid: 11792, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{34830364-BEF3-4080-A8EE-58CD957529F0}\.ba\wixstdba.dll, EstimatedImpact: 22% 2026-06-03T18:19:26.190 ProcessImageName: vc_redist.x86.exe, Pid: 6988, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 30% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 9% 2026-06-03T18:19:26.190 ProcessImageName: RuntimeBroker.exe, Pid: 6908, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.down_data, EstimatedImpact: 7% 2026-06-03T18:19:26.190 ProcessImageName: OfficeClickToRun.exe, Pid: 13276, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: dasHost.exe, Pid: 5556, TotalTime: 60, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: BackgroundTransferHost.exe, Pid: 12948, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.up_meta_secure, EstimatedImpact: 14% 2026-06-03T18:19:26.190 ProcessImageName: ngentask.exe, Pid: 3076, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 22% 2026-06-03T18:19:26.190 ProcessImageName: OfficeC2RClient.exe, Pid: 5500, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1815.log, EstimatedImpact: 2% 2026-06-03T18:19:26.190 ProcessImageName: dllhost.exe, Pid: 5692, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 10972, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: PhoneExperienceHost.exe, Pid: 5712, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 8% 2026-06-03T18:19:26.190 ProcessImageName: OfficeClickToRun.exe, Pid: 12744, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: AdobeCollabSync.exe, Pid: 10496, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: , Pid: 4, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 5% 2026-06-03T18:19:26.190 ProcessImageName: tzsync.exe, Pid: 13000, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 9% 2026-06-03T18:19:26.190 ProcessImageName: backgroundTaskHost.exe, Pid: 4896, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-06-03T18:19:26.190 ProcessImageName: svchost.exe, Pid: 3772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\ActionsServer.msix, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: svchost.exe, Pid: 8048, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 2604, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\pinning.db, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: OfficeC2RClient.exe, Pid: 13268, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1636.log, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: sihost.exe, Pid: 5680, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk->[CMDEmbedded], EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: brynhildr.exe, Pid: 4432, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-03T18:19:26.190 ProcessImageName: DismHost.exe, Pid: 3672, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-03T18:25:46.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T18:40:51.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T18:55:56.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T18:58:38.971 Bm signature throttled:0x00002db31bed458f 2026-06-03T18:59:01.572 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26416, FileId: 0x3c000000010dd1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T19:07:33.572 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26588, FileId: 0x2500000001a828, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T19:10:07.556 Bm signature throttled:0x00002db31bed458f 2026-06-03T19:11:01.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T19:26:06.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T19:41:11.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T19:50:29.192 Bm signature throttled:0x00002db31bed458f 2026-06-03T19:53:04.551 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #26765, FileId: 0x2300000001bb78, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T19:56:16.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T20:11:21.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T20:15:07.912 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #26926, FileId: 0x75000000010907, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T20:19:26.191 ProcessImageName: svchost.exe, Pid: 11508, TotalTime: 24257, Count: 18, MaxTime: 11843, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOEC50.tmp, EstimatedImpact: 2% 2026-06-03T20:19:26.191 ProcessImageName: VirtualBoxVM.exe, Pid: 7076, TotalTime: 16442, Count: 26, MaxTime: 5125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\VirtualBox Dropped Files\2026-06-03T14_28_39.662824800Z\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: explorer.exe, Pid: 3600, TotalTime: 14008, Count: 154, MaxTime: 5171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2912, TotalTime: 10077, Count: 2, MaxTime: 9968, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\MicrosoftEdge_X64_148.0.3967.96.exe, EstimatedImpact: 17% 2026-06-03T20:19:26.191 ProcessImageName: VirtualBoxVM.exe, Pid: 3912, TotalTime: 8514, Count: 50, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 5% 2026-06-03T20:19:26.191 ProcessImageName: setup.exe, Pid: 2852, TotalTime: 7857, Count: 78, MaxTime: 4812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\msedge.dll, EstimatedImpact: 33% 2026-06-03T20:19:26.191 ProcessImageName: setup.exe, Pid: 12664, TotalTime: 3185, Count: 353, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\Locales\bs.pak, EstimatedImpact: 41% 2026-06-03T20:19:26.191 ProcessImageName: SrTasks.exe, Pid: 7144, TotalTime: 3000, Count: 388, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\Windows\System32\DriverStore\FileRepository\1394.inf_amd64_aee05b5c33eee9d2\1394.inf->(UTF-16LE), EstimatedImpact: 28% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 11060, TotalTime: 2721, Count: 25, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-03T20:19:26.191 ProcessImageName: VBoxSVC.exe, Pid: 11120, TotalTime: 2299, Count: 29, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: Integrator.exe, Pid: 12644, TotalTime: 2238, Count: 245, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.excelmui.msi.16.de-de.xml, EstimatedImpact: 9% 2026-06-03T20:19:26.191 ProcessImageName: VSSVC.exe, Pid: 6300, TotalTime: 1640, Count: 2, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-06-03T20:19:26.191 ProcessImageName: SDXHelper.exe, Pid: 2032, TotalTime: 1620, Count: 165, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-06-03T20:19:26.191 ProcessImageName: OfficeClickToRun.exe, Pid: 2428, TotalTime: 1311, Count: 37, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: notepad++.exe, Pid: 8104, TotalTime: 1236, Count: 60, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 5% 2026-06-03T20:19:26.191 ProcessImageName: AddInUtil.exe, Pid: 9380, TotalTime: 868, Count: 14, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 53% 2026-06-03T20:19:26.191 ProcessImageName: svchost.exe, Pid: 1464, TotalTime: 803, Count: 64, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\opushutil.exe, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: VirtualBox.exe, Pid: 10832, TotalTime: 723, Count: 70, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7z.exe, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: sdiagnhost.exe, Pid: 3420, TotalTime: 709, Count: 43, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T20:19:26.191 ProcessImageName: WmiPrvSE.exe, Pid: 7504, TotalTime: 709, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-03T20:19:26.191 ProcessImageName: wevtutil.exe, Pid: 10500, TotalTime: 702, Count: 2, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 63% 2026-06-03T20:19:26.191 ProcessImageName: Integrator.exe, Pid: 7256, TotalTime: 666, Count: 65, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: firefox.exe, Pid: 3772, TotalTime: 555, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 42% 2026-06-03T20:19:26.191 ProcessImageName: wevtutil.exe, Pid: 11100, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 86% 2026-06-03T20:19:26.191 ProcessImageName: SDXHelper.exe, Pid: 10488, TotalTime: 480, Count: 11, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 16% 2026-06-03T20:19:26.191 ProcessImageName: powershell.exe, Pid: 10124, TotalTime: 477, Count: 31, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T20:19:26.191 ProcessImageName: firefox.exe, Pid: 8864, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05984, EstimatedImpact: 55% 2026-06-03T20:19:26.191 ProcessImageName: VirtualBoxVM.exe, Pid: 5404, TotalTime: 300, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.22000.1761.cat, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: FileCoAuth.exe, Pid: 7216, TotalTime: 243, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\Telemetry.dll, EstimatedImpact: 3% 2026-06-03T20:19:26.191 ProcessImageName: ngentask.exe, Pid: 10812, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: backgroundTaskHost.exe, Pid: 2716, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1780496358, EstimatedImpact: 3% 2026-06-03T20:19:26.191 ProcessImageName: ngentask.exe, Pid: 6544, TotalTime: 210, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: backgroundTaskHost.exe, Pid: 7976, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 5% 2026-06-03T20:19:26.191 ProcessImageName: AggregatorHost.exe, Pid: 5856, TotalTime: 183, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70.exe, Pid: 7796, TotalTime: 170, Count: 4, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B9892DF6-BCA0-49A9-957B-DA020EBDF5B8}\EDGEMITMP_E6231.tmp\setup.exe, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 3564, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 67% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 3728, TotalTime: 167, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_88e8fb3d-9ec6-4f24-9dfc-d3cc1155ae79\DiagPackage.diagpkg, EstimatedImpact: 39% 2026-06-03T20:19:26.191 ProcessImageName: ngentask.exe, Pid: 5880, TotalTime: 150, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: dasHost.exe, Pid: 5556, TotalTime: 120, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96.exe, Pid: 13256, TotalTime: 109, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\EDGEMITMP_27F4F.tmp\setup.exe, EstimatedImpact: 51% 2026-06-03T20:19:26.191 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96_148.0.3967.83.exe, Pid: 7680, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{FAF845CD-61B0-47AA-827D-CE0A0A909AC0}\EDGEMITMP_7A785.tmp\setup.exe, EstimatedImpact: 52% 2026-06-03T20:19:26.191 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: spoolsv.exe, Pid: 3220, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\A35917FB-3745-4691-9EA8-F1FB29B7B68C\merged.gpd, EstimatedImpact: 32% 2026-06-03T20:19:26.191 ProcessImageName: dllhost.exe, Pid: 7904, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{56cbbacb-5d2e-4116-949a-06b0c13d7251}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: vc_redist.x64.exe, Pid: 11792, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{34830364-BEF3-4080-A8EE-58CD957529F0}\.ba\wixstdba.dll, EstimatedImpact: 22% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 9% 2026-06-03T20:19:26.191 ProcessImageName: vc_redist.x86.exe, Pid: 6988, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 30% 2026-06-03T20:19:26.191 ProcessImageName: RuntimeBroker.exe, Pid: 6908, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.down_data, EstimatedImpact: 7% 2026-06-03T20:19:26.191 ProcessImageName: OfficeClickToRun.exe, Pid: 13276, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: svchost.exe, Pid: 5264, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_4532_1014451980\BIT8B42.tmp, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: BackgroundTransferHost.exe, Pid: 12948, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.up_meta_secure, EstimatedImpact: 14% 2026-06-03T20:19:26.191 ProcessImageName: dllhost.exe, Pid: 5692, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: ngentask.exe, Pid: 3076, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 22% 2026-06-03T20:19:26.191 ProcessImageName: OfficeC2RClient.exe, Pid: 5500, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1815.log, EstimatedImpact: 2% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 10972, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 1% 2026-06-03T20:19:26.191 ProcessImageName: OfficeClickToRun.exe, Pid: 12744, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-03T20:19:26.191 ProcessImageName: PhoneExperienceHost.exe, Pid: 5712, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 8% 2026-06-03T20:19:26.192 ProcessImageName: GUP.exe, Pid: 9588, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\gup.xml, EstimatedImpact: 1% 2026-06-03T20:19:26.192 ProcessImageName: AdobeCollabSync.exe, Pid: 10496, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: , Pid: 4, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 5% 2026-06-03T20:19:26.192 ProcessImageName: tzsync.exe, Pid: 13000, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 9% 2026-06-03T20:19:26.192 ProcessImageName: backgroundTaskHost.exe, Pid: 4896, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-06-03T20:19:26.192 ProcessImageName: OfficeC2RClient.exe, Pid: 5912, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-2153.log, EstimatedImpact: 1% 2026-06-03T20:19:26.192 ProcessImageName: OfficeC2RClient.exe, Pid: 9432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-2058.log, EstimatedImpact: 1% 2026-06-03T20:19:26.192 ProcessImageName: svchost.exe, Pid: 3772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\ActionsServer.msix, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: svchost.exe, Pid: 8048, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 2604, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\pinning.db, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: OfficeC2RClient.exe, Pid: 13268, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1636.log, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: sihost.exe, Pid: 5680, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk->[CMDEmbedded], EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: OfficeC2RClient.exe, Pid: 5372, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-2107.log, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: brynhildr.exe, Pid: 4432, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-03T20:19:26.192 ProcessImageName: DismHost.exe, Pid: 3672, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-03T20:26:26.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T20:41:31.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T20:56:36.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T21:11:41.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T21:26:46.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T21:41:51.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T21:54:40.148 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27521, FileId: 0xa7000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.148 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27523, FileId: 0xa9000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.152 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27520, FileId: 0x121000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.152 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27526, FileId: 0xac000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.155 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27528, FileId: 0xae000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.156 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27529, FileId: 0x127000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.158 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27530, FileId: 0x128000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.159 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27527, FileId: 0x126000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.160 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27525, FileId: 0x125000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.161 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27524, FileId: 0x123000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.162 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27522, FileId: 0x122000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.164 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27534, FileId: 0xb0000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.164 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27533, FileId: 0x129000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.167 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27531, FileId: 0xaf000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.169 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27535, FileId: 0x12a000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.182 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27539, FileId: 0x12c000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.184 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27540, FileId: 0x12d000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.184 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #27537, FileId: 0x12b000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:54:40.597 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\501bd49d-4bc0-4063-9252-172e81413ecd. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #27574, FileId: 0xba00000000b4ff, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-03T21:56:56.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T22:12:01.385 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-03T22:19:26.192 ProcessImageName: svchost.exe, Pid: 11508, TotalTime: 24257, Count: 18, MaxTime: 11843, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOEC50.tmp, EstimatedImpact: 2% 2026-06-03T22:19:26.192 ProcessImageName: VirtualBoxVM.exe, Pid: 7076, TotalTime: 16442, Count: 26, MaxTime: 5125, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\VirtualBox Dropped Files\2026-06-03T14_28_39.662824800Z\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-03T22:19:26.192 ProcessImageName: explorer.exe, Pid: 3600, TotalTime: 14008, Count: 154, MaxTime: 5171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-03T22:19:26.192 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2912, TotalTime: 10077, Count: 2, MaxTime: 9968, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\MicrosoftEdge_X64_148.0.3967.96.exe, EstimatedImpact: 17% 2026-06-03T22:19:26.192 ProcessImageName: VirtualBoxVM.exe, Pid: 3912, TotalTime: 8514, Count: 50, MaxTime: 1078, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 5% 2026-06-03T22:19:26.193 ProcessImageName: setup.exe, Pid: 2852, TotalTime: 7857, Count: 78, MaxTime: 4812, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\msedge.dll, EstimatedImpact: 33% 2026-06-03T22:19:26.193 ProcessImageName: setup.exe, Pid: 12664, TotalTime: 3185, Count: 353, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\148.0.3967.96\Locales\bs.pak, EstimatedImpact: 41% 2026-06-03T22:19:26.193 ProcessImageName: SrTasks.exe, Pid: 7144, TotalTime: 3000, Count: 388, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\Windows\System32\DriverStore\FileRepository\1394.inf_amd64_aee05b5c33eee9d2\1394.inf->(UTF-16LE), EstimatedImpact: 28% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 11060, TotalTime: 2721, Count: 25, MaxTime: 1828, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-03T22:19:26.193 ProcessImageName: VBoxSVC.exe, Pid: 11120, TotalTime: 2299, Count: 29, MaxTime: 1015, MaxTimeFile: \Device\HarddiskVolume5\vhd+ISOs\VHD\Windows7_32bit.vhd, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: Integrator.exe, Pid: 12644, TotalTime: 2238, Count: 245, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.excelmui.msi.16.de-de.xml, EstimatedImpact: 9% 2026-06-03T22:19:26.193 ProcessImageName: VSSVC.exe, Pid: 6300, TotalTime: 1640, Count: 2, MaxTime: 828, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-06-03T22:19:26.193 ProcessImageName: SDXHelper.exe, Pid: 2032, TotalTime: 1620, Count: 165, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 2% 2026-06-03T22:19:26.193 ProcessImageName: OfficeClickToRun.exe, Pid: 2428, TotalTime: 1311, Count: 37, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: notepad++.exe, Pid: 8104, TotalTime: 1236, Count: 60, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 5% 2026-06-03T22:19:26.193 ProcessImageName: AddInUtil.exe, Pid: 9380, TotalTime: 868, Count: 14, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 53% 2026-06-03T22:19:26.193 ProcessImageName: svchost.exe, Pid: 1464, TotalTime: 848, Count: 69, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\opushutil.exe, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: VirtualBox.exe, Pid: 10832, TotalTime: 723, Count: 70, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7z.exe, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: sdiagnhost.exe, Pid: 3420, TotalTime: 709, Count: 43, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T22:19:26.193 ProcessImageName: WmiPrvSE.exe, Pid: 7504, TotalTime: 709, Count: 16, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-03T22:19:26.193 ProcessImageName: wevtutil.exe, Pid: 10500, TotalTime: 702, Count: 2, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 63% 2026-06-03T22:19:26.193 ProcessImageName: Integrator.exe, Pid: 7256, TotalTime: 666, Count: 65, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: firefox.exe, Pid: 3772, TotalTime: 555, Count: 51, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 42% 2026-06-03T22:19:26.193 ProcessImageName: wevtutil.exe, Pid: 11100, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 86% 2026-06-03T22:19:26.193 ProcessImageName: SDXHelper.exe, Pid: 10488, TotalTime: 480, Count: 11, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 16% 2026-06-03T22:19:26.193 ProcessImageName: powershell.exe, Pid: 10124, TotalTime: 477, Count: 31, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 26% 2026-06-03T22:19:26.193 ProcessImageName: firefox.exe, Pid: 8864, TotalTime: 420, Count: 43, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa05984, EstimatedImpact: 55% 2026-06-03T22:19:26.193 ProcessImageName: firefox.exe, Pid: 10512, TotalTime: 360, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa08904, EstimatedImpact: 47% 2026-06-03T22:19:26.193 ProcessImageName: VirtualBoxVM.exe, Pid: 5404, TotalTime: 300, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.22000.1761.cat, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: FileCoAuth.exe, Pid: 7216, TotalTime: 243, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\Telemetry.dll, EstimatedImpact: 3% 2026-06-03T22:19:26.193 ProcessImageName: AggregatorHost.exe, Pid: 5856, TotalTime: 213, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdFilter.sys, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: ngentask.exe, Pid: 10812, TotalTime: 211, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: backgroundTaskHost.exe, Pid: 2716, TotalTime: 210, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280811\1780496358, EstimatedImpact: 3% 2026-06-03T22:19:26.193 ProcessImageName: ngentask.exe, Pid: 6544, TotalTime: 210, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: backgroundTaskHost.exe, Pid: 7976, TotalTime: 195, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 5% 2026-06-03T22:19:26.193 ProcessImageName: MicrosoftEdge_X64_148.0.3967.70.exe, Pid: 7796, TotalTime: 170, Count: 4, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B9892DF6-BCA0-49A9-957B-DA020EBDF5B8}\EDGEMITMP_E6231.tmp\setup.exe, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 3564, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 67% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 3728, TotalTime: 167, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_88e8fb3d-9ec6-4f24-9dfc-d3cc1155ae79\DiagPackage.diagpkg, EstimatedImpact: 39% 2026-06-03T22:19:26.193 ProcessImageName: ngentask.exe, Pid: 5880, TotalTime: 150, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: dasHost.exe, Pid: 5556, TotalTime: 120, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96.exe, Pid: 13256, TotalTime: 109, Count: 2, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{BF85C5A7-3BCF-45B1-ABA4-9798B2AC62E0}\EDGEMITMP_27F4F.tmp\setup.exe, EstimatedImpact: 51% 2026-06-03T22:19:26.193 ProcessImageName: MicrosoftEdge_X64_148.0.3967.96_148.0.3967.83.exe, Pid: 7680, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{FAF845CD-61B0-47AA-827D-CE0A0A909AC0}\EDGEMITMP_7A785.tmp\setup.exe, EstimatedImpact: 52% 2026-06-03T22:19:26.193 ProcessImageName: svchost.exe, Pid: 2056, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\tquery.dll.mun, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: spoolsv.exe, Pid: 3220, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\A35917FB-3745-4691-9EA8-F1FB29B7B68C\merged.gpd, EstimatedImpact: 32% 2026-06-03T22:19:26.193 ProcessImageName: dllhost.exe, Pid: 7904, TotalTime: 75, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{56cbbacb-5d2e-4116-949a-06b0c13d7251}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: vc_redist.x64.exe, Pid: 11792, TotalTime: 75, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{34830364-BEF3-4080-A8EE-58CD957529F0}\.ba\wixstdba.dll, EstimatedImpact: 22% 2026-06-03T22:19:26.193 ProcessImageName: vc_redist.x86.exe, Pid: 6988, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 30% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 75, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 9% 2026-06-03T22:19:26.193 ProcessImageName: RuntimeBroker.exe, Pid: 6908, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.down_data, EstimatedImpact: 7% 2026-06-03T22:19:26.193 ProcessImageName: dllhost.exe, Pid: 5692, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: OfficeClickToRun.exe, Pid: 13276, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: svchost.exe, Pid: 5264, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\msedgeedge_BITS_4532_1014451980\BIT8B42.tmp, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: ngentask.exe, Pid: 3076, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 22% 2026-06-03T22:19:26.193 ProcessImageName: BackgroundTransferHost.exe, Pid: 12948, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bebf40e8-7753-40eb-8442-c6ed2fbf59ed.up_meta_secure, EstimatedImpact: 14% 2026-06-03T22:19:26.193 ProcessImageName: OfficeC2RClient.exe, Pid: 5500, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-1815.log, EstimatedImpact: 2% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 10972, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: taskhostw.exe, Pid: 864, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: PhoneExperienceHost.exe, Pid: 5712, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 8% 2026-06-03T22:19:26.193 ProcessImageName: OfficeClickToRun.exe, Pid: 12744, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: GUP.exe, Pid: 9588, TotalTime: 45, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\updater\gup.xml, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: AdobeCollabSync.exe, Pid: 10496, TotalTime: 45, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: , Pid: 4, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 5% 2026-06-03T22:19:26.193 ProcessImageName: backgroundTaskHost.exe, Pid: 5664, TotalTime: 45, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1780525102, EstimatedImpact: 8% 2026-06-03T22:19:26.193 ProcessImageName: tzsync.exe, Pid: 13000, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Globalization\Time Zone\timezones.xml, EstimatedImpact: 9% 2026-06-03T22:19:26.193 ProcessImageName: backgroundTaskHost.exe, Pid: 4896, TotalTime: 30, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379->(UTF-16LE), EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: SDXHelper.exe, Pid: 3688, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 3% 2026-06-03T22:19:26.193 ProcessImageName: svchost.exe, Pid: 3772, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\ActionsServer.msix, EstimatedImpact: 0% 2026-06-03T22:19:26.193 ProcessImageName: OfficeC2RClient.exe, Pid: 5912, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-2153.log, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: OfficeC2RClient.exe, Pid: 9432, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260603-2058.log, EstimatedImpact: 1% 2026-06-03T22:19:26.193 ProcessImageName: svchost.exe, Pid: 8048, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 06-17-2026 08:24:11 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 06/17/2026 08:24:11.990444900 UTC (18703 ms since boot) 2026-06-17T08:24:12.041 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-06-17T08:24:12.056 WARNING: the previous service shutdown was not expected. 2026-06-17T08:24:12.056 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-17T08:24:12.056 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-06-17T08:24:12.103 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260617-082412-00000003-fffffffeffffffff.bin ... 2026-06-17T08:24:12.197 [WPP] Trace session started - MpWppTracing-20260617-082412-00000003-fffffffeffffffff.bin 2026-06-17T08:24:12.213 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-06-17T08:24:12.213 [RbM] Rollback manager succesfully initialized. 2026-06-17T08:24:12.213 [RbM] Rollback manager EnableRollbackManager called. 2026-06-17T08:24:12.228 [RbM] Rollback manager EnableRollbackManager completed. 2026-06-17T08:24:12.228 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 2026-06-17T08:24:12.228 MpWriteUupPlatformVersion 4.18.26050.15, hr = 0 2026-06-17T08:24:12.228 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-06-17T08:24:12.228 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-06-17T08:24:12.244 MdCoreSvc is supported in this platform and OS 2026-06-17T08:24:12.244 MdCoreSvc is supported in this platform and OS 2026-06-17T08:24:12.244 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-17T08:24:12.244 [PlatUpd] Starting MdCoreSvc service 2026-06-17T08:24:12.291 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0" 2026-06-17T08:24:15.869 [PlatUpd] MpAddMpUxRegistration succeeded 2026-06-17T08:24:15.869 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-06-17T08:24:15.869 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-06-17T08:24:15.869 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-06-17T08:24:15.869 [PlatUpd] CSP platform update started 2026-06-17T08:24:15.869 [PlatUpd] Defender MDM CSP platform update not required 2026-06-17T08:24:15.869 [PlatUpd] WMI/PS provider platform update started 2026-06-17T08:24:15.869 [PlatUpd] WMI/PS provider platform update not required 2026-06-17T08:24:15.869 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-06-17T08:24:15.869 MdCoreSvc is supported in this platform and OS 2026-06-17T08:24:15.869 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-06-17T08:24:15.869 [PlatUpd] Starting MdCoreSvc service 2026-06-17T08:24:15.869 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-06-17T08:24:15.869 [TS] Troubleshooting mode is not available! 2026-06-17T08:24:15.869 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-17T08:24:15.869 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-06-17T08:24:15.900 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-06-17T08:24:15.900 [Service] Enabling AutoLoggers ... 2026-06-17T08:24:15.900 [Service] Enabling AMSI registration ... 2026-06-17T08:24:15.900 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-06-17T08:24:15.916 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 40738 Number of invalid entries is 0 Number of inserts issued is 1595114 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6576 Number of lookups is 108844548 Number of lookup misses is 5233484 Number of fast lookup misses is 55455494 Number of false fast lookups is 5233479 Number of invalidations is 740518 Number of maintenance invalidations is 530887 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-06-17T08:24:15.916 Verifying license file... 2026-06-17T08:24:15.916 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll] (file in cache) 2026-06-17T08:24:15.931 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-06-17T08:24:15.931 Loaded module#0 MpComServer. 2026-06-17T08:24:15.931 Loaded module#1 StartupPolicies. 2026-06-17T08:24:15.931 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-06-17T08:24:15.931 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-17T08:24:15.931 COM server initialized successfully. 2026-06-17T08:24:15.947 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-06-17T08:24:15.963 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll ... 2026-06-17T08:24:15.963 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll] due to PPL. 2026-06-17T08:24:15.963 [RTP] [RTP] FilterCommunicator object 0x000001F3910C67E0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-17T08:24:15.978 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-06-17T08:24:15.978 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T08:24:15.978 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T08:24:15.978 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-06-17T08:24:15.978 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-17T08:24:15.978 [RTP] [RTP] FilterCommunicator object 0x000001F3910C69F0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-17T08:24:15.978 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-06-17T08:24:15.978 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-06-17T08:24:15.978 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-06-17T08:24:15.978 [RTP] [RTP] StartCommunication 0x000001F3910C67E0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-06-17T08:24:15.978 [init][RTP] RTPPlugin initialization completed 2026-06-17T08:24:15.978 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mpnirtp.dll does not exist. 2026-06-17T08:24:15.978 [init][NiRTP] NiRTPPlugin initialization completed 2026-06-17T08:24:15.978 OS boot count = 2 2026-06-17T08:24:15.978 OS Install = 0 2026-06-17T08:24:15.978 [ManagedAgent] HooksInitialize: starting 2026-06-17T08:24:15.978 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-06-17T08:24:15.978 [ManagedAgent] HooksInitialize: complete 2026-06-17T08:24:15.994 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-06-17T08:24:15.994 [KSL] Entering CKSLEngine::Initialize. 2026-06-17T08:24:15.994 [KSL] Leaving CKSLEngine::Initialize(0). 2026-06-17T08:24:15.994 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-06-17T08:24:15.994 [KSL] MpInstallKslD: hr=0x1 2026-06-17T08:24:15.994 [KSL] MpRegisterKslD: hr=0 2026-06-17T08:24:15.994 [KSL] MpStartKslD: hr=0 2026-06-17T08:24:15.994 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T08:24:15.994 Loading engine... 2026-06-17T08:24:16.009 Verifying engine and signature files (source: 1) ... 2026-06-17T08:24:16.009 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpengine.dll] due to PPL. 2026-06-17T08:24:16.009 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm]. File not in cache (0x1) 2026-06-17T08:24:16.978 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm] 2026-06-17T08:24:16.978 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasdlta.vdm] (file in cache) 2026-06-17T08:24:16.978 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm]. File not in cache (0x1) 2026-06-17T08:24:17.400 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavbase.vdm] 2026-06-17T08:24:17.400 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpavdlta.vdm] (file in cache) 2026-06-17T08:24:17.463 [Engine] IsHybridMode: 0 2026-06-17T08:24:17.463 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-17T08:24:17.494 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-59F7A723E8A6981DE5D2C2CF6D325878F61C4C15.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-17T08:24:22.666 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-17T08:24:22.666 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-06-17T08:24:22.666 [Engine] New active engine 00007FF84B7584C0 (no old engine). Number of active engines: 1 2026-06-17T08:24:22.681 EngineInit:Global ASOC is enabled 2026-06-17T08:24:22.681 EngineInit:ASOO is enabled for developer volumes 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:24:22.759 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3ddf4f2caecc51af05071d2946169b0c33625670 Dynamic Signature Compilation Timestamp:05-16-2026 06:43:09 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.759 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\68ac9d0249ce823d29f3185a38c4e5e7564dd6f0 Dynamic Signature Compilation Timestamp:05-16-2026 07:59:03 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\77e208217a7ab31d295fb9a3e0976a10c306254e Dynamic Signature Compilation Timestamp:05-16-2026 09:01:09 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8a99c4b09334d7de0bc016cded98b82d0b160594 Dynamic Signature Compilation Timestamp:05-16-2026 09:01:09 Persistence Type:Duration Time remaining:150196224 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cd7abf4f758b7f11b7b924c03bc78d06e697632b Dynamic Signature Compilation Timestamp:05-16-2026 16:54:35 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 Dynamic signature dropped 2026-06-17T08:24:22.775 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\10ade06d9afbd40681463dc4ff8a426040edcf96 Dynamic Signature Compilation Timestamp:05-16-2026 16:54:56 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3dc3af4b59bb7b09aebef44c7d900f0601c139fe Dynamic Signature Compilation Timestamp:05-16-2026 16:55:26 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\334aa24b7bb66925972b40e7a01194bda777efbb Dynamic Signature Compilation Timestamp:05-16-2026 16:55:32 Persistence Type:Duration Time remaining:150196224 2026-06-17T08:24:22.775 MpWriteUupSignatureVersion 1.451.246.0, hr = 0 2026-06-17T08:24:22.775 [SigStatUpd] CSignatureStatus: Changed to DUE_TRY_1 2026-06-17T08:24:22.775 [SigStatUpd] CSignatureStatus: Triggering signature update... 2026-06-17T08:24:22.806 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-06-17T08:24:22.806 [SigStatUpd] CSignatureStatus: Signature update triggered! 2026-06-17T08:24:22.806 [SigStatUpd] CSignatureStatus: UpdateWaitTimer #1 scheduled 2026-06-17T08:24:22.806 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-17T08:24:22.806 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:7776] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7784]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:24:22.822 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-17T08:24:22.822 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-17T08:24:22.822 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-17T08:24:22.822 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-17T08:24:22.822 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-17T08:24:22.853 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-17T08:24:22.853 [Plugin] Initializing RTP plugin state... 2026-06-17T08:24:22.853 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2754 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2224 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:13238 TotalHits:0 InstanceCacheInserts:15 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2593 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-17T08:24:22.853 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-17T08:24:22.853 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51} 2026-06-17T08:24:22.853 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:24:22.853 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:24:22.853 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:24:22.853 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T08:24:22.853 MdCoreSvc is supported in this platform and OS 2026-06-17T08:24:22.853 Engine loaded! 2026-06-17T08:24:22.853 [DLP] Create FeatureControlState instance 2026-06-17T08:24:22.853 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-06-17T08:24:22.853 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-06-17T08:24:22.853 RegisterSModeChangeListener: hr = 0x1 2026-06-17T08:24:22.869 RegisterHybridModeChangeListener: hr = 0 2026-06-17T08:24:22.869 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-06-17T08:24:22.869 [SigReleaseHb] Initialized with Stage 0 2026-06-17T08:24:22.869 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-06-17T08:24:22.869 [SCC][CID=29593_5768] Initializing ... 2026-06-17T08:24:22.869 [SCC][CID=29593_5768] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-06-17T08:24:22.884 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-17T08:24:22.884 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-17T08:24:22.884 [NRI] Stopping NIS service ... 2026-06-17T08:24:22.884 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-06-17T08:24:22.884 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26050.11 AS Signature Version: 1.451.246.0 AV Signature Version: 1.451.246.0 ************************************************************ 2026-06-17T08:24:22.884 Resource usage Monitoring is enabled 2026-06-17T08:24:22.884 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-06-17T08:24:22.884 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-17T08:24:22.884 Job Notification: New process added to job (4756) 2026-06-17T08:24:22.884 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:7844] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7852]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:24:22.978 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-17T08:24:22.994 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-17T08:24:22.994 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-17T08:24:22.994 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-17T08:24:22.994 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-17T08:24:22.994 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T08:24:22.994 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T08:24:22.994 [RTP] Generating the base plugin configuration ... 2026-06-17T08:24:22.994 [RTP] Path exclusion changed, new size in bytes: 2 2026-06-17T08:24:22.994 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:24:22.994 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-06-17T08:24:22.994 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-06-17T08:24:22.994 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:24:22.994 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-17T08:24:22.994 [RTP] [RTP] StartCommunication 0x000001F3910C69F0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-06-17T08:24:23.009 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-06-17T08:24:23.025 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-06-17T08:24:23.213 Job Notification: New process added to job (8084) 2026-06-17T08:24:23.213 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-06-17T08:24:23.244 Job Notification: New process added to job (8108) 2026-06-17T08:24:23.259 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:8084] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8108]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:24:23.322 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-17T08:24:23.322 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-17T08:24:23.322 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T08:24:23.509 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:24:23.650 [PlatUpd] WMI MOF schema validation completed successfully 2026-06-17T08:24:26.088 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:24:26.088 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:24:26.088 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-06-17T08:24:26.088 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-17T08:24:26.088 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=2, resourceid=0xcd098c58 2026-06-17T08:24:37.275 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Program Files\TeamViewer\update.exe. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x157ef1bef48f 2026-06-17T08:24:37.275 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files\TeamViewer\update.exe` is 5718 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=2, resourceid=0x460b5620 Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xb0cd8d18 BEGIN BM telemetry GUID:{E4DCB36B-6F53-9719-D15E-8405D6634577} SignatureID:66739850906303 SigSha:27f2bd265fd12d929dacd7650d7a8faffb59aae8 ThreatLevel:0 ProcessID:7608 ProcessCreationTime:134261582790867635 SessionID:0 CreationTime:06-17-2026 08:24:41 ImagePath:C:\Program Files\TeamViewer\Update\update.exe Taint Info:Friendly: N; Reason: ; Modules: C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\System.dll:25,C:\Windows\Temp\nsbB47D.tmp\UserInfo.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\UAC.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\UserInfo.dll:25,C:\Windows\Temp\nsbB47D.tmp\UAC.dll:25,C:\Windows\Temp\nsbB47D.tmp\UserInfo.dll:25,C:\Windows\Temp\nsbB47D.tmp\UAC.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nsbB47D.tmp\TvGetVersion.dll:25,; Parents: C:\Program Files\TeamViewer\TeamViewer_Service.exe:4788:3,C:\Windows\System32\csrss.exe:600:2, Operations:None END BM telemetry 2026-06-17T08:24:41.916 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8a8820867ffffffe 2026-06-17T08:24:41.931 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=0, resourceid=0x0725b9ae Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xb86e4f5e Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xb86e4f5e 2026-06-17T08:24:48.103 ExpensiveFile:Scan time for `\\?\C:\Program Files\TeamViewer\Update\update.exe` is 5484 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=0, resourceid=0xb86e4f5e 2026-06-17T08:24:51.369 ExpensiveFile:Scan time for `\\?\C:\Program Files\TeamViewer\Update\update.exe` is 6156 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=false, source=0, resourceid=0xb0cd8d18 2026-06-17T08:24:51.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8a8820867ffffffe 2026-06-17T08:24:51.463 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x29de103d7ffffffe 2026-06-17T08:24:51.478 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8a8820867ffffffe 2026-06-17T08:24:51.478 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x29de103d7ffffffe 2026-06-17T08:24:52.025 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-17T08:24:52.041 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-17T08:24:54.634 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:24:54.634 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:24:54.634 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-06-17T08:24:54.634 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-17T08:24:54.634 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-06-17T08:24:58.025 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:24:58.025 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:24:58.025 [Cloud] Queued cloud request. 2026-06-17T08:24:58.025 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:24:58.025 [Cloud] Dequeued cloud request. 2026-06-17T08:24:58.025 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:24:58.697 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-06-17T08:24:58.697 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:24:58.697 [Cloud] Queued cloud request. 2026-06-17T08:24:58.697 [Cloud] Dequeued cloud request. 2026-06-17T08:24:58.697 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a94246ff920554b666d1236e7365ba472f72a0ff Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:24:58.916 Dynamic signature received 2026-06-17T08:24:58.916 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-06-17T08:24:58.916 [Cloud] End of cloud request. 2026-06-17T08:24:59.431 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:25:03.634 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-06-17T08:25:03.634 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:25:03.634 [Cloud] Queued cloud request. 2026-06-17T08:25:03.634 [Cloud] Dequeued cloud request. 2026-06-17T08:25:03.650 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:25:03.744 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-06-17T08:25:03.744 [Cloud] End of cloud request. 2026-06-17T08:25:04.259 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:25:08.338 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f62a590a52507ff3c756b9f7b22623b4a8012559 Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b82f7af4a05ad7089859330013f38a80d986f1cc Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:25:08.338 Dynamic signature received 2026-06-17T08:25:08.338 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x0000157EF1BEF48F, sigsha=88199b23bf19d286f43e8f883776ee295b1669db, cached=true, source=2, resourceid=0x460b5620 2026-06-17T08:25:08.838 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:25:13.431 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\5A970328-142F-4697-935B-6CA1B7B2D1171f70.1dcfe32bc63ff19 2026-06-17T08:25:14.853 Verifying engine and signature files (source: 0) ... 2026-06-17T08:25:14.853 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpengine.dll] due to PPL. 2026-06-17T08:25:14.853 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpasbase.vdm]. File not in cache (0x1) 2026-06-17T08:25:15.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpasbase.vdm] 2026-06-17T08:25:15.713 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpasdlta.vdm]. File not in cache (0x1) 2026-06-17T08:25:15.713 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpasdlta.vdm] 2026-06-17T08:25:15.713 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpavbase.vdm]. File not in cache (0x1) 2026-06-17T08:25:15.916 Process scan (poststartupscan) started. 2026-06-17T08:25:15.916 Process scan (poststartupscan) completed. 2026-06-17T08:25:16.134 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpavbase.vdm] 2026-06-17T08:25:16.134 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpavdlta.vdm]. File not in cache (0x1) 2026-06-17T08:25:16.150 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpavdlta.vdm] 2026-06-17T08:25:16.322 [Engine] IsHybridMode: 0 2026-06-17T08:25:16.322 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-17T08:25:16.322 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-785CA86DC0C199A8D1D7AE1AB9265B1FA335D95B.bin): 0x00000002 2026-06-17T08:25:16.338 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-785CA86DC0C199A8D1D7AE1AB9265B1FA335D95B.bin) 2026-06-17T08:25:16.338 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-06-17T08:25:16.338 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-06-17T08:25:16.338 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-06-17T08:25:16.338 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-17T08:25:26.400 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-17T08:25:26.400 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-06-17T08:25:26.416 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF84B7584C0, lRefCount: 5, hr=0 2026-06-17T08:25:26.416 [Engine] New active engine 00007FF8465F84C0 replacing engine 00007FF84B7584C0. Number of active engines: 2 2026-06-17T08:25:26.416 EngineInit:Global ASOC is enabled 2026-06-17T08:25:26.416 EngineInit:ASOO is enabled for developer volumes 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T08:25:26.478 MpWriteUupSignatureVersion 1.453.137.0, hr = 0 2026-06-17T08:25:26.478 [SigStatUpd] CSignatureStatus: back to good 2026-06-17T08:25:26.478 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-17T08:25:26.494 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-17T08:25:26.494 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-17T08:25:26.494 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-17T08:25:26.494 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-17T08:25:26.494 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-17T08:25:26.509 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-17T08:25:26.509 [Plugin] Initializing RTP plugin state... 2026-06-17T08:25:26.509 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-17T08:25:26.509 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎06‎-‎17‎-‎2026 10:24:22 Last Perf:‎06‎-‎17‎-‎2026 10:24:22 First RTP Scan:‎06‎-‎17‎-‎2026 10:24:23 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:491 Misses:842 BM Queue:0,15,0 Proc:0,14,0 File:0,9,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:1895 Pending:0 RegSize:308276 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:1784240 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2808 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:16197 TotalHits:3371 InstanceCacheInserts:52 InstanceCacheUpdates:0 InstanceCacheDeletes:20 InstanceCacheHits:6 InstanceCacheMisses:3341 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:2ms (88/33) Success: 33, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-17T08:25:26.509 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6} 2026-06-17T08:25:26.509 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51}\mpasbase.vdm in use, hr=0x80070020 2026-06-17T08:25:26.525 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-17T08:25:26.525 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:25:26.525 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-17T08:25:26.541 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D8A61371-3D6F-48BB-B909-EBC391B0A0E1} removed 2026-06-17T08:25:26.541 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.541 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.541 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.541 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.541 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:06-17-2026 08:25:26 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-17-2026 08:25:26 2026-06-17T08:25:26.556 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-17T08:25:26.556 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-17T08:25:26.556 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:25:26.556 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.556 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.556 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.556 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T08:25:26.556 MdCoreSvc is supported in this platform and OS 2026-06-17T08:25:26.556 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 06-17-2026 08:25:26 Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26050.11 AS Signature Version: 1.453.137.0 AV Signature Version: 1.453.137.0 ************************************************************ 2026-06-17T08:25:26.556 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-06-17T08:25:26.556 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\5A970328-142F-4697-935B-6CA1B7B2D1171f70.1dcfe32bc63ff19 2026-06-17T08:25:26.603 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-17T08:25:26.603 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 06-17-2026 08:25:26 ************************************************************ 2026-06-17T08:25:26.728 Job Notification: Process exited from job (8084) 2026-06-17T08:25:26.728 Job Notification: Process exited from job (8108) 2026-06-17T08:25:26.947 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-17T08:25:26.947 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-17T08:25:26.947 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-17T08:25:26.947 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T08:25:26.947 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T08:25:26.947 [Engine] Engine 00007FF84B7584C0 no longer in use. Number of active engines: 1 2026-06-17T08:25:26.947 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:25:26.947 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-06-17T08:25:26.994 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-17T08:25:26.994 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-17T08:25:26.994 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T08:25:27.041 ProcessImageName: TeamViewer_Service.exe, Pid: 4788, TotalTime: 6397, Count: 20, MaxTime: 5718, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\update.exe, EstimatedImpact: 41% 2026-06-17T08:25:27.041 ProcessImageName: update.exe, Pid: 7608, TotalTime: 5691, Count: 452, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nsbB47D.tmp\TvUpdateInfo.exe, EstimatedImpact: 13% 2026-06-17T08:25:27.041 ProcessImageName: taskhostw.exe, Pid: 7432, TotalTime: 890, Count: 2, MaxTime: 859, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-06-17T08:25:27.041 ProcessImageName: tv_x64.exe, Pid: 5196, TotalTime: 424, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\setupapi.dev.log, EstimatedImpact: 48% 2026-06-17T08:25:27.041 ProcessImageName: WmiPrvSE.exe, Pid: 3916, TotalTime: 315, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T08:25:27.041 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 229, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\crashpad_handler.exe, EstimatedImpact: 32% 2026-06-17T08:25:27.041 ProcessImageName: tv_x64.exe, Pid: 716, TotalTime: 182, Count: 14, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_x64.dll, EstimatedImpact: 37% 2026-06-17T08:25:27.041 ProcessImageName: wuauclt.exe, Pid: 7796, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\SoftwareDistribution\Download\Install\AM_Base_Patch1.exe, EstimatedImpact: 7% 2026-06-17T08:25:27.041 ProcessImageName: mofcomp.exe, Pid: 7916, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpOAV.dll, EstimatedImpact: 9% 2026-06-17T08:25:27.041 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Flighting\OneSettings\RefreshCache->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T08:25:27.041 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\1779ed3881527c40341a9af87c790dbbf6d1d042\content.phf, EstimatedImpact: 0% 2026-06-17T08:25:27.041 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.aggregators.json, EstimatedImpact: 0% 2026-06-17T08:25:27.072 [Engine] RSIG_UNLOADENGINE, 00007FF84B7584C0, err=0x0 2026-06-17T08:25:27.088 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3DC0D16A-8109-45EE-94C6-E53721AF4D51} removed Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-06-17T08:25:40.971 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-17T08:25:42.533 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-17T08:25:52.767 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:9912:134261583478154253) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:25:52.783 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:9848:134261583477432135) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:25:52.783 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:10140:134261583482799089) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:26:11.851 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #4675, FileId: 0x180000000337ed, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:26:15.814 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:26:15.830 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T08:26:15.830 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:26:24.283 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-06-17T08:26:24.283 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:26:24.283 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:26:24.283 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-06-17T08:26:24.283 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-06-17T08:26:24.283 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-06-17T08:26:24.361 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-06-17T08:26:25.346 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-06-17T08:26:25.814 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-06-17T08:26:26.283 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-06-17T08:26:47.392 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-06-17T08:26:49.330 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #5932, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 2026-06-17T08:26:53.283 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5963, FileId: 0x34000000036760, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 2026-06-17T08:26:54.392 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 6203 units Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x211f41cf 2026-06-17T08:26:56.439 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:56.439 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:56.439 [Cloud] Queued cloud request. 2026-06-17T08:26:56.439 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:56.439 [Cloud] Dequeued cloud request. 2026-06-17T08:26:56.439 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:26:56.939 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d02b42d69714adab274eabf9bc15d979fb815bc8 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:53 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:26:56.939 [Cloud] End of cloud request. 2026-06-17T08:26:56.939 RTSD:RTSD recieved, rescanning impacted resources 2026-06-17T08:26:56.955 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7133769a 2026-06-17T08:26:57.205 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:57.205 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:57.205 [Cloud] Queued cloud request. 2026-06-17T08:26:57.205 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:57.205 [Cloud] Dequeued cloud request. 2026-06-17T08:26:57.205 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:26:57.502 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\325bf51f096b740b55b00a6d1ebe0b34001385e0 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:54 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:26:57.502 [Cloud] End of cloud request. 2026-06-17T08:26:57.502 RTSD:RTSD recieved, rescanning impacted resources 2026-06-17T08:26:57.658 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:7560:134261584169020610) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a883020 2026-06-17T08:26:57.752 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:57.752 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:57.752 [Cloud] Queued cloud request. 2026-06-17T08:26:57.752 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:57.752 [Cloud] Dequeued cloud request. 2026-06-17T08:26:57.752 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:26:58.017 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:26:58.033 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7c6a32f4247ee4b30c5140cc7fcd1e2713191ad8 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:54 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:26:58.033 [Cloud] End of cloud request. 2026-06-17T08:26:58.033 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ccbb36f 2026-06-17T08:26:58.111 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:58.111 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:58.111 [Cloud] Queued cloud request. 2026-06-17T08:26:58.111 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:58.111 [Cloud] Dequeued cloud request. 2026-06-17T08:26:58.111 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:26:58.533 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:26:58.549 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8373dbb68197a4792de8390535aca663b776f30f Dynamic Signature Compilation Timestamp:06-17-2026 08:26:55 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:26:58.549 [Cloud] End of cloud request. 2026-06-17T08:26:58.549 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3dc12e4b 2026-06-17T08:26:58.955 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:58.955 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:58.955 [Cloud] Queued cloud request. 2026-06-17T08:26:58.955 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:58.955 [Cloud] Dequeued cloud request. 2026-06-17T08:26:58.955 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:26:59.049 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:26:59.221 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c948f66e9cef90e09fe7648e0f0c9aebd069fe6e Dynamic Signature Compilation Timestamp:06-17-2026 08:26:56 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:26:59.221 [Cloud] End of cloud request. 2026-06-17T08:26:59.221 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-06-17T08:26:59.721 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:26:59.783 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:26:59.783 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:26:59.783 [Cloud] Queued cloud request. 2026-06-17T08:26:59.783 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:26:59.783 [Cloud] Dequeued cloud request. 2026-06-17T08:26:59.783 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:00.502 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0685c867f9ba76f252524a2c04bc26182c2fae5b Dynamic Signature Compilation Timestamp:06-17-2026 08:26:57 Persistence Type:Duration Time remaining:288000000 2026-06-17T08:27:00.502 [Cloud] End of cloud request. 2026-06-17T08:27:00.502 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c25bb8 2026-06-17T08:27:00.564 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:00.564 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:00.564 [Cloud] Queued cloud request. 2026-06-17T08:27:00.564 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:00.580 [Cloud] Dequeued cloud request. 2026-06-17T08:27:00.580 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:00.783 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\94d6033d4710f704422cd4e8b6220399013ff73f Dynamic Signature Compilation Timestamp:06-17-2026 08:26:57 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:00.783 [Cloud] End of cloud request. 2026-06-17T08:27:00.783 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6ab8889 2026-06-17T08:27:00.924 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:00.924 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:00.924 [Cloud] Queued cloud request. 2026-06-17T08:27:00.924 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:00.924 [Cloud] Dequeued cloud request. 2026-06-17T08:27:00.924 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:01.018 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:01.189 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ade69a5fb3b661fe6e30afc32a9574585f4b91ca Dynamic Signature Compilation Timestamp:06-17-2026 08:26:58 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:01.189 [Cloud] End of cloud request. 2026-06-17T08:27:01.189 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf20873eb 2026-06-17T08:27:01.252 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:01.252 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:01.252 [Cloud] Queued cloud request. 2026-06-17T08:27:01.252 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:01.252 [Cloud] Dequeued cloud request. 2026-06-17T08:27:01.252 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:01.689 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:02.096 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a4488878040cda951352028580d98b2848f8c16d Dynamic Signature Compilation Timestamp:06-17-2026 08:26:58 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:02.096 [Cloud] End of cloud request. 2026-06-17T08:27:02.096 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb934f277 2026-06-17T08:27:02.158 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:02.158 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:02.158 [Cloud] Queued cloud request. 2026-06-17T08:27:02.158 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:02.158 [Cloud] Dequeued cloud request. 2026-06-17T08:27:02.158 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:02.611 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:03.174 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2bd2582f072fc17eb3b98ec8247605a0d8d1f338 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:59 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:03.174 [Cloud] End of cloud request. 2026-06-17T08:27:03.174 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7c337a01 2026-06-17T08:27:03.236 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:03.236 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:03.236 [Cloud] Queued cloud request. 2026-06-17T08:27:03.236 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:03.236 [Cloud] Dequeued cloud request. 2026-06-17T08:27:03.236 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:03.689 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:03.955 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1a476a63232e4e08d8a88316e444d87f168d6091 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:00 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:03.955 [Cloud] End of cloud request. 2026-06-17T08:27:03.955 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe4e9c3ef 2026-06-17T08:27:04.002 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:04.002 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:04.002 [Cloud] Queued cloud request. 2026-06-17T08:27:04.002 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:04.002 [Cloud] Dequeued cloud request. 2026-06-17T08:27:04.002 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:04.455 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:04.487 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ce03e99622f021757998db6cfd38b9cf8b252f0d Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:04.487 [Cloud] End of cloud request. 2026-06-17T08:27:04.487 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9cab2c6 2026-06-17T08:27:04.533 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:04.533 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:04.533 [Cloud] Queued cloud request. 2026-06-17T08:27:04.533 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:04.533 [Cloud] Dequeued cloud request. 2026-06-17T08:27:04.533 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:04.846 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd7854045a9c30258cb08df94b072c0add9546b7 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:04.861 [Cloud] End of cloud request. 2026-06-17T08:27:04.861 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf05abbb8 2026-06-17T08:27:04.908 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T08:27:04.908 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:27:04.908 [Cloud] Queued cloud request. 2026-06-17T08:27:04.908 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T08:27:04.908 [Cloud] Dequeued cloud request. 2026-06-17T08:27:04.908 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:27:05.002 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:05.174 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48648f2cbde2c433eafc0c17218c2d4ef849f387 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 2026-06-17T08:27:05.174 [Cloud] End of cloud request. 2026-06-17T08:27:05.174 RTSD:RTSD recieved, rescanning impacted resources 2026-06-17T08:27:05.689 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:27:09.877 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:9544:134261584296683214) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:27:27.127 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:8836:134261584464523318) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf97ff7bf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x35abdb83 2026-06-17T08:27:48.330 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:6332:134261584673084302) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:28:13.346 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:10884:134261584923269180) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:28:42.736 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:10352:134261585217239255) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:29:03.049 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\nmhproxy.exe.moz-backup", hr=0x800710da 2026-06-17T08:29:17.357 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:9352:134261585555982587) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:29:22.889 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T08:29:55.096 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe (PPID:6688:134261585940788155) is tainted: TaintType:0x5. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-06-17T08:30:26.549 [RbM] Setting Last known good engine candidate. hr = 0 2026-06-17T08:30:43.783 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8341, FileId: 0x179000000003f59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0x4d0cdcf8 2026-06-17T08:32:41.814 [RTP] [Mini-filter] OpenWithoutRead notification (932, 21620, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-06-17T08:32:47.643 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23710, FileId: 0x130000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.643 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23716, FileId: 0x131000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.643 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23717, FileId: 0x10000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.659 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23720, FileId: 0x133000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.659 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23709, FileId: 0x10000000058eb3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.659 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23715, FileId: 0xf000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.659 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23718, FileId: 0x132000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.674 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23719, FileId: 0x11000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.846 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23733, FileId: 0x140000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.877 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23735, FileId: 0x142000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.877 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23732, FileId: 0x20000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:47.877 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23734, FileId: 0x22000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.034 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23742, FileId: 0x25000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.049 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23743, FileId: 0x26000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.049 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23747, FileId: 0x27000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.080 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23749, FileId: 0x28000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.080 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23751, FileId: 0x29000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.080 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23750, FileId: 0x149000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.080 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23752, FileId: 0x14a000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.112 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23762, FileId: 0x14b000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.159 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23770, FileId: 0x2d000000058eb4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:48.190 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23769, FileId: 0x14d000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:50.145 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23893, FileId: 0x151000000001831, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:50.145 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23894, FileId: 0x57000000058c24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:50.161 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23892, FileId: 0x56000000058c24, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.414 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\58686e55-7fdf-47f6-8b10-3e6e17d245ca. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #23961, FileId: 0x1900000008f826, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.430 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23964, FileId: 0x9200000000a88e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.946 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23989, FileId: 0x247000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.946 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23993, FileId: 0x1b0000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.946 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23999, FileId: 0x24c000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.946 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24000, FileId: 0x1b2000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.946 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23998, FileId: 0x1b1000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.961 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23987, FileId: 0x1a9000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.961 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23997, FileId: 0x24b000000002d36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:51.961 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23988, FileId: 0x1ad000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:52.352 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\6f6e2d77-2c80-4a33-a786-6eafbef1721d. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #24051, FileId: 0x1690000000035bf, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:32:52.368 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #24053, FileId: 0x20000000062067, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:05.861 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC91A5C9A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24886, FileId: 0xe0000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:05.892 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj39FE039EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24893, FileId: 0xf0000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:05.924 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9A236E978. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24895, FileId: 0x199000000018597, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:06.127 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2D5D38927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24908, FileId: 0x110000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:06.158 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5A2072928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24911, FileId: 0x120000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:06.629 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj83CBCB901. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24957, FileId: 0x140000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:06.692 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7841E096A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24960, FileId: 0x150000000b66b3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:07.163 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFE6F5797C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #24980, FileId: 0x190000000b66fc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:08.705 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C7344929. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25048, FileId: 0xd0000000b670b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:08.720 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7F2B99975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25050, FileId: 0xe0000000b670b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:08.861 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8C75DF967. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25055, FileId: 0xac000000018e22, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:08.971 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6077AC9C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25060, FileId: 0x130000000b670b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.164 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEC53A4997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25067, FileId: 0x19400000000036f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.196 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB6DCEE946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25071, FileId: 0x13e000000001417, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.437 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3FC5889AA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25097, FileId: 0x189000000000b08, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.546 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj256FCA991. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25111, FileId: 0x100000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.593 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC664A298D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25124, FileId: 0x110000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:09.640 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF15BDF98F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25130, FileId: 0x120000000b671f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.218 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDAA1369EF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25176, FileId: 0x2f0000000000484, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.249 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF6DE459A6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25177, FileId: 0x130000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.265 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE69ED79AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25179, FileId: 0x140000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.281 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB1B95F976. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25180, FileId: 0x150000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.390 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0526B0982. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25182, FileId: 0x160000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.421 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj163FAD96B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25184, FileId: 0x170000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.437 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj46A7CB9D8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25185, FileId: 0x180000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.468 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6589BA941. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25186, FileId: 0x190000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.484 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFFEEE29B4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25187, FileId: 0x1a0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.499 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB3BB73910. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25188, FileId: 0x1b0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.546 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C20B09CF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25189, FileId: 0x1c0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.627 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8561EC961. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25193, FileId: 0x1d0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.650 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E50F0954. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25194, FileId: 0x1e0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:10.881 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4DAE2D9DC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25198, FileId: 0x1f0000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.156 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj00875E944. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25210, FileId: 0xc6000000018e44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.219 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0A7B409E3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25219, FileId: 0xab000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.266 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0097EE9E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25223, FileId: 0xc8000000018e44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.672 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8479BB932. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25240, FileId: 0x140000000b671f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.766 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7EFC2E98B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25242, FileId: 0x220000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.812 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF93F70902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25244, FileId: 0x230000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.844 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj03613F9E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25246, FileId: 0x240000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:11.875 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1D053A940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25247, FileId: 0x250000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:12.016 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE88936906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25249, FileId: 0x150000000b671f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:12.047 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB2F72594F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25250, FileId: 0x270000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:12.129 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj806F329AC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25253, FileId: 0x280000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:12.144 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6A9F58906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25254, FileId: 0x290000000b6719, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:20.405 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25444, FileId: 0x2a000000033678, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:20.514 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25467, FileId: 0x140000000b65f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:33:20.608 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #25488, FileId: 0x130000000b66a8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0xfae7ef79 2026-06-17T08:34:16.721 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #26182, FileId: 0x8c000000012bc2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:34:19.299 [RTP] 3 newly mounted volumes accumulated, forcing a config update ... 2026-06-17T08:34:19.299 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:34:19.299 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:34:19.299 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-06-17T08:34:19.299 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-06-17T08:34:19.299 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-06-17T08:34:19.299 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-06-17T08:34:20.642 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-06-17T08:34:20.705 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\System Volume Information\SPP\snapshot-2 2026-06-17T08:34:20.767 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #26248, FileId: 0x6a00000000fd44, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:34:22.877 Timer callback: Initializating/verifying scheduled tasks ... 2026-06-17T08:34:22.877 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-06-17T08:34:23.017 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 58307123(ms) from now at 02:46 (00:46 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-06-17T08:34:23.111 Job Notification: New process added to job (10508) 2026-06-17T08:34:23.658 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-06-17T08:34:23.658 Job Notification: New process added to job (10408) 2026-06-17T08:34:23.674 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:10508] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10408]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:34:23.799 Job Notification: New process added to job (7452) 2026-06-17T08:34:23.814 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-06-17T08:34:23.814 Job Notification: New process added to job (7076) 2026-06-17T08:34:23.830 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:7452] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7076]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:34:24.174 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-17T08:34:24.174 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:34:24.174 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:34:24.174 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-06-17T08:34:24.174 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:34:24.174 [RTP] No config change detected. Not updating plugin configuration. 2026-06-17T08:34:24.174 [RTP] No config changes found. No configuration switch. 2026-06-17T08:34:24.174 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-06-17T08:34:24.205 Aggressive catchup quick scan threshold: 11878626152323 / 25920000000000 2026-06-17T08:34:24.642 Job Notification: New process added to job (5336) 2026-06-17T08:34:25.049 Task(GetDeviceTicket -AccessKey 9FBB0B17-6CA6-8BD9-F4E3-D8774D148E2C ) launched as network service 2026-06-17T08:34:25.439 Job Notification: Process exited from job (5336) 2026-06-17T08:34:26.424 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-06-17T08:34:26.424 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T08:34:26.424 [Cloud] Queued cloud request. 2026-06-17T08:34:26.424 [Cloud] Dequeued cloud request. 2026-06-17T08:34:26.424 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T08:34:26.564 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-06-17T08:34:26.564 [Cloud] End of cloud request. 2026-06-17T08:34:26.939 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T08:34:37.502 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-06-17T08:34:45.642 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:10508] from process [\Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe][Pid:11696]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:34:45.642 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:7452] from process [\Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe][Pid:11696]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-06-17T08:35:15.924 Process scan (postsignatureupdatescan) started. 2026-06-17T08:35:20.252 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-17T08:35:33.533 Process scan (postsignatureupdatescan) completed. 2026-06-17T08:35:35.424 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\pagefile.sys 2026-06-17T08:35:37.814 Job Notification: Process exited from job (7452) 2026-06-17T08:35:37.814 Job Notification: Process exited from job (7076) 2026-06-17T08:35:37.892 Job Notification: Process exited from job (10508) 2026-06-17T08:35:37.892 Job Notification: Process exited from job (10408) 2026-06-17T08:35:49.689 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-06-17T08:35:50.799 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\pagefile.sys 2026-06-17T08:36:56.002 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #32245, FileId: 0x20000000036339, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:36:56.064 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #32249, FileId: 0x175000000016cca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x113e36ff 2026-06-17T08:44:27.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T08:44:58.487 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #35124, FileId: 0x19000000029eb0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:45:01.061 [AutoPurge] Routine task for Cache Maintenance has started. 2026-06-17T08:45:01.061 [AutoPurge] Routine task for Cache Maintenance ... 2026-06-17T08:45:01.061 [AutoPurge] Routine task for MpSFCBuild ... 2026-06-17T08:45:01.061 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-06-17T08:45:01.061 [AutoPurge] MpSignalMaintenanceMode ... 2026-06-17T08:45:01.096 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:3F3FE61A-EAFE-4203-9AFC-4A7AC1D765D3, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-06-17T08:45:01.096 Scheduled scan with Id 3F3FE61A-EAFE-4203-9AFC-4A7AC1D765D3 configured CPU priority: normal (LowCpuPriority: 0) 2026-06-17T08:45:01.158 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-06-17T08:45:01.158 [SFC] System file cache build is not needed (already completed) 2026-06-17T08:45:01.392 Engine:Setting original file name "powershell.exe" for "c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-06-17T08:45:01.642 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-06-17T08:45:02.658 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:45:04.486 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:45:04.502 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T08:45:04.517 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:45:05.767 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-06-17T08:45:05.892 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-06-17T08:45:05.908 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-06-17T08:45:05.939 Engine:Setting original file name "mscordaccore.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\mscordaccore_amd64_amd64_9.0.1426.11910.dll", hr=0x800710da 2026-06-17T08:45:06.424 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-06-17T08:45:06.517 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-06-17T08:45:06.674 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-17T08:45:06.674 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-06-17T08:45:06.861 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-06-17T08:45:06.955 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-06-17T08:45:07.017 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-06-17T08:45:07.174 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:07.392 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-06-17T08:45:07.564 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-06-17T08:45:07.783 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-06-17T08:45:07.799 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:07.877 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-06-17T08:45:07.986 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-06-17T08:45:08.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-06-17T08:45:08.346 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-06-17T08:45:08.611 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-06-17T08:45:08.642 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:08.955 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-06-17T08:45:09.127 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-06-17T08:45:09.971 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-17T08:45:10.111 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:10.736 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-06-17T08:45:11.002 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-06-17T08:45:11.252 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-06-17T08:45:11.767 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-06-17T08:45:11.924 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-06-17T08:45:11.955 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-06-17T08:45:11.986 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-17T08:45:12.377 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-06-17T08:45:12.439 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-06-17T08:45:12.564 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-06-17T08:45:12.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-06-17T08:45:13.205 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-06-17T08:45:13.236 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-06-17T08:45:13.424 Engine:Setting original file name "updater.exe" for "c:\program files\mozilla firefox\tobedeleted\moz05bda535-bbf5-4b52-9ac3-dc8112bcb40a", hr=0x800710da 2026-06-17T08:45:13.486 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-06-17T08:45:13.549 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-06-17T08:45:14.221 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-06-17T08:45:14.252 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-06-17T08:45:14.252 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:14.267 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-06-17T08:45:14.330 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-06-17T08:45:14.408 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-06-17T08:45:14.517 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-06-17T08:45:14.830 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-06-17T08:45:15.017 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-06-17T08:45:15.064 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2620.102.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-06-17T08:45:15.096 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-06-17T08:45:15.221 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-06-17T08:45:15.267 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-06-17T08:45:15.283 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-06-17T08:45:15.299 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-06-17T08:45:15.533 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-06-17T08:45:15.721 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-06-17T08:45:15.721 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-06-17T08:45:16.017 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-06-17T08:45:16.486 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-06-17T08:45:16.627 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:16.627 Engine:Setting original file name "vccorlib140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll", hr=0x800710da 2026-06-17T08:45:16.689 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-06-17T08:45:16.924 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-06-17T08:45:16.939 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-06-17T08:45:17.221 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-06-17T08:45:17.299 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-06-17T08:45:17.314 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-06-17T08:45:17.377 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-06-17T08:45:17.392 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-06-17T08:45:17.424 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-06-17T08:45:17.846 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-06-17T08:45:17.892 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-17T08:45:17.986 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-06-17T08:45:18.017 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-06-17T08:45:18.158 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-06-17T08:45:18.283 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-06-17T08:45:18.346 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-06-17T08:45:18.377 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-06-17T08:45:18.517 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-06-17T08:45:19.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-06-17T08:45:19.080 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-06-17T08:45:19.158 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:19.533 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:19.642 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:20.111 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-06-17T08:45:20.158 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-06-17T08:45:20.299 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-06-17T08:45:20.392 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-06-17T08:45:20.439 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:20.455 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-06-17T08:45:20.799 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-06-17T08:45:20.892 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-06-17T08:45:20.971 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-06-17T08:45:21.080 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-06-17T08:45:21.096 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-06-17T08:45:21.205 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-06-17T08:45:21.346 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-06-17T08:45:21.455 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-06-17T08:45:21.517 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-06-17T08:45:21.549 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-06-17T08:45:21.767 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-06-17T08:45:21.767 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-06-17T08:45:21.924 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-06-17T08:45:22.424 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-06-17T08:45:22.627 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-06-17T08:45:22.689 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-06-17T08:45:23.049 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-06-17T08:45:23.096 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-06-17T08:45:23.158 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-06-17T08:45:23.252 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-06-17T08:45:23.361 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-06-17T08:45:23.361 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-06-17T08:45:23.502 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-06-17T08:45:23.658 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-06-17T08:45:23.846 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-06-17T08:45:23.971 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-06-17T08:45:24.361 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-06-17T08:45:24.486 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-06-17T08:45:24.861 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-06-17T08:45:24.892 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-06-17T08:45:25.017 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-06-17T08:45:25.017 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-06-17T08:45:25.189 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-06-17T08:45:25.346 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-06-17T08:45:25.455 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-06-17T08:45:25.455 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:25.705 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-06-17T08:45:25.986 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-06-17T08:45:26.002 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-06-17T08:45:26.049 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-17T08:45:26.158 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-06-17T08:45:26.439 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-06-17T08:45:26.580 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-06-17T08:45:26.689 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:27.439 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-06-17T08:45:27.564 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-06-17T08:45:27.721 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-06-17T08:45:28.096 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-06-17T08:45:28.127 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-06-17T08:45:28.127 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-06-17T08:45:28.424 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-06-17T08:45:28.658 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-06-17T08:45:28.814 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-06-17T08:45:28.955 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-06-17T08:45:28.971 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-06-17T08:45:29.205 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-06-17T08:45:29.377 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-06-17T08:45:29.392 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-06-17T08:45:29.502 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-17T08:45:29.877 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-06-17T08:45:29.939 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-06-17T08:45:29.939 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-06-17T08:45:30.033 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-06-17T08:45:30.502 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-06-17T08:45:30.658 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-06-17T08:45:30.721 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-06-17T08:45:30.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-06-17T08:45:30.908 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-06-17T08:45:31.002 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-06-17T08:45:31.049 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-06-17T08:45:31.174 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:31.283 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-06-17T08:45:31.439 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-06-17T08:45:31.564 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-06-17T08:45:31.642 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-06-17T08:45:31.736 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-06-17T08:45:31.752 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-06-17T08:45:31.846 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-06-17T08:45:32.721 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-06-17T08:45:33.252 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-06-17T08:45:33.283 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-17T08:45:33.361 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-06-17T08:45:33.986 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-06-17T08:45:34.486 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-06-17T08:45:34.564 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-06-17T08:45:34.721 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-06-17T08:45:34.986 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-06-17T08:45:35.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-06-17T08:45:35.361 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-06-17T08:45:35.439 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-06-17T08:45:35.517 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-06-17T08:45:35.549 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-06-17T08:45:35.674 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-06-17T08:45:36.174 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:45:36.502 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-06-17T08:45:36.564 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-06-17T08:45:37.158 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-17T08:45:37.471 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-06-17T08:45:37.611 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-06-17T08:45:37.830 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:37.955 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-06-17T08:45:38.017 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-06-17T08:45:38.174 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-06-17T08:45:38.236 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-06-17T08:45:38.314 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-06-17T08:45:38.424 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-06-17T08:45:38.439 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-06-17T08:45:38.455 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-06-17T08:45:38.502 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-06-17T08:45:38.502 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-06-17T08:45:38.767 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-17T08:45:38.783 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-06-17T08:45:38.814 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-06-17T08:45:38.955 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-06-17T08:45:39.064 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-06-17T08:45:39.283 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-06-17T08:45:39.549 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:45:39.799 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-06-17T08:45:39.939 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-06-17T08:45:40.189 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-06-17T08:45:41.174 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-06-17T08:45:41.252 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-06-17T08:45:41.533 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-06-17T08:45:41.846 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-06-17T08:45:41.924 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-06-17T08:45:41.971 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-06-17T08:45:41.986 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-06-17T08:45:42.002 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-06-17T08:45:42.064 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:42.377 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-06-17T08:45:42.392 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-06-17T08:45:42.971 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-06-17T08:45:43.049 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-06-17T08:45:43.892 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-06-17T08:45:43.908 Engine:Setting original file name "msvcp140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_app.dll", hr=0x800710da 2026-06-17T08:45:44.127 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-06-17T08:45:44.174 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-06-17T08:45:44.236 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-06-17T08:45:44.580 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-06-17T08:45:44.689 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-17T08:45:44.892 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-06-17T08:45:45.283 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-06-17T08:45:45.346 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-06-17T08:45:45.611 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-06-17T08:45:45.830 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-06-17T08:45:45.939 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-06-17T08:45:45.986 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-06-17T08:45:46.080 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-06-17T08:45:46.158 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:46.189 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-06-17T08:45:46.502 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-06-17T08:45:46.783 Engine:Setting original file name "Microsoft.Management.Deployment.OutOfProc.dll" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\microsoft.management.deployment.dll", hr=0x800710da 2026-06-17T08:45:46.799 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-06-17T08:45:46.846 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-06-17T08:45:47.408 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-06-17T08:45:47.658 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-06-17T08:45:47.767 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:47.892 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-06-17T08:45:48.283 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-06-17T08:45:48.392 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-06-17T08:45:48.439 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-06-17T08:45:48.486 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-06-17T08:45:48.549 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-06-17T08:45:48.580 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:48.736 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-06-17T08:45:48.783 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-06-17T08:45:48.892 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-06-17T08:45:48.955 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-06-17T08:45:49.017 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:45:49.174 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-06-17T08:45:49.502 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-06-17T08:45:49.564 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-06-17T08:45:49.752 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-06-17T08:45:50.221 Engine:Setting original file name "setup" for "c:\program files\microsoft office\root\integration\addons\vc_redist.x64.exe", hr=0x800710da 2026-06-17T08:45:50.252 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-06-17T08:45:50.549 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-06-17T08:45:50.642 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:51.002 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-06-17T08:45:51.408 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-06-17T08:45:51.752 Engine:Setting original file name "msvcp140_1_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\msvcp140_1_app.dll", hr=0x800710da 2026-06-17T08:45:51.814 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-06-17T08:45:51.861 Engine:Setting original file name "vcruntime140_app" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll", hr=0x800710da 2026-06-17T08:45:52.127 Engine:Setting original file name "mapi32.dll" for "c:\windows\winsxs\wow64_microsoft-windows-mapi_31bf3856ad364e35_10.0.22000.120_none_b1071c7fd34df0e8\mapistub.dll", hr=0x800710da 2026-06-17T08:45:52.267 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-06-17T08:45:53.142 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-06-17T08:45:53.721 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-06-17T08:45:53.939 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-06-17T08:45:53.971 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-06-17T08:45:54.033 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-06-17T08:45:54.049 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-06-17T08:45:54.549 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-06-17T08:45:54.596 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-06-17T08:45:54.658 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-06-17T08:45:54.971 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-06-17T08:45:54.986 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-06-17T08:45:55.221 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-06-17T08:45:55.299 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-06-17T08:45:55.346 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-06-17T08:45:55.361 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-06-17T08:45:55.486 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-06-17T08:45:56.299 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-06-17T08:45:56.549 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-06-17T08:45:56.596 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-06-17T08:45:56.814 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:56.924 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\mozilla firefox\coremessagingxp.dll", hr=0x800710da 2026-06-17T08:45:57.236 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-06-17T08:45:57.236 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-06-17T08:45:57.236 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-06-17T08:45:57.564 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-06-17T08:45:57.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-06-17T08:45:57.814 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.desktopappinstaller_1.28.240.0_x64__8wekyb3d8bbwe\dotnet\system.io.compression.native.dll", hr=0x800710da 2026-06-17T08:45:58.017 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-06-17T08:45:58.096 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-06-17T08:45:58.189 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-06-17T08:45:58.221 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-06-17T08:45:59.127 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\winsxs\amd64_microsoft-windows-appx-deployment-server_31bf3856ad364e35_10.0.22000.2538_none_da66fd59ee613b34\applytrustoffline.exe", hr=0x800710da 2026-06-17T08:45:59.283 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-06-17T08:45:59.330 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-06-17T08:45:59.564 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-06-17T08:45:59.611 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-06-17T08:45:59.642 Engine:Setting original file name "MicrosoftEdgeUpdateSetup.exe" for "c:\program files (x86)\microsoft\edgeupdate\download\{f3c4fe00-efd5-403b-9569-398a20f1ba4a}\1.3.241.13\microsoftedgeupdatesetup_x86_1.3.241.13.exe", hr=0x800710da 2026-06-17T08:45:59.721 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-06-17T08:45:59.861 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:45:59.955 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-06-17T08:45:59.986 Engine:Setting original file name "powershell.exe" for "c:\windows\winsxs\wow64_microsoft-windows-powershell-exe_31bf3856ad364e35_10.0.22000.1_none_c9ae46ac3b5c78ef\powershell.exe", hr=0x800710da 2026-06-17T08:46:00.017 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-06-17T08:46:00.064 Engine:Setting original file name "Firefox" for "c:\program files\mozilla firefox\crashreporter.exe", hr=0x800710da 2026-06-17T08:46:00.236 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-06-17T08:46:00.283 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-06-17T08:46:00.361 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-06-17T08:46:00.392 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-06-17T08:46:00.392 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-06-17T08:46:00.705 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-06-17T08:46:00.846 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-06-17T08:46:00.908 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-06-17T08:46:00.924 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-06-17T08:46:01.174 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-06-17T08:46:01.314 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:46:01.330 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:46:01.346 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-06-17T08:46:01.658 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-06-17T08:46:02.049 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-06-17T08:46:02.142 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-06-17T08:46:02.267 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-06-17T08:46:02.377 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-06-17T08:46:02.471 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-06-17T08:46:02.596 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-06-17T08:46:02.689 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-06-17T08:46:02.830 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-06-17T08:46:02.971 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-06-17T08:46:03.017 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-06-17T08:46:03.049 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-06-17T08:46:03.283 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-06-17T08:46:03.377 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-06-17T08:46:03.392 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-06-17T08:46:03.392 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-06-17T08:46:03.986 Engine:Setting original file name "uasp.sys" for "c:\windows\system32\driverstore\filerepository\uaspstor.inf_amd64_ead2ec56d8760a84\uaspstor.sys", hr=0x800710da 2026-06-17T08:46:04.283 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-06-17T08:46:04.408 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-06-17T08:46:04.486 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-06-17T08:46:04.580 Engine:Setting original file name "clrgc.dll" for "c:\program files\windowsapps\microsoft.gethelp_10.2409.41132.0_x64__8wekyb3d8bbwe\clrgcexp.dll", hr=0x800710da 2026-06-17T08:46:04.846 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-06-17T08:46:05.142 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-06-17T08:46:05.174 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-06-17T08:46:05.580 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-06-17T08:46:05.705 Engine:Setting original file name "msdxm.ocx" for "c:\windows\syswow64\dxmasf.dll", hr=0x800710da 2026-06-17T08:46:06.627 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-06-17T08:46:06.674 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-06-17T08:46:06.799 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-06-17T08:46:06.799 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-06-17T08:46:06.924 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_flac_plugin.dll", hr=0x800710da 2026-06-17T08:46:07.017 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\de-de\wsepno.dll.mui", hr=0x800710da 2026-06-17T08:46:07.314 Engine:Setting original file name "iscsiexe.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a56629be7473c8fd73a9fa129c67ea10\iscsiexe.dll.mui", hr=0x800710da 2026-06-17T08:46:07.408 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\11a533a2a1579c078648dff16787f54d\winnlsres.dll.mui", hr=0x800710da 2026-06-17T08:46:07.611 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_udp_plugin.dll", hr=0x800710da 2026-06-17T08:46:07.611 Engine:Setting original file name "hgclientservice.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\3bbe55bd039ee800ee6a295dceb66af6\hgclientservice.dll.mui", hr=0x800710da 2026-06-17T08:46:07.705 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\bcf69d5438188e70293457b0ada7ebac\aeevts.dll.mui", hr=0x800710da 2026-06-17T08:46:07.736 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\system32\devobj.dll", hr=0x800710da 2026-06-17T08:46:08.361 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\websockify\melt command websocket.vshost.exe", hr=0x800710da 2026-06-17T08:46:08.392 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libudp_plugin.dll", hr=0x800710da 2026-06-17T08:46:08.517 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\libmarq_plugin.dll", hr=0x800710da 2026-06-17T08:46:08.658 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libasf_plugin.dll", hr=0x800710da 2026-06-17T08:46:08.674 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x800710da 2026-06-17T08:46:08.830 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-06-17T08:46:09.314 Engine:Setting original file name "srprop.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..pertypage.resources_31bf3856ad364e35_10.0.22000.1_de-de_d550522784983fe6\srrstr.dll.mui", hr=0x800710da 2026-06-17T08:46:09.439 OriginalFileName Maintenance::9849 files in Moac, 225 skipped (cached), 1 filename set 2026-06-17T08:46:09.439 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-06-17T08:46:15.111 Engine:Triggered AR EMS scan 2026-06-17T08:46:15.111 Engine:EMS scan for process: lsass pid: 776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.142 Engine:EMS scan for process: svchost pid: 980, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.158 Engine:EMS scan for process: svchost pid: 808, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.158 Engine:EMS scan for process: svchost pid: 1064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.174 Engine:EMS scan for process: svchost pid: 1228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.189 Engine:EMS scan for process: svchost pid: 1264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.205 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.221 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.221 Engine:EMS scan for process: svchost pid: 1428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.221 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.236 Engine:EMS scan for process: svchost pid: 1464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.236 Engine:EMS scan for process: svchost pid: 1528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.236 Engine:EMS scan for process: svchost pid: 1572, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.252 Engine:EMS scan for process: svchost pid: 1664, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.252 Engine:EMS scan for process: svchost pid: 1672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.267 Engine:EMS scan for process: svchost pid: 1720, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.267 Engine:EMS scan for process: svchost pid: 1964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.283 Engine:EMS scan for process: svchost pid: 764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.299 Engine:EMS scan for process: svchost pid: 1536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.299 Engine:EMS scan for process: svchost pid: 2156, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.314 Engine:EMS scan for process: svchost pid: 2184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.314 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2516, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2560, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.330 Engine:EMS scan for process: svchost pid: 2728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.346 Engine:EMS scan for process: svchost pid: 2776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.377 Engine:EMS scan for process: svchost pid: 2792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.392 Engine:EMS scan for process: svchost pid: 3056, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.392 Engine:EMS scan for process: svchost pid: 2820, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.408 Engine:EMS scan for process: svchost pid: 3120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.408 Engine:EMS scan for process: svchost pid: 3244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.439 Engine:EMS scan for process: svchost pid: 3796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.439 Engine:EMS scan for process: svchost pid: 3920, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.471 Engine:EMS scan for process: svchost pid: 3952, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.471 Engine:EMS scan for process: svchost pid: 3960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.486 Engine:EMS scan for process: svchost pid: 3992, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.486 Engine:EMS scan for process: svchost pid: 4088, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.486 Engine:EMS scan for process: svchost pid: 3352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.517 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.517 Engine:EMS scan for process: svchost pid: 4204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.533 Engine:EMS scan for process: svchost pid: 4380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.533 Engine:EMS scan for process: svchost pid: 4392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.549 Engine:EMS scan for process: svchost pid: 4660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.549 Engine:EMS scan for process: svchost pid: 4688, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.564 Engine:EMS scan for process: svchost pid: 4732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.564 Engine:EMS scan for process: svchost pid: 4772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.564 Engine:EMS scan for process: svchost pid: 5404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.580 Engine:EMS scan for process: svchost pid: 5464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.596 Engine:EMS scan for process: svchost pid: 5472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.596 Engine:EMS scan for process: svchost pid: 5728, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.596 Engine:EMS scan for process: dllhost pid: 6104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.611 Engine:EMS scan for process: svchost pid: 956, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.611 Engine:EMS scan for process: svchost pid: 6488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.611 Engine:EMS scan for process: svchost pid: 6344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.611 Engine:EMS scan for process: svchost pid: 7304, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.611 Engine:EMS scan for process: svchost pid: 6308, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.627 Engine:EMS scan for process: svchost pid: 5840, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.627 Engine:EMS scan for process: svchost pid: 7916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.642 Engine:EMS scan for process: svchost pid: 6356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.642 Engine:EMS scan for process: svchost pid: 8064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.658 Engine:EMS scan for process: svchost pid: 4100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.658 Engine:EMS scan for process: explorer pid: 3424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.767 Engine:EMS scan for process: svchost pid: 8296, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.767 Engine:EMS scan for process: svchost pid: 8420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.767 Engine:EMS scan for process: svchost pid: 8800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.783 Engine:EMS scan for process: svchost pid: 9344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.783 Engine:EMS scan for process: dllhost pid: 10104, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.783 Engine:EMS scan for process: svchost pid: 11384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.799 Engine:EMS scan for process: svchost pid: 3492, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.799 Engine:EMS scan for process: svchost pid: 7192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.814 Engine:EMS scan for process: svchost pid: 3340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.814 Engine:EMS scan for process: svchost pid: 12324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.814 Engine:EMS scan for process: svchost pid: 7748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.830 Engine:EMS scan for process: svchost pid: 1112, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.830 Engine:EMS scan for process: svchost pid: 11344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.830 Engine:EMS scan for process: svchost pid: 11964, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.846 Engine:EMS scan for process: svchost pid: 11556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.846 Engine:EMS scan for process: wuauclt pid: 7564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.846 Engine:EMS scan for process: svchost pid: 6408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.846 Engine:EMS scan for process: svchost pid: 6968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:46:15.846 Engine:EMS scan for process: svchost pid: 9972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-06-17T08:51:30.471 QuickScan:ScanID:3F3FE61A-EAFE-4203-9AFC-4A7AC1D765D3: Quick scan finished with error 0 2026-06-17T08:51:30.986 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-17T08:51:30.986 [RTP] Duplicating the current plugin configuration object... 2026-06-17T08:51:30.986 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T08:51:30.986 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-06-17T08:51:30.986 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T08:51:30.986 [RTP] No config change detected. Not updating plugin configuration. 2026-06-17T08:51:30.986 [RTP] No config changes found. No configuration switch. 2026-06-17T08:51:30.986 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-06-17T08:51:32.486 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:51:32.486 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T08:51:32.502 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T08:52:35.939 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #49021, FileId: 0x24d0000000001a6, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T08:52:37.314 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-06-17T08:52:37.330 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-06-17T08:59:32.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T09:14:37.870 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T09:29:42.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T09:44:47.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T09:49:05.439 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53093, FileId: 0x3b00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.439 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53092, FileId: 0x3900000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.439 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53096, FileId: 0x3c00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.439 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53091, FileId: 0x4000000000d128, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.455 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53098, FileId: 0x3d00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.455 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53095, FileId: 0x4300000000d128, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:49:05.471 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #53104, FileId: 0x4000000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T09:59:52.870 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T10:14:57.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T10:25:26.424 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 27362, Count: 727, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T10:25:26.424 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T10:25:26.424 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T10:25:26.424 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T10:25:26.424 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T10:25:26.424 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T10:25:26.424 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3827, Count: 140, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T10:25:26.424 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T10:25:26.424 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T10:25:26.424 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T10:25:26.424 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T10:25:26.424 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2144, Count: 68, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 12% 2026-06-17T10:25:26.424 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T10:25:26.424 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T10:25:26.424 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T10:25:26.424 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T10:25:26.424 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T10:25:26.424 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T10:25:26.424 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1096, Count: 62, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T10:25:26.424 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T10:25:26.424 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T10:25:26.424 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T10:25:26.424 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T10:25:26.424 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T10:25:26.424 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T10:25:26.424 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T10:25:26.424 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T10:25:26.424 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T10:25:26.424 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T10:25:26.424 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T10:25:26.424 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 217, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 202, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T10:25:26.424 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T10:25:26.424 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T10:25:26.424 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T10:25:26.424 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T10:25:26.424 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T10:25:26.424 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T10:25:26.424 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T10:25:26.424 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T10:25:26.424 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T10:25:26.424 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T10:25:26.424 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T10:25:26.424 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T10:25:26.424 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T10:25:26.424 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T10:25:26.424 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T10:25:26.424 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T10:25:26.424 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T10:25:26.424 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T10:25:26.424 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T10:25:26.424 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T10:25:26.424 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T10:25:26.424 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T10:25:26.424 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T10:25:26.424 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T10:25:26.424 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T10:25:26.424 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T10:25:26.424 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T10:25:26.424 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T10:30:02.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T10:45:07.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T11:00:12.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T11:15:17.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T11:30:22.884 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T11:45:27.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T12:00:32.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T12:15:37.878 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T12:25:26.425 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 27408, Count: 729, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T12:25:26.425 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T12:25:26.425 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T12:25:26.425 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T12:25:26.425 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T12:25:26.425 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T12:25:26.425 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 142, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T12:25:26.425 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T12:25:26.425 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T12:25:26.425 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T12:25:26.425 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T12:25:26.425 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2144, Count: 68, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 12% 2026-06-17T12:25:26.425 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T12:25:26.425 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T12:25:26.425 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T12:25:26.425 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T12:25:26.425 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T12:25:26.425 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T12:25:26.425 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1172, Count: 66, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T12:25:26.425 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T12:25:26.425 ProcessImageName: httpd.exe, Pid: 2948, TotalTime: 742, Count: 70, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T12:25:26.425 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T12:25:26.425 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T12:25:26.425 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T12:25:26.425 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T12:25:26.425 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T12:25:26.425 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T12:25:26.425 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T12:25:26.425 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T12:25:26.425 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T12:25:26.425 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T12:25:26.425 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 217, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 202, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T12:25:26.425 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T12:25:26.425 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T12:25:26.425 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T12:25:26.425 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T12:25:26.425 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T12:25:26.425 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T12:25:26.425 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T12:25:26.425 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T12:25:26.425 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T12:25:26.425 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T12:25:26.425 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T12:25:26.425 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T12:25:26.425 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T12:25:26.425 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T12:25:26.425 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T12:25:26.425 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T12:25:26.425 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T12:25:26.425 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T12:25:26.425 ProcessImageName: mysqld.exe, Pid: 7380, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\02_myWebseiten\0_Webseiten_offline\javascript_offline\www.javascript-kurs.de\bilder\javascript-use-strict-mode.jpg, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T12:25:26.425 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 4656, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1244.log->(UTF-16LE), EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T12:25:26.425 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T12:25:26.425 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: dllhost.exe, Pid: 3004, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T12:25:26.425 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 5420, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1402.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T12:25:26.425 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T12:25:26.425 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T12:30:42.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T12:45:47.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T13:00:52.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T13:15:57.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T13:22:23.861 [AutoPurge] Verification Routine tasks have started. 2026-06-17T13:22:23.861 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-17T13:22:23.893 [AutoPurge] Cleanup Routine tasks have started. 2026-06-17T13:22:23.893 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-06-17T13:22:23.893 [AutoPurge] Routine task for Cache Maintenance has started. 2026-06-17T13:22:23.893 [AutoPurge] Routine task for Cache Maintenance ... 2026-06-17T13:22:23.893 [AutoPurge] Routine task for MpSFCBuild ... 2026-06-17T13:22:23.893 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-06-17T13:22:23.893 [AutoPurge] MpSignalMaintenanceMode ... 2026-06-17T13:22:23.893 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-06-17T13:22:23.893 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:305D4703-A2AD-4AFC-A8E1-BCCC78203873, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-06-17T13:22:23.893 Scheduled scan with Id 305D4703-A2AD-4AFC-A8E1-BCCC78203873 configured CPU priority: normal (LowCpuPriority: 0) 2026-06-17T13:22:23.893 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-06-17T13:22:23.893 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:06-17-2026 13:22:23 2026-06-17T13:22:23.893 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-06-17T13:22:23.893 [SFC] System file cache build is not needed (already completed) 2026-06-17T13:22:23.893 QuickScan:ScanID:305D4703-A2AD-4AFC-A8E1-BCCC78203873: Quick Scan skipped since it already ran during the past 7 days 2026-06-17T13:22:23.893 QuickScan:ScanID:305D4703-A2AD-4AFC-A8E1-BCCC78203873: Quick scan finished with error 1223 2026-06-17T13:22:23.908 OnDemandScanWorker: Scan Cancelled! scanId:305D4703-A2AD-4AFC-A8E1-BCCC78203873, hr = 0x80508018 !ERROR Begin Quick Scan Scan ID:{305D4703-A2AD-4AFC-A8E1-BCCC78203873} Scan Source:1 Start Time:06-17-2026 13:22:23 Unsuccessful Scan Return Code:1223 ************************************************************ Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-17-2026 13:22:23 2026-06-17T13:22:23.924 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-06-17T13:22:23.924 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-06-17T13:22:23.924 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-06-17T13:22:23.924 [PlatUpd] Deleting orphaned platform update directory C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26030.3011-0 ... 2026-06-17T13:22:24.018 [PlatUpd] Deleting orphaned platform update directory C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26020.6-0 ... 2026-06-17T13:22:24.096 EnsureProtectedFolderAcls(), hr = 0x0 2026-06-17T13:22:24.111 [AutoPurge] MpReinforceServiceAcls: 0 2026-06-17T13:22:24.111 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-06-17T13:22:24.111 [AutoPurge] Cleanup Routine tasks have ended. 2026-06-17T13:22:24.127 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-06-17T13:22:24.143 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-06-17T13:22:24.143 [AutoPurge] Verification Routine tasks have ended. 2026-06-17T13:22:24.683 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-17T13:22:24.717 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 2 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 4096 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 4 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 8 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 16 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-17T13:22:24.718 [RTP] [RtpConfig] Config change detected, type: 2048 2026-06-17T13:22:24.718 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-17T13:22:24.718 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-17T13:22:24.718 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-17T13:22:24.719 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-17T13:22:24.719 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-17T13:22:24.719 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-17T13:22:24.720 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-17T13:22:24.720 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T13:22:24.720 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T13:22:24.720 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-17T13:22:24.721 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-17T13:22:24.721 [RTP] [RtpConfig] Config change detected, type: 64 2026-06-17T13:22:24.727 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T13:22:24.733 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T13:22:24.738 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T13:22:24.745 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T13:22:24.749 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T13:22:24.765 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 43867814(ms) from now at 03:33 (01:33 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-06-17T13:22:26.532 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T13:22:26.859 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T13:22:26.863 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T13:22:27.792 [RTP] Duplicating the current plugin configuration object... 2026-06-17T13:22:27.792 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T13:22:27.792 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-06-17T13:22:27.792 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T13:22:27.792 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-17T13:22:27.795 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-06-17T13:22:28.878 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T13:22:28.884 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T13:22:28.885 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T13:22:37.436 Engine:Process 4280 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-06-17T13:26:38.080 [AutoPurge] Verification Routine tasks have started. 2026-06-17T13:26:38.080 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-17T13:26:38.080 [AutoPurge] Routine task for Cache Maintenance has started. 2026-06-17T13:26:38.080 [AutoPurge] Routine task for Cache Maintenance ... 2026-06-17T13:26:38.080 [AutoPurge] Routine task for MpSFCBuild ... 2026-06-17T13:26:38.080 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-06-17T13:26:38.080 [AutoPurge] MpSignalMaintenanceMode ... 2026-06-17T13:26:38.080 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-06-17T13:26:38.080 [AutoPurge] Cleanup Routine tasks have started. 2026-06-17T13:26:38.080 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-06-17T13:26:38.096 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-06-17T13:26:38.096 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:06-17-2026 13:26:38 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-17-2026 13:26:38 2026-06-17T13:26:38.096 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-06-17T13:26:38.096 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-06-17T13:26:38.096 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-06-17T13:26:38.096 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-06-17T13:26:38.096 [AutoPurge] Cleanup Routine tasks have ended. 2026-06-17T13:26:38.221 EnsureProtectedFolderAcls(), hr = 0x0 2026-06-17T13:26:38.221 [AutoPurge] MpReinforceServiceAcls: 0 2026-06-17T13:26:38.236 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-06-17T13:26:38.252 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-06-17T13:26:38.252 [AutoPurge] Verification Routine tasks have ended. 2026-06-17T13:26:39.377 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #55828, FileId: 0xbc0000000246f2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T13:31:02.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T13:37:41.002 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #56079, FileId: 0x19e0000000060c3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T13:46:07.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T14:01:12.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T14:16:17.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T14:24:23.393 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-06-17T14:24:23.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 32 2026-06-17T14:24:23.409 [RTP] Duplicating the current plugin configuration object... 2026-06-17T14:24:23.409 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T14:24:23.409 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 2 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 4096 2026-06-17T14:24:23.409 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T14:24:23.409 [RTP] No config change detected. Not updating plugin configuration. 2026-06-17T14:24:23.409 [RTP] No config changes found. No configuration switch. 2026-06-17T14:24:23.409 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-06-17T14:24:23.409 [RTP] Duplicating the current plugin configuration object... 2026-06-17T14:24:23.409 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T14:24:23.409 [RTP] Updating plugin configuration due to recent config changes (0x2) ... 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 4 2026-06-17T14:24:23.409 [RTP] No config change detected. Not updating plugin configuration. 2026-06-17T14:24:23.409 [RTP] No config changes found. No configuration switch. 2026-06-17T14:24:23.409 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x2, Changed: 0 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 8 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 16 2026-06-17T14:24:23.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 1024 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 2048 2026-06-17T14:24:23.409 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-17T14:24:23.409 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T14:24:23.409 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T14:24:23.409 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-17T14:24:23.409 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-06-17T14:24:23.409 [RTP] [RtpConfig] Config change detected, type: 64 2026-06-17T14:24:23.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T14:24:23.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T14:24:23.424 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T14:24:23.440 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 40727427(ms) from now at 03:43 (01:43 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-06-17T14:24:25.987 [RTP] Duplicating the current plugin configuration object... 2026-06-17T14:24:25.987 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-06-17T14:24:25.987 [RTP] Updating plugin configuration due to recent config changes (0x41c) ... 2026-06-17T14:24:25.987 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-06-17T14:24:25.987 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41c, Changed: 0x208 2026-06-17T14:25:26.440 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 35787, Count: 786, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T14:25:26.440 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T14:25:26.440 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T14:25:26.440 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T14:25:26.440 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T14:25:26.440 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T14:25:26.440 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 144, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T14:25:26.440 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T14:25:26.440 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T14:25:26.440 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T14:25:26.440 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2299, Count: 72, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T14:25:26.440 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T14:25:26.440 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T14:25:26.440 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T14:25:26.440 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T14:25:26.440 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T14:25:26.440 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T14:25:26.440 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1202, Count: 75, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T14:25:26.440 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T14:25:26.440 ProcessImageName: httpd.exe, Pid: 2948, TotalTime: 742, Count: 70, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T14:25:26.440 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T14:25:26.440 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T14:25:26.440 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T14:25:26.440 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T14:25:26.440 ProcessImageName: SDXHelper.exe, Pid: 12196, TotalTime: 511, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 15% 2026-06-17T14:25:26.440 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T14:25:26.440 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T14:25:26.440 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T14:25:26.440 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T14:25:26.440 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T14:25:26.440 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T14:25:26.440 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 248, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 217, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T14:25:26.440 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T14:25:26.440 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T14:25:26.440 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T14:25:26.440 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T14:25:26.440 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 107, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 5988, TotalTime: 106, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 4% 2026-06-17T14:25:26.440 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: SDXHelper.exe, Pid: 5276, TotalTime: 105, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 2% 2026-06-17T14:25:26.440 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T14:25:26.440 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 105, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T14:25:26.440 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T14:25:26.440 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T14:25:26.440 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T14:25:26.440 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T14:25:26.440 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T14:25:26.440 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 764, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\042DAB8CC792B670CFA0C1C9B65448D2C8F5D961, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T14:25:26.440 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T14:25:26.440 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T14:25:26.440 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T14:25:26.440 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T14:25:26.440 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T14:25:26.440 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\02_myWebseiten\0_Webseiten_offline\javascript_offline\www.javascript-kurs.de\bilder\javascript-use-strict-mode.jpg, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T14:25:26.440 ProcessImageName: mysqld.exe, Pid: 7380, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T14:25:26.440 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 4656, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1244.log->(UTF-16LE), EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T14:25:26.440 ProcessImageName: sihost.exe, Pid: 8164, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T14:25:26.440 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: dllhost.exe, Pid: 3004, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 1552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1522.log, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T14:25:26.440 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T14:25:26.440 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 5420, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1402.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 1228, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-17T14:25:26.440 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T14:26:52.099 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #56335, FileId: 0x2300000003a702, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:31:22.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T14:46:27.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T14:54:40.377 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56670, FileId: 0x8e00000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.377 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56671, FileId: 0x4700000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.377 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56673, FileId: 0x4800000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.377 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56667, FileId: 0x4600000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.393 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56672, FileId: 0x8f00000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.393 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56675, FileId: 0x4900000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56678, FileId: 0x9200000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56679, FileId: 0x4b00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56682, FileId: 0x9400000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56677, FileId: 0x4a00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56684, FileId: 0x4d00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56685, FileId: 0x9500000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56674, FileId: 0x9000000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56680, FileId: 0x9300000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.408 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56687, FileId: 0x9600000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.424 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56681, FileId: 0x4c00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56690, FileId: 0x5000000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56691, FileId: 0x9800000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56686, FileId: 0x4e00000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56693, FileId: 0x9900000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56692, FileId: 0x5100000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56689, FileId: 0x9700000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56694, FileId: 0x9a00000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.439 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56695, FileId: 0x5200000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.830 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\45bf5d73-c41b-42e7-b85f-f0ef2fa0ff83. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #56781, FileId: 0x7800000000a02c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T14:54:40.830 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #56779, FileId: 0x5400000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T15:01:32.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T15:11:29.222 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #57330, FileId: 0x9f000000008146, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T15:16:37.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T15:31:42.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T15:46:47.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T16:01:52.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T16:16:57.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T16:25:26.444 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 37175, Count: 829, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T16:25:26.444 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T16:25:26.444 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T16:25:26.444 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T16:25:26.444 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T16:25:26.444 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T16:25:26.444 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 146, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T16:25:26.444 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T16:25:26.444 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T16:25:26.444 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T16:25:26.444 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2299, Count: 72, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T16:25:26.444 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T16:25:26.444 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T16:25:26.444 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T16:25:26.444 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T16:25:26.444 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T16:25:26.444 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1217, Count: 77, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T16:25:26.444 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T16:25:26.444 ProcessImageName: httpd.exe, Pid: 2948, TotalTime: 742, Count: 70, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T16:25:26.444 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T16:25:26.444 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T16:25:26.444 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T16:25:26.444 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T16:25:26.444 ProcessImageName: SDXHelper.exe, Pid: 12196, TotalTime: 511, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 15% 2026-06-17T16:25:26.444 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T16:25:26.444 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T16:25:26.444 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T16:25:26.444 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T16:25:26.444 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: firefox.exe, Pid: 7152, TotalTime: 285, Count: 100, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 21% 2026-06-17T16:25:26.444 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T16:25:26.444 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T16:25:26.444 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 248, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 217, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: FileCoAuth.exe, Pid: 8120, TotalTime: 196, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T16:25:26.444 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T16:25:26.444 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T16:25:26.444 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 5988, TotalTime: 106, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 4% 2026-06-17T16:25:26.444 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: SDXHelper.exe, Pid: 5276, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 105, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T16:25:26.444 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T16:25:26.444 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T16:25:26.444 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T16:25:26.444 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T16:25:26.444 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T16:25:26.444 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 8936, TotalTime: 75, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1781684921, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 764, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\042DAB8CC792B670CFA0C1C9B65448D2C8F5D961, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T16:25:26.444 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T16:25:26.444 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\02_myWebseiten\0_Webseiten_offline\javascript_offline\www.javascript-kurs.de\bilder\javascript-use-strict-mode.jpg, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T16:25:26.444 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T16:25:26.444 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T16:25:26.444 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: SDXHelper.exe, Pid: 1480, TotalTime: 61, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7FE0CA44-35C7-4A07-B94C-63D6071D6BDD, EstimatedImpact: 6% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 5608, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 2% 2026-06-17T16:25:26.444 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: mysqld.exe, Pid: 7380, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T16:25:26.444 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T16:25:26.444 ProcessImageName: taskhostw.exe, Pid: 8144, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 22% 2026-06-17T16:25:26.444 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 4656, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1244.log->(UTF-16LE), EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T16:25:26.444 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T16:25:26.444 ProcessImageName: sihost.exe, Pid: 8164, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T16:25:26.444 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: dllhost.exe, Pid: 3004, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 1552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1522.log, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T16:25:26.444 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T16:25:26.444 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 5420, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1402.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 1228, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-17T16:25:26.444 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T16:32:02.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T16:47:07.881 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T16:49:04.865 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59629, FileId: 0x16100000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.865 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59628, FileId: 0xa100000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.881 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59630, FileId: 0x16200000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.881 Bm signature throttled:0x000045b3435c1067 2026-06-17T16:49:04.881 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59633, FileId: 0xa300000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.881 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59627, FileId: 0xa000000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.881 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59635, FileId: 0xa400000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.881 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59634, FileId: 0x16400000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.897 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59640, FileId: 0xa800000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.897 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59639, FileId: 0xa700000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:04.897 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59637, FileId: 0xa500000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:05.334 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #59727, FileId: 0xab00000000c175, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:49:05.334 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\9a17648e-36ff-4bbf-a9b9-eeebd4105cc1. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #59729, FileId: 0x44000000097e07, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T16:59:07.528 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #59863, FileId: 0x7d00000003e43e, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T17:02:12.877 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T17:15:10.417 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #60194, FileId: 0x2100000003d706, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T17:17:17.869 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{F6E6769A-E450-C933-8593-774C21DD32BA} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:3616 ProcessCreationTime:134261664301862945 SessionID:2 CreationTime:06-17-2026 17:22:18 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-06-17T17:22:19.736 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T17:22:19.736 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T17:22:19.736 [Cloud] Queued cloud request. 2026-06-17T17:22:19.736 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T17:22:19.736 [Cloud] Dequeued cloud request. 2026-06-17T17:22:19.736 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T17:22:20.065 [Cloud] End of cloud request. 2026-06-17T17:22:20.580 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T17:28:25.408 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #60233, FileId: 0x2600000003d706, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T17:32:19.944 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T17:33:55.475 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #60279, FileId: 0x1500000003d75f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T17:47:24.944 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T18:02:29.943 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T18:17:34.943 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T18:18:00.271 [NRI] Successfully updated NIS service with platform settings for enforcement level Log IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 2026-06-17T18:18:00.303 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-17T18:18:00.303 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-17T18:18:00.303 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-17T18:18:00.303 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T18:18:00.303 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T18:18:00.303 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T18:18:00.303 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T18:18:00.303 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T18:18:00.303 MdCoreSvc is supported in this platform and OS 2026-06-17T18:18:00.787 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-17T18:18:00.787 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-17T18:18:00.787 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T18:25:23.521 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 37175, Count: 831, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T18:25:23.521 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T18:25:23.521 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T18:25:23.521 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T18:25:23.521 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T18:25:23.521 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T18:25:23.521 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 148, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T18:25:23.521 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T18:25:23.521 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T18:25:23.521 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T18:25:23.521 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2314, Count: 75, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T18:25:23.521 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T18:25:23.521 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T18:25:23.521 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T18:25:23.521 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T18:25:23.521 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1217, Count: 79, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T18:25:23.521 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T18:25:23.521 ProcessImageName: httpd.exe, Pid: 2948, TotalTime: 742, Count: 70, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T18:25:23.521 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T18:25:23.521 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T18:25:23.521 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T18:25:23.521 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T18:25:23.521 ProcessImageName: SDXHelper.exe, Pid: 12196, TotalTime: 511, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 15% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T18:25:23.521 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 11696, TotalTime: 450, Count: 94, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10812, EstimatedImpact: 58% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T18:25:23.521 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T18:25:23.521 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 7152, TotalTime: 285, Count: 100, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 21% 2026-06-17T18:25:23.521 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 279, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T18:25:23.521 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 248, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 2532, TotalTime: 201, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: FileCoAuth.exe, Pid: 8120, TotalTime: 196, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T18:25:23.521 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T18:25:23.521 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T18:25:23.521 ProcessImageName: TabTip.exe, Pid: 12952, TotalTime: 139, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 81% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T18:25:23.521 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 5988, TotalTime: 106, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 4% 2026-06-17T18:25:23.521 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: SDXHelper.exe, Pid: 5276, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T18:25:23.521 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T18:25:23.521 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T18:25:23.521 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T18:25:23.521 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T18:25:23.521 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T18:25:23.521 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 8936, TotalTime: 75, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1781684921, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: dasHost.exe, Pid: 5716, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 764, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\042DAB8CC792B670CFA0C1C9B65448D2C8F5D961, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T18:25:23.521 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T18:25:23.521 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T18:25:23.521 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\02_myWebseiten\0_Webseiten_offline\javascript_offline\www.javascript-kurs.de\bilder\javascript-use-strict-mode.jpg, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T18:25:23.521 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T18:25:23.521 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: SDXHelper.exe, Pid: 1480, TotalTime: 61, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7FE0CA44-35C7-4A07-B94C-63D6071D6BDD, EstimatedImpact: 6% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 5608, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 2% 2026-06-17T18:25:23.521 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T18:25:23.521 ProcessImageName: mysqld.exe, Pid: 7380, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T18:25:23.521 ProcessImageName: taskhostw.exe, Pid: 8144, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 22% 2026-06-17T18:25:23.521 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 4656, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1244.log->(UTF-16LE), EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 5868, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1915.log, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: sihost.exe, Pid: 8164, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: SDXHelper.exe, Pid: 8404, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-06-17T18:25:23.521 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1928.log, EstimatedImpact: 1% 2026-06-17T18:25:23.521 ProcessImageName: dllhost.exe, Pid: 3004, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 1552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1522.log, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T18:25:23.521 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 5576, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1933.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 5420, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1402.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 1228, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T18:25:23.521 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T18:32:39.934 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T18:47:44.934 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T19:02:49.948 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T19:17:54.948 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_Kernel_VetoCldFltRegSyncRoot hr=0x8007007b 2026-06-17T19:18:01.463 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T19:18:01.495 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-17T19:18:01.495 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-17T19:18:01.495 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-17T19:18:01.495 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T19:18:01.495 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T19:18:01.495 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T19:18:01.495 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T19:18:01.495 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T19:18:01.495 MdCoreSvc is supported in this platform and OS 2026-06-17T19:18:01.979 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-17T19:18:01.979 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-17T19:18:01.979 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T19:24:10.576 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #61070, FileId: 0x6600000000d128, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T19:32:59.947 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T19:48:04.947 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) BEGIN BM telemetry GUID:{1BC9075A-BD7A-2E8F-14FE-9D74969AFFB2} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:6440 ProcessCreationTime:134261664301467409 SessionID:2 CreationTime:06-17-2026 19:59:56 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-06-17T19:59:57.468 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-06-17T19:59:57.468 [Cloud] Start of cloud request. Passive mode: 0 2026-06-17T19:59:57.468 [Cloud] Queued cloud request. 2026-06-17T19:59:57.468 [Cloud] MpEngineCloudRequest(). hr = 0 2026-06-17T19:59:57.468 [Cloud] Dequeued cloud request. 2026-06-17T19:59:57.468 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-06-17T20:00:00.453 [Cloud] End of cloud request. 2026-06-17T20:00:00.968 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T20:03:09.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T20:18:14.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T20:25:23.531 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 37175, Count: 831, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T20:25:23.531 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T20:25:23.531 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T20:25:23.531 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T20:25:23.531 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T20:25:23.531 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T20:25:23.531 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 150, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 54, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T20:25:23.531 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T20:25:23.531 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T20:25:23.531 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T20:25:23.531 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2314, Count: 75, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: DeviceCensus.exe, Pid: 10208, TotalTime: 2232, Count: 6, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 39% 2026-06-17T20:25:23.531 ProcessImageName: setup.exe, Pid: 9352, TotalTime: 2130, Count: 351, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\Installer\msedge_7z.data, EstimatedImpact: 57% 2026-06-17T20:25:23.531 ProcessImageName: OneDriveUpdaterService.exe, Pid: 10092, TotalTime: 1920, Count: 5, MaxTime: 1875, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 10% 2026-06-17T20:25:23.531 ProcessImageName: xampp-control.exe, Pid: 11768, TotalTime: 1840, Count: 10, MaxTime: 1578, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 7% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 7228, TotalTime: 1830, Count: 24, MaxTime: 968, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveSetup.exe, EstimatedImpact: 28% 2026-06-17T20:25:23.531 ProcessImageName: MOM.exe, Pid: 13036, TotalTime: 1727, Count: 29, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 11488, TotalTime: 1474, Count: 124, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 27% 2026-06-17T20:25:23.531 ProcessImageName: AISuite3.exe, Pid: 3192, TotalTime: 1306, Count: 22, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 1444, TotalTime: 1217, Count: 79, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeClickToRun.exe, Pid: 10096, TotalTime: 1178, Count: 27, MaxTime: 468, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\vc_redist.x64.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: mysqld.exe, Pid: 7320, TotalTime: 1111, Count: 119, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 6% 2026-06-17T20:25:23.531 ProcessImageName: wevtutil.exe, Pid: 3284, TotalTime: 749, Count: 2, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 67% 2026-06-17T20:25:23.531 ProcessImageName: httpd.exe, Pid: 2948, TotalTime: 742, Count: 70, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\dashboard\javascripts\all.js, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: websockify.exe, Pid: 13056, TotalTime: 741, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 45% 2026-06-17T20:25:23.531 ProcessImageName: updater.exe, Pid: 7560, TotalTime: 717, Count: 45, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\browser\omni.ja->(SCRIPT0012), EstimatedImpact: 5% 2026-06-17T20:25:23.531 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 2388, TotalTime: 703, Count: 2, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: AddInUtil.exe, Pid: 10744, TotalTime: 665, Count: 14, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 62% 2026-06-17T20:25:23.531 ProcessImageName: Integrator.exe, Pid: 12036, TotalTime: 651, Count: 62, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: WmiPrvSE.exe, Pid: 1176, TotalTime: 571, Count: 15, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 79% 2026-06-17T20:25:23.531 ProcessImageName: wevtutil.exe, Pid: 11372, TotalTime: 530, Count: 2, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 84% 2026-06-17T20:25:23.531 ProcessImageName: SDXHelper.exe, Pid: 12196, TotalTime: 511, Count: 15, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\Mso30win32client.dll, EstimatedImpact: 15% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 7220, TotalTime: 465, Count: 45, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa03052, EstimatedImpact: 47% 2026-06-17T20:25:23.531 ProcessImageName: sdiagnhost.exe, Pid: 7788, TotalTime: 463, Count: 27, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Wad78daf4#\1df0430800a98aa6a2febe3699cc780d\Microsoft.Windows.Diagnosis.SDHost.ni.dll, EstimatedImpact: 17% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 11696, TotalTime: 450, Count: 94, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa10812, EstimatedImpact: 58% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 11140, TotalTime: 429, Count: 16, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\BIT1863.tmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: powershell.exe, Pid: 5152, TotalTime: 401, Count: 24, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 13% 2026-06-17T20:25:23.531 ProcessImageName: TeamViewer_Service.exe, Pid: 2012, TotalTime: 389, Count: 4, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 8% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 10096, TotalTime: 315, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 5% 2026-06-17T20:25:23.531 ProcessImageName: msiexec.exe, Pid: 992, TotalTime: 296, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\SingleClientServicesUpdater.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: FileCoAuth.exe, Pid: 12236, TotalTime: 289, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 7152, TotalTime: 285, Count: 100, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 21% 2026-06-17T20:25:23.531 ProcessImageName: WhatsApp.Root.exe, Pid: 10832, TotalTime: 285, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\5319275A.WhatsAppDesktop_cv1g1gvanyjgm\LocalState\sadRecord.dat, EstimatedImpact: 2% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 808, TotalTime: 279, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.084.0504.0007\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: FileCoAuth.exe, Pid: 7328, TotalTime: 274, Count: 15, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncSessions.dll, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: FileSyncConfig.exe, Pid: 6024, TotalTime: 273, Count: 20, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncFS.dll, EstimatedImpact: 72% 2026-06-17T20:25:23.531 ProcessImageName: AdobeCollabSync.exe, Pid: 1640, TotalTime: 256, Count: 26, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 980, TotalTime: 248, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 2532, TotalTime: 201, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: FileCoAuth.exe, Pid: 8120, TotalTime: 196, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\OneDriveTelemetryStable.dll, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 6520, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_886f9d61-19b0-4311-aa35-5803898cf213\result\results.xsl->(SCRIPT0000), EstimatedImpact: 57% 2026-06-17T20:25:23.531 ProcessImageName: armsvc.exe, Pid: 4232, TotalTime: 195, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: ngentask.exe, Pid: 13132, TotalTime: 180, Count: 20, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: RuntimeBroker.exe, Pid: 9364, TotalTime: 171, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 12924, TotalTime: 165, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1780496376->(UTF-16LE), EstimatedImpact: 12% 2026-06-17T20:25:23.531 ProcessImageName: , Pid: 4, TotalTime: 165, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\{33a4cc21-59b8-11f1-a18d-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: dllhost.exe, Pid: 6984, TotalTime: 150, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{ab83d9a4-643f-4b49-b1bc-61f7686b2700}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: ngentask.exe, Pid: 10544, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 1884, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{CDA0223D-823A-4A70-AB65-11053159377D}\EDGEMITMP_E15E5.tmp\setup.exe, EstimatedImpact: 68% 2026-06-17T20:25:23.531 ProcessImageName: TabTip.exe, Pid: 12952, TotalTime: 139, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 81% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 2156, TotalTime: 122, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\shsvcs.dll.mun, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 4172, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 55% 2026-06-17T20:25:23.531 ProcessImageName: dllhost.exe, Pid: 6104, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 2116, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, EstimatedImpact: 2% 2026-06-17T20:25:23.531 ProcessImageName: PhoneExperienceHost.exe, Pid: 12064, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: vc_redist.x64.exe, Pid: 8596, TotalTime: 120, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{8CDA23CD-6821-48C4-9E1A-CDEEEB0B7D5D}\.ba\wixstdba.dll, EstimatedImpact: 36% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 12876, TotalTime: 120, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Experiences\SubscribedContent\experience, EstimatedImpact: 13% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 5988, TotalTime: 106, Count: 14, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 4% 2026-06-17T20:25:23.531 ProcessImageName: OfficeClickToRun.exe, Pid: 12180, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: updater.exe, Pid: 6856, TotalTime: 106, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Mozilla Maintenance Service\UpdateLogs\308046B0AF4A39CB.id, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: SDXHelper.exe, Pid: 5276, TotalTime: 105, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\PowerPointCapabilities.json, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: vc_redist.x86.exe, Pid: 11568, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 44% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 2140, TotalTime: 93, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\BITEB8F.tmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 3512, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\OPushUtil.msix, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 2792, TotalTime: 91, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\msyh.ttc, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 10676, TotalTime: 91, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\ARM\Acrobat_26.001.21563\BIT96BF.tmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 13120, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280815\1780496461, EstimatedImpact: 13% 2026-06-17T20:25:23.531 ProcessImageName: httpd.exe, Pid: 6576, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\02_myWebseiten\0_Webseiten_offline\javascript_offline\www.javascript-kurs.de\bilder\javascript-use-strict-mode.jpg, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeClickToRun.exe, Pid: 8408, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CECA6B7B-EF2C-4C55-8F5D-32E039FB47CE, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: AcroCEF.exe, Pid: 8280, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 64% 2026-06-17T20:25:23.531 ProcessImageName: OpenWith.exe, Pid: 7928, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\seguisym.ttf, EstimatedImpact: 64% 2026-06-17T20:25:23.531 ProcessImageName: ngentask.exe, Pid: 10780, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log, EstimatedImpact: 16% 2026-06-17T20:25:23.531 ProcessImageName: ngentask.exe, Pid: 3700, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\CLR_v4.0\ngen.log, EstimatedImpact: 30% 2026-06-17T20:25:23.531 ProcessImageName: MicrosoftEdge_X64_149.0.4022.69_148.0.3967.96.exe, Pid: 7260, TotalTime: 78, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{3EA233EA-E9B7-49DE-A3D1-500468755B90}\EDGEMITMP_5B086.tmp\setup.exe, EstimatedImpact: 55% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 2556, TotalTime: 77, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-2124.log, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: AdobeARM.exe, Pid: 3360, TotalTime: 76, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 8936, TotalTime: 75, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1781684921, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: dasHost.exe, Pid: 5716, TotalTime: 75, Count: 18, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 764, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\042DAB8CC792B670CFA0C1C9B65448D2C8F5D961, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: RuntimeBroker.exe, Pid: 13284, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\79475d20-8b83-4b70-93e4-19014b52c3d7.down_data, EstimatedImpact: 16% 2026-06-17T20:25:23.531 ProcessImageName: SecurityHealthHost.exe, Pid: 5868, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 7% 2026-06-17T20:25:23.531 ProcessImageName: spoolsv.exe, Pid: 2296, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\prnms006.inf_amd64_c3bdcb6fc975b614\prnms006.PNF, EstimatedImpact: 32% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 7916, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8.cdpresource, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: Acrobat.exe, Pid: 10984, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 6208, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres, EstimatedImpact: 10% 2026-06-17T20:25:23.531 ProcessImageName: BackgroundTransferHost.exe, Pid: 5336, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fcd8c33-75e8-4379-87d0-131537062fba.up_meta_secure, EstimatedImpact: 30% 2026-06-17T20:25:23.531 ProcessImageName: pingsender.exe, Pid: 4340, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Pending Pings\9C3C3957-1406-46A1-85DB-A29F335988E5, EstimatedImpact: 34% 2026-06-17T20:25:23.531 ProcessImageName: OneDriveSetup.exe, Pid: 12988, TotalTime: 62, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileSyncConfig.exe, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: SDXHelper.exe, Pid: 1480, TotalTime: 61, Count: 16, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\7FE0CA44-35C7-4A07-B94C-63D6071D6BDD, EstimatedImpact: 6% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 5608, TotalTime: 61, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CD93C18B-2920-41C2-9EA4-D6929CCE3031, EstimatedImpact: 2% 2026-06-17T20:25:23.531 ProcessImageName: RuntimeBroker.exe, Pid: 9240, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Public\wsxpacks\Account\SettingsExtensions.json, EstimatedImpact: 8% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 8272, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: mysqld.exe, Pid: 7380, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql.pid, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: runonce.exe, Pid: 12696, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 11508, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1032.log, EstimatedImpact: 2% 2026-06-17T20:25:23.531 ProcessImageName: mysqld.exe, Pid: 2676, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 1072, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: wevtutil.exe, Pid: 12020, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\msoutilstat.etw.man, EstimatedImpact: 36% 2026-06-17T20:25:23.531 ProcessImageName: taskhostw.exe, Pid: 8144, TotalTime: 31, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\hidparse.sys, EstimatedImpact: 22% 2026-06-17T20:25:23.531 ProcessImageName: AdobeARM.exe, Pid: 13264, TotalTime: 30, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\RdrServicesUpdater2_x64.exe, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: firefox.exe, Pid: 8356, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\defaults\pref\channel-prefs.js, EstimatedImpact: 2% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 4656, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1244.log->(UTF-16LE), EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 5868, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1915.log, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: Acrobat.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: backgroundTaskHost.exe, Pid: 9860, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: SDXHelper.exe, Pid: 8404, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 4% 2026-06-17T20:25:23.531 ProcessImageName: sihost.exe, Pid: 8164, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MSTeams_26120.3106.4722.3411_x64__8wekyb3d8bbwe\msteams_autostarter.exe, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 6552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1928.log, EstimatedImpact: 1% 2026-06-17T20:25:23.531 ProcessImageName: MicrosoftEdgeUpdateComRegisterShell64.exe, Pid: 6428, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\1.3.241.13\psmachine_64.dll, EstimatedImpact: 8% 2026-06-17T20:25:23.531 ProcessImageName: AdobeARM.exe, Pid: 7416, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_5809FDAACC125718B26BC11DC8E8116A, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: dllhost.exe, Pid: 3004, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-423DD4D2.pf, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 1552, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1522.log, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 10992, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1044.log, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: helper.exe, Pid: 10080, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 3% 2026-06-17T20:25:23.531 ProcessImageName: RdrServicesUpdater2_x64.exe, Pid: 1800, TotalTime: 15, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\ChromeReprompt.txt->(UTF-16LE), EstimatedImpact: 7% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 5576, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1933.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: AcroCEF.exe, Pid: 8640, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json, EstimatedImpact: 13% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 5420, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260617-1402.log->(UTF-16LE), EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 1228, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: SingleClientServicesUpdater.exe, Pid: 11796, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\WebInstaller\JZJJGRJYXBHFEVOA.7z, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: WindowsPackageManagerServer.exe, Pid: 5540, TotalTime: 0, Count: 8, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.28.240.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: AdobeARM.exe, Pid: 11696, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemTemp\TmpEA93.tmp, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: OfficeC2RClient.exe, Pid: 11504, TotalTime: 0, Count: 5, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: AppHostRegistrationVerifier.exe, Pid: 4584, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\DUJMIIJA\windows-app-web-link[1], EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: brynhildr.exe, Pid: 4324, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-06-17T20:25:23.531 ProcessImageName: DismHost.exe, Pid: 792, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-06-17T20:26:51.937 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #61675, FileId: 0x2100000001b5dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T20:33:19.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T20:45:21.030 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\FEC4EA78-F7AA-4426-8F5D-6AC77A79875E1c74.1dcfe9a35e279bc 2026-06-17T20:45:21.202 Verifying engine and signature files (source: 0) ... 2026-06-17T20:45:21.202 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpengine.dll] due to PPL. 2026-06-17T20:45:21.202 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasbase.vdm] (file in cache) 2026-06-17T20:45:21.202 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasdlta.vdm]. File not in cache (0x1) 2026-06-17T20:45:21.218 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasdlta.vdm] 2026-06-17T20:45:21.218 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavbase.vdm] (file in cache) 2026-06-17T20:45:21.218 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavdlta.vdm]. File not in cache (0x1) 2026-06-17T20:45:21.234 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavdlta.vdm] 2026-06-17T20:45:21.390 [Engine] IsHybridMode: 0 2026-06-17T20:45:21.390 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-06-17T20:45:21.405 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-122B26C9A635A91FD0DAA3950C829E329C3D975A.bin): 0x00000002 2026-06-17T20:45:21.405 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-122B26C9A635A91FD0DAA3950C829E329C3D975A.bin) 2026-06-17T20:45:21.405 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-06-17T20:45:21.405 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-06-17T20:45:21.405 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-06-17T20:45:21.405 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-06-17T20:45:32.202 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-06-17T20:45:32.218 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_Kernel_VetoCldFltRegSyncRoot hr=0x8007007b IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-06-17T20:45:32.234 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF8465F84C0, lRefCount: 5, hr=0 2026-06-17T20:45:32.234 [Engine] New active engine 00007FF807E284C0 replacing engine 00007FF8465F84C0. Number of active engines: 2 2026-06-17T20:45:32.249 EngineInit:Global ASOC is enabled 2026-06-17T20:45:32.249 EngineInit:ASOO is enabled for developer volumes 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-06-17T20:45:32.312 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0685c867f9ba76f252524a2c04bc26182c2fae5b Dynamic Signature Compilation Timestamp:06-17-2026 08:26:57 Persistence Type:Duration Time remaining:288000000 2026-06-17T20:45:32.312 MpWriteUupSignatureVersion 1.453.138.0, hr = 0 2026-06-17T20:45:32.312 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-06-17T20:45:32.327 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-06-17T20:45:32.343 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-06-17T20:45:32.343 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-06-17T20:45:32.343 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-06-17T20:45:32.343 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-06-17T20:45:32.359 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-06-17T20:45:32.359 [Plugin] Initializing RTP plugin state... 2026-06-17T20:45:32.359 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎06‎-‎17‎-‎2026 10:25:26 Last Perf:‎06‎-‎17‎-‎2026 10:25:26 First RTP Scan:‎06‎-‎17‎-‎2026 10:25:26 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:10381 Misses:42010 BM Queue:0,506,0 Proc:0,273,0 File:0,330,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,1,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:62957 Pending:0 RegSize:308636 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:395528704 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:16 TotalStreamCon:32363 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:158205 TotalHits:484633 InstanceCacheInserts:11818 InstanceCacheUpdates:0 InstanceCacheDeletes:5407 InstanceCacheHits:4582 InstanceCacheMisses:77867 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:6ms (11064/1735) Success: 1735, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-06-17T20:45:32.359 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-06-17T20:45:32.359 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269} 2026-06-17T20:45:32.359 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{546A245F-EC19-4291-859E-F63A1C6944F5} removed 2026-06-17T20:45:32.359 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6}\mpasbase.vdm in use, hr=0x80070020 2026-06-17T20:45:32.359 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-06-17T20:45:32.359 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.359 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.359 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.359 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.359 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:06-17-2026 20:45:32 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:06-17-2026 20:45:32 2026-06-17T20:45:32.359 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-06-17T20:45:32.359 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-06-17T20:45:32.374 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-06-17T20:45:32.374 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T20:45:32.374 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-06-17T20:45:32.374 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.374 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f BmLoggingDisabled:MpDisableBmLogging not set. 2026-06-17T20:45:32.374 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.374 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-06-17T20:45:32.374 MdCoreSvc is supported in this platform and OS 2026-06-17T20:45:32.374 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 06-17-2026 20:45:32 Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26050.11 AS Signature Version: 1.453.138.0 AV Signature Version: 1.453.138.0 ************************************************************ 2026-06-17T20:45:32.374 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-06-17T20:45:32.374 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\FEC4EA78-F7AA-4426-8F5D-6AC77A79875E1c74.1dcfe9a35e279bc 2026-06-17T20:45:32.390 Process scan (postsignatureupdatescan) started. 2026-06-17T20:45:32.468 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-06-17T20:45:32.468 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-06-17T20:45:32.780 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-06-17T20:45:32.780 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-06-17T20:45:32.780 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-06-17T20:45:32.780 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-06-17T20:45:32.780 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-06-17T20:45:32.780 [Engine] Engine 00007FF8465F84C0 no longer in use. Number of active engines: 1 2026-06-17T20:45:32.780 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-06-17T20:45:32.780 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-06-17T20:45:32.827 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-06-17T20:45:32.827 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-06-17T20:45:32.843 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-06-17T20:45:33.062 ProcessImageName: explorer.exe, Pid: 3424, TotalTime: 37175, Count: 831, MaxTime: 4671, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-06-17T20:45:33.062 ProcessImageName: setup.exe, Pid: 5352, TotalTime: 9722, Count: 411, MaxTime: 4375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\149.0.4022.69\msedge.dll, EstimatedImpact: 16% 2026-06-17T20:45:33.062 ProcessImageName: AdobeARM.exe, Pid: 8120, TotalTime: 6950, Count: 37, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Adobe\ARM\Acrobat_26.001.21563\13820\AcroRdrDCx64Upd2600121662_incr.msp, EstimatedImpact: 6% 2026-06-17T20:45:33.062 ProcessImageName: Windows-KB890830-x64-V5.142.exe, Pid: 10212, TotalTime: 5171, Count: 2, MaxTime: 3421, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\MRT.exe, EstimatedImpact: 76% 2026-06-17T20:45:33.062 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 4552, Count: 78, MaxTime: 671, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\php8ts.dll, EstimatedImpact: 36% 2026-06-17T20:45:33.062 ProcessImageName: SrTasks.exe, Pid: 6840, TotalTime: 4200, Count: 678, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2, EstimatedImpact: 21% 2026-06-17T20:45:33.062 ProcessImageName: AcroCEF.exe, Pid: 11896, TotalTime: 4053, Count: 168, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-06-17T20:45:33.062 ProcessImageName: AggregatorHost.exe, Pid: 5796, TotalTime: 3842, Count: 150, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-06-17T20:45:33.062 ProcessImageName: svchost.exe, Pid: 4056, TotalTime: 3694, Count: 55, MaxTime: 2859, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO5E5E.tmp, EstimatedImpact: 0% 2026-06-17T20:45:33.062 ProcessImageName: helper.exe, Pid: 11528, TotalTime: 3657, Count: 85, MaxTime: 2046, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 81% 2026-06-17T20:45:33.062 ProcessImageName: AsPowerBar.exe, Pid: 12384, TotalTime: 2863, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 30% 2026-06-17T20:45:33.062 ProcessImageName: dllhost.exe, Pid: 10104, TotalTime: 2664, Count: 89, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\NCHJNR25YO_67, EstimatedImpact: 41% 2026-06-17T20:45:33.062 ProcessImageName: OfficeClickToRun.exe, Pid: 4440, TotalTime: 2658, Count: 134, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20026.20168\OfficeClickToRun.exe, EstimatedImpact: 1% 2026-06-17T20:45:33.062 ProcessImageName: Integrator.exe, Pid: 5072, TotalTime: 2629, Count: 243, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.de-de.xml->(UTF-16LE), EstimatedImpact: 8% 2026-06-17T20:45:33.062 ProcessImageName: DipAwayMode.exe, Pid: 3668, TotalTime: 2494, Count: 16, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 0% 2026-06-17T20:45:33.062 ProcessImageName: TeamViewer.exe, Pid: 6232, TotalTime: 2314, Count: 75, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 0% 2026-06-17T20:45:33.171 [Engine] RSIG_UNLOADENGINE, 00007FF8465F84C0, err=0x0 2026-06-17T20:45:33.202 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BC3EEA70-E371-47E7-A782-E1858848AFA6} removed 2026-06-17T20:45:34.390 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T20:45:34.405 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-06-17T20:45:34.405 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-06-17T20:45:36.734 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-06-17T20:45:51.968 Process scan (postsignatureupdatescan) completed. 2026-06-17T20:48:24.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T20:50:32.280 [RbM] Setting Last known good engine candidate. hr = 0 2026-06-17T21:03:29.937 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T21:18:34.936 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T21:33:39.936 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T21:48:44.936 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-06-17T21:54:39.920 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63823, FileId: 0x16e00000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.920 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63827, FileId: 0x9100000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.920 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63829, FileId: 0x9200000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.936 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63828, FileId: 0x17000000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.936 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63826, FileId: 0x16f00000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.936 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63830, FileId: 0x17100000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.936 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63834, FileId: 0x17300000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.952 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63836, FileId: 0x17400000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.952 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63837, FileId: 0x9600000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.952 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63832, FileId: 0x17200000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63840, FileId: 0x17600000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63841, FileId: 0x9800000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63844, FileId: 0x17800000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63845, FileId: 0x9a00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63835, FileId: 0x9500000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63843, FileId: 0x9900000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.967 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63846, FileId: 0x17900000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:39.983 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63842, FileId: 0x17700000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:40.342 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #63878, FileId: 0x17b00000000c0b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-06-17T21:54:40.358 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\13cefe48-4eb4-4d9e-a22f-53b88832b374. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #63880, FileId: 0xd60000000051c4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-16-2026 20:50:09 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/16/2026 20:50:09.274921700 UTC (17984 ms since boot) 2026-08-16T20:50:09.279 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-16T20:50:09.279 WARNING: the previous service shutdown was not expected. 2026-08-16T20:50:09.279 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-16T20:50:09.279 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-16T20:50:09.358 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260816-205009-00000003-fffffffeffffffff.bin ... 2026-08-16T20:50:09.483 [WPP] Trace session started - MpWppTracing-20260816-205009-00000003-fffffffeffffffff.bin 2026-08-16T20:50:09.498 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-16T20:50:09.498 [RbM] Rollback manager succesfully initialized. 2026-08-16T20:50:09.498 [RbM] Rollback manager EnableRollbackManager called. 2026-08-16T20:50:09.498 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-16T20:50:09.498 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 2026-08-16T20:50:09.498 MpWriteUupPlatformVersion 4.18.26050.15, hr = 0 2026-08-16T20:50:09.498 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-08-16T20:50:09.498 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-08-16T20:50:09.498 MdCoreSvc is supported in this platform and OS 2026-08-16T20:50:09.498 MdCoreSvc is supported in this platform and OS 2026-08-16T20:50:09.498 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-16T20:50:09.498 [PlatUpd] Starting MdCoreSvc service 2026-08-16T20:50:09.545 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0" 2026-08-16T20:50:13.686 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-16T20:50:13.686 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-08-16T20:50:13.686 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-16T20:50:13.686 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-16T20:50:13.686 [PlatUpd] CSP platform update started 2026-08-16T20:50:13.686 [PlatUpd] Defender MDM CSP platform update not required 2026-08-16T20:50:13.686 [PlatUpd] WMI/PS provider platform update started 2026-08-16T20:50:13.686 [PlatUpd] WMI/PS provider platform update not required 2026-08-16T20:50:13.686 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-16T20:50:13.686 MdCoreSvc is supported in this platform and OS 2026-08-16T20:50:13.686 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-16T20:50:13.686 [PlatUpd] Starting MdCoreSvc service 2026-08-16T20:50:13.686 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-16T20:50:13.701 [TS] Troubleshooting mode is not available! 2026-08-16T20:50:13.701 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-16T20:50:13.701 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-16T20:50:13.733 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-16T20:50:13.733 [Service] Enabling AutoLoggers ... 2026-08-16T20:50:13.733 [Service] Enabling AMSI registration ... 2026-08-16T20:50:13.733 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-16T20:50:13.748 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 41401 Number of invalid entries is 0 Number of inserts issued is 1595823 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6585 Number of lookups is 108881927 Number of lookup misses is 5235092 Number of fast lookup misses is 55479170 Number of false fast lookups is 5235087 Number of invalidations is 740564 Number of maintenance invalidations is 530887 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-16T20:50:13.748 Verifying license file... 2026-08-16T20:50:13.748 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll]. File not in cache (0x1) 2026-08-16T20:50:13.795 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll] 2026-08-16T20:50:13.811 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-16T20:50:13.811 Loaded module#0 MpComServer. 2026-08-16T20:50:13.811 Loaded module#1 StartupPolicies. 2026-08-16T20:50:13.811 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-16T20:50:13.815 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-16T20:50:13.815 COM server initialized successfully. 2026-08-16T20:50:13.846 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-16T20:50:13.858 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll ... 2026-08-16T20:50:13.858 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll] due to PPL. 2026-08-16T20:50:13.890 [RTP] [RTP] FilterCommunicator object 0x000001F2DC332C70 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-16T20:50:13.922 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-16T20:50:13.922 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-16T20:50:13.922 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-16T20:50:13.922 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-16T20:50:13.922 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-16T20:50:13.922 [RTP] [RTP] FilterCommunicator object 0x000001F2DC332E80 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-16T20:50:13.922 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-16T20:50:13.922 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-16T20:50:13.922 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-16T20:50:13.922 [RTP] [RTP] StartCommunication 0x000001F2DC332C70 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-16T20:50:13.922 [init][RTP] RTPPlugin initialization completed 2026-08-16T20:50:13.922 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mpnirtp.dll does not exist. 2026-08-16T20:50:13.922 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-16T20:50:13.922 OS boot count = 2 2026-08-16T20:50:13.922 OS Install = 0 2026-08-16T20:50:13.985 [ManagedAgent] HooksInitialize: starting 2026-08-16T20:50:13.985 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-16T20:50:13.985 [ManagedAgent] HooksInitialize: complete 2026-08-16T20:50:14.002 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-08-16T20:50:14.017 [KSL] Entering CKSLEngine::Initialize. 2026-08-16T20:50:14.017 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-16T20:50:14.017 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-16T20:50:14.034 [KSL] MpInstallKslD: hr=0x1 2026-08-16T20:50:14.034 [KSL] MpRegisterKslD: hr=0 2026-08-16T20:50:14.034 [KSL] MpStartKslD: hr=0 2026-08-16T20:50:14.034 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-16T20:50:14.034 Loading engine... 2026-08-16T20:50:14.065 Verifying engine and signature files (source: 1) ... 2026-08-16T20:50:14.065 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpengine.dll] due to PPL. 2026-08-16T20:50:14.065 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasbase.vdm]. File not in cache (0x1) 2026-08-16T20:50:15.439 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasbase.vdm] 2026-08-16T20:50:15.439 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-16T20:50:15.455 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasdlta.vdm] 2026-08-16T20:50:15.455 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavbase.vdm]. File not in cache (0x1) 2026-08-16T20:50:15.939 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavbase.vdm] 2026-08-16T20:50:15.939 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-16T20:50:15.955 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpavdlta.vdm] 2026-08-16T20:50:16.018 [Engine] IsHybridMode: 0 2026-08-16T20:50:16.018 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-16T20:50:16.049 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-122B26C9A635A91FD0DAA3950C829E329C3D975A.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-16T20:50:24.596 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-16T20:50:24.596 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_Kernel_VetoCldFltRegSyncRoot hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnection hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnectionThrottle hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNriRiskIQDetect hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorTcp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorUdp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFc_Kernel_DoNotResetExcludeOnModify hr=0x8007007b IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_SupportedSettings new=3 old1 IDynamicConfig::ReportChange ECS value=MpFC_SCC_VerifyPayloadSignature new=4294967279 old4294967295 IDynamicConfig::ReportChange ECS value=MpFC_NISDrv_Cleanup new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_FeatureAvailable new=1 old4294967295 IDynamicConfig::ReportChange ECS value=MpFC_NisSrv_QueryConnectionVolume new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_AcceptedSources new=3 old1 IDynamicConfig::ReportChange ECS value=MpFC_Dlp_Reclassify_Enable new=3 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_DC_AvailableOnServer new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_Dlp_OnDemandUserConfigFetchEnabled new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-16T20:50:24.596 [Engine] New active engine 00007FF8D01084C0 (no old engine). Number of active engines: 1 2026-08-16T20:50:24.627 EngineInit:Global ASOC is enabled 2026-08-16T20:50:24.627 EngineInit:ASOO is enabled for developer volumes 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:50:24.783 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a94246ff920554b666d1236e7365ba472f72a0ff Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b82f7af4a05ad7089859330013f38a80d986f1cc Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f62a590a52507ff3c756b9f7b22623b4a8012559 Dynamic Signature Compilation Timestamp:06-17-2026 08:24:55 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d02b42d69714adab274eabf9bc15d979fb815bc8 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:53 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:50:24.799 Dynamic signature dropped 2026-08-16T20:50:24.799 Dynamic signature dropped 2026-08-16T20:50:24.799 Dynamic signature dropped 2026-08-16T20:50:24.799 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\325bf51f096b740b55b00a6d1ebe0b34001385e0 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:54 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7c6a32f4247ee4b30c5140cc7fcd1e2713191ad8 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:54 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8373dbb68197a4792de8390535aca663b776f30f Dynamic Signature Compilation Timestamp:06-17-2026 08:26:55 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c948f66e9cef90e09fe7648e0f0c9aebd069fe6e Dynamic Signature Compilation Timestamp:06-17-2026 08:26:56 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\94d6033d4710f704422cd4e8b6220399013ff73f Dynamic Signature Compilation Timestamp:06-17-2026 08:26:57 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ade69a5fb3b661fe6e30afc32a9574585f4b91ca Dynamic Signature Compilation Timestamp:06-17-2026 08:26:58 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a4488878040cda951352028580d98b2848f8c16d Dynamic Signature Compilation Timestamp:06-17-2026 08:26:58 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2bd2582f072fc17eb3b98ec8247605a0d8d1f338 Dynamic Signature Compilation Timestamp:06-17-2026 08:26:59 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1a476a63232e4e08d8a88316e444d87f168d6091 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:00 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ce03e99622f021757998db6cfd38b9cf8b252f0d Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd7854045a9c30258cb08df94b072c0add9546b7 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\48648f2cbde2c433eafc0c17218c2d4ef849f387 Dynamic Signature Compilation Timestamp:06-17-2026 08:27:01 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:50:24.830 MpWriteUupSignatureVersion 1.453.138.0, hr = 0 2026-08-16T20:50:24.830 [SigStatUpd] CSignatureStatus: Changed to DUE_TRY_1 2026-08-16T20:50:24.830 [SigStatUpd] CSignatureStatus: Triggering signature update... 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.830 Dynamic signature dropped 2026-08-16T20:50:24.877 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-16T20:50:24.877 [SigStatUpd] CSignatureStatus: Signature update triggered! 2026-08-16T20:50:24.877 [SigStatUpd] CSignatureStatus: UpdateWaitTimer #1 scheduled 2026-08-16T20:50:24.877 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-16T20:50:24.908 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-16T20:50:24.908 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-16T20:50:24.908 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-16T20:50:24.955 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-16T20:50:25.064 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-16T20:50:25.064 [Plugin] Initializing RTP plugin state... 2026-08-16T20:50:25.064 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-16T20:50:25.064 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2758 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3157 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:16760 TotalHits:0 InstanceCacheInserts:33 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3492 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-16T20:50:25.064 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269} 2026-08-16T20:50:25.064 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:50:25.064 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:50:25.064 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:50:25.064 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-16T20:50:25.064 MdCoreSvc is supported in this platform and OS 2026-08-16T20:50:25.064 Engine loaded! 2026-08-16T20:50:25.064 [DLP] Create FeatureControlState instance 2026-08-16T20:50:25.080 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-16T20:50:25.080 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-16T20:50:25.080 RegisterSModeChangeListener: hr = 0x1 2026-08-16T20:50:25.080 RegisterHybridModeChangeListener: hr = 0 2026-08-16T20:50:25.111 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:10328] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10348]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T20:50:25.111 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-16T20:50:25.111 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-16T20:50:25.111 [SigReleaseHb] Initialized with Stage 0 2026-08-16T20:50:25.111 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-16T20:50:25.111 [SCC][CID=33828_5420] Initializing ... 2026-08-16T20:50:25.111 [SCC][CID=33828_5420] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-16T20:50:25.111 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-16T20:50:25.111 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-16T20:50:25.127 [NRI] Stopping NIS service ... 2026-08-16T20:50:25.143 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-16T20:50:25.143 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26050.11 AS Signature Version: 1.453.138.0 AV Signature Version: 1.453.138.0 ************************************************************ 2026-08-16T20:50:25.143 Resource usage Monitoring is enabled 2026-08-16T20:50:25.143 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-16T20:50:25.158 Job Notification: New process added to job (4668) 2026-08-16T20:50:25.158 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-08-16T20:50:25.190 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:10412] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10428]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T20:50:25.361 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-16T20:50:25.361 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-16T20:50:25.361 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-16T20:50:25.361 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-16T20:50:25.361 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-16T20:50:25.361 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-16T20:50:25.361 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-16T20:50:25.361 [RTP] Generating the base plugin configuration ... 2026-08-16T20:50:25.361 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-16T20:50:25.361 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T20:50:25.361 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-16T20:50:25.361 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-16T20:50:25.361 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T20:50:25.361 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-16T20:50:25.393 [RTP] [RTP] StartCommunication 0x000001F2DC332E80 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-16T20:50:25.424 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-16T20:50:25.502 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-16T20:50:25.502 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-16T20:50:25.502 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-16T20:50:25.533 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe 2026-08-16T20:50:25.799 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:25.986 [PlatUpd] WMI MOF schema validation completed successfully 2026-08-16T20:50:26.924 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-16T20:50:28.096 Job Notification: New process added to job (10852) 2026-08-16T20:50:28.096 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-16T20:50:28.190 Job Notification: New process added to job (10872) 2026-08-16T20:50:28.266 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:10852] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10872]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T20:50:28.971 [RTP] Duplicating the current plugin configuration object... 2026-08-16T20:50:28.971 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T20:50:28.971 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-08-16T20:50:28.971 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-16T20:50:28.971 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-08-16T20:50:32.596 Bm signature throttled:0x00002db31bed458f 2026-08-16T20:50:35.971 [AutoPurge] Cleanup Routine tasks have started. 2026-08-16T20:50:35.971 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-08-16T20:50:35.971 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-08-16T20:50:35.971 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:08-16-2026 20:50:35 2026-08-16T20:50:36.002 [AutoPurge] Verification Routine tasks have started. 2026-08-16T20:50:36.002 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-16-2026 20:50:36ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-16T20:50:36.018 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-08-16T20:50:36.018 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-08-16T20:50:36.018 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-08-16T20:50:36.018 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-08-16T20:50:36.018 [AutoPurge] Cleanup Routine tasks have ended. 2026-08-16T20:50:36.346 EnsureProtectedFolderAcls(), hr = 0x0 2026-08-16T20:50:36.361 [AutoPurge] MpReinforceServiceAcls: 0 2026-08-16T20:50:36.393 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-08-16T20:50:36.908 Task(GetDeviceTicket -AccessKey 6470778A-2641-83F9-6A88-2FD4289F9C2A ) launched as network service 2026-08-16T20:50:36.924 Job Notification: New process added to job (9224) 2026-08-16T20:50:37.627 Job Notification: Process exited from job (9224) 2026-08-16T20:50:38.158 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 2 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 4096 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 4 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 8 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 16 2026-08-16T20:50:38.174 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-16T20:50:38.189 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:38.189 [RTP] [RtpConfig] Config change detected, type: 2048 2026-08-16T20:50:38.189 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-16T20:50:38.189 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:38.189 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 2 (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-16T20:50:38.189 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-16T20:50:38.189 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-16T20:50:38.189 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-16T20:50:38.189 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-16T20:50:38.189 [RTP] [RtpConfig] Config change detected, type: 64 2026-08-16T20:50:38.189 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:38.205 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:38.205 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:39.049 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-08-16T20:50:39.049 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:50:39.049 [Cloud] Queued cloud request. 2026-08-16T20:50:39.049 [Cloud] Dequeued cloud request. 2026-08-16T20:50:39.049 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:50:39.064 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-08-16T20:50:39.064 [AutoPurge] Verification Routine tasks have ended. 2026-08-16T20:50:39.268 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-16T20:50:39.268 [Cloud] End of cloud request. 2026-08-16T20:50:39.549 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:50:40.768 [RTP] Duplicating the current plugin configuration object... 2026-08-16T20:50:40.768 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T20:50:40.768 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-08-16T20:50:40.768 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T20:50:40.768 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-16T20:50:40.768 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-08-16T20:50:55.788 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.095.0519.0003\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #2657, FileId: 0x1c0000000393f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:51:13.815 Process scan (poststartupscan) started. 2026-08-16T20:51:13.815 Process scan (poststartupscan) completed. Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x43d5426f 2026-08-16T20:51:27.532 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-08-16T20:51:27.532 [RTP] Duplicating the current plugin configuration object... 2026-08-16T20:51:27.532 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T20:51:27.532 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-16T20:51:27.532 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-16T20:51:27.534 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-16T20:51:27.543 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x35abdb83 2026-08-16T20:51:27.630 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:51:27.630 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:51:27.630 [Cloud] Queued cloud request. 2026-08-16T20:51:27.630 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:51:27.630 [Cloud] Dequeued cloud request. 2026-08-16T20:51:27.631 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf97ff7bf 2026-08-16T20:51:27.681 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:51:27.681 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:51:27.681 [Cloud] Queued cloud request. 2026-08-16T20:51:27.681 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:51:27.681 [Cloud] Dequeued cloud request. 2026-08-16T20:51:27.681 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a8a42c4af8686c5f54e87315f4b28ef956d223f8 Dynamic Signature Compilation Timestamp:08-16-2026 20:51:15 Persistence Type:Duration Time remaining:150196224 2026-08-16T20:51:28.082 RTSD:RTSD recieved, rescanning impacted resources 2026-08-16T20:51:28.091 [Cloud] End of cloud request. 2026-08-16T20:51:28.102 Dynamic signature received 2026-08-16T20:51:28.143 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c18cad2e6f16f81cf458eeed368ff4ff663bc952 Dynamic Signature Compilation Timestamp:08-16-2026 20:51:15 Persistence Type:Duration Time remaining:150196224 2026-08-16T20:51:28.143 [Cloud] End of cloud request. 2026-08-16T20:51:28.144 RTSD:RTSD recieved, rescanning impacted resources 2026-08-16T20:51:28.626 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:51:32.733 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-16T20:51:33.221 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-16T20:51:58.549 ReportLowfi(c:\program files\microsoft onedrive\update\onedrivesetup.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0xd04a1fea 2026-08-16T20:52:04.486 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\logs\Common\telemetryCache.otc-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.139.0720.0007\FileCoAuth.exe, Status: 0xc0000001, State: 0, ScanRequest #5255, FileId: 0x1a000000009620, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x820, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:52:06.533 ExpensiveFile:Scan time for `\\?\c:\program files\microsoft onedrive\update\onedrivesetup.exe` is 6781 units 2026-08-16T20:52:11.955 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T20:52:11.955 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T20:52:11.955 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) BEGIN BM telemetry GUID:{35FDA1E8-75DE-FC37-2E2B-9E1C0D327C43} SignatureID:66739850906303 SigSha:27f2bd265fd12d929dacd7650d7a8faffb59aae8 ThreatLevel:0 ProcessID:14016 ProcessCreationTime:134313871554362375 SessionID:0 CreationTime:08-16-2026 20:52:38 ImagePath:C:\Program Files\TeamViewer\Update\update.exe Taint Info:Friendly: N; Reason: ; Modules: C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\System.dll:25,C:\Windows\Temp\nss82C4.tmp\UserInfo.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\UAC.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\UserInfo.dll:25,C:\Windows\Temp\nss82C4.tmp\UAC.dll:25,C:\Windows\Temp\nss82C4.tmp\UserInfo.dll:25,C:\Windows\Temp\nss82C4.tmp\UAC.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\TvGetVersion.dll:25,C:\Windows\Temp\nss82C4.tmp\nsExec.dll:25,; Parents: C:\Program Files\TeamViewer\TeamViewer_Service.exe:4640:3,C:\Windows\System32\csrss.exe:600:2, Operations:None END BM telemetry 2026-08-16T20:52:44.475 ExpensiveFile:Scan time for `\\?\C:\Program Files\TeamViewer\Update\update.exe` is 5093 units 2026-08-16T20:52:51.011 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:52:51.011 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:52:51.011 [Cloud] Queued cloud request. 2026-08-16T20:52:51.011 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:52:51.011 [Cloud] Dequeued cloud request. 2026-08-16T20:52:51.011 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:52:51.313 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7f16d289ab07426902f796741ce7930ca86d9d1f Dynamic Signature Compilation Timestamp:08-16-2026 20:52:38 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae4b758fe6686f10f8f709e2aab9f39266874851 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:38 Persistence Type:Duration Time remaining:150196224 2026-08-16T20:52:51.329 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4c92dfed38388cf9dd4b58ab0ace762825566a01 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:38 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:52:51.329 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\83f1e871993fd817ad7862b1962e161bde8d9679 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:38 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:52:51.329 Dynamic signature received 2026-08-16T20:52:51.329 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2e10080df0c3712e0558bb967a7c2b4053bba540 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:38 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:52:51.329 [Cloud] End of cloud request. 2026-08-16T20:52:51.579 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-08-16T20:52:51.579 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:52:51.579 [Cloud] Queued cloud request. 2026-08-16T20:52:51.579 [Cloud] Dequeued cloud request. 2026-08-16T20:52:51.579 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dc2d0cfbde14fb3ef4c09f9e6a808566654d4b3d Dynamic Signature Compilation Timestamp:08-16-2026 20:52:39 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\416a6be27f783111305991999206e40b940e9768 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:39 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c9b2440fdf02aff6eba34a961c5961d424bbb813 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:39 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4408ea7e2ad6c7e9a227012bd926250a66c4ce26 Dynamic Signature Compilation Timestamp:08-16-2026 20:52:39 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:52:51.704 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-16T20:52:51.704 [Cloud] End of cloud request. 2026-08-16T20:52:51.704 Dynamic signature received 2026-08-16T20:52:51.704 Dynamic signature received 2026-08-16T20:52:51.704 Dynamic signature received 2026-08-16T20:52:51.704 Dynamic signature received 2026-08-16T20:52:51.829 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:52:57.418 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\CB7D5E13-E0BF-4E60-A2C8-66D323A88F333754.1dd2dc12e3d8fc0 2026-08-16T20:52:59.639 Verifying engine and signature files (source: 0) ... 2026-08-16T20:52:59.639 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpengine.dll] due to PPL. 2026-08-16T20:52:59.639 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasbase.vdm]. File not in cache (0x1) 2026-08-16T20:53:00.533 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasbase.vdm] 2026-08-16T20:53:00.533 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-16T20:53:00.549 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasdlta.vdm] 2026-08-16T20:53:00.549 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavbase.vdm]. File not in cache (0x1) 2026-08-16T20:53:00.940 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavbase.vdm] 2026-08-16T20:53:00.940 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-16T20:53:00.955 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavdlta.vdm] 2026-08-16T20:53:01.143 [Engine] IsHybridMode: 0 2026-08-16T20:53:01.143 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-16T20:53:01.143 Current mpengine.dll version(1.1.26070.7) is newer than mpengine_etw.dll version(1.1.26050.11). Updating C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll ... 2026-08-16T20:53:01.158 C:\ProgramData\Microsoft\Windows Defender\Definition Updates\StableEngineEtwLocation\mpengine_etw.dll updated. 2026-08-16T20:53:01.580 Job Notification: New process added to job (8680) 2026-08-16T20:53:01.580 Job Notification: New process added to job (3204) 2026-08-16T20:53:02.205 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-16T20:53:02.236 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-16T20:53:02.252 Job Notification: Process exited from job (8680) 2026-08-16T20:53:02.252 Job Notification: Process exited from job (3204) 2026-08-16T20:53:02.252 Job Notification: New process added to job (12156) 2026-08-16T20:53:02.268 Job Notification: New process added to job (6512) 2026-08-16T20:53:03.580 Job Notification: Process exited from job (12156) 2026-08-16T20:53:03.580 Job Notification: Process exited from job (6512) 2026-08-16T20:53:03.580 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A2AA6B92914AB6DF8D99138A3D735D61A67B0FEF.bin): 0x00000002 2026-08-16T20:53:03.596 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A2AA6B92914AB6DF8D99138A3D735D61A67B0FEF.bin) 2026-08-16T20:53:03.596 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-16T20:53:03.596 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-16T20:53:03.596 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-16T20:53:03.596 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-08-16T20:53:04.080 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-16T20:53:04.096 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-16T20:53:04.814 [RTP] Duplicating the current plugin configuration object... 2026-08-16T20:53:04.814 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T20:53:04.814 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-08-16T20:53:04.814 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-16T20:53:04.814 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-08-16T20:53:12.611 Engine:Process C:\Windows\System32\svchost.exe (PPID:4360:134313870084511140) is tainted: TaintType:0x4. TaintReason:C:\Program Files\TeamViewer\TeamViewer_Service.exe, EnableCfa:1 2026-08-16T20:53:13.502 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-16T20:53:14.439 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-16T20:53:17.350 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-16T20:53:17.350 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_Kernel_VetoCldFltRegSyncRoot hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnection hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnectionThrottle hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNriRiskIQDetect hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorTcp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorUdp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFc_Kernel_DoNotResetExcludeOnModify hr=0x8007007b IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-16T20:53:17.350 Engine upgrade detected 0x1000165c2000b. Saving old engine files to last known good engine files ... 2026-08-16T20:53:17.366 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF8D01084C0, lRefCount: 5, hr=0 2026-08-16T20:53:17.366 [Engine] New active engine 00007FF8959C55E0 replacing engine 00007FF8D01084C0. Number of active engines: 2 2026-08-16T20:53:17.382 EngineInit:Global ASOC is enabled 2026-08-16T20:53:17.382 EngineInit:ASOO is enabled for developer volumes 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-16T20:53:17.475 MpWriteUupSignatureVersion 1.457.196.0, hr = 0 2026-08-16T20:53:17.475 [SigStatUpd] CSignatureStatus: back to good 2026-08-16T20:53:17.475 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-16T20:53:17.507 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-16T20:53:17.507 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-16T20:53:17.507 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-16T20:53:17.507 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-16T20:53:17.507 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-16T20:53:17.538 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-16T20:53:17.538 [Plugin] Initializing RTP plugin state... 2026-08-16T20:53:17.538 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎16‎-‎2026 22:50:25 Last Perf:‎08‎-‎16‎-‎2026 22:50:25 First RTP Scan:‎08‎-‎16‎-‎2026 22:50:25 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2233 Misses:3545 BM Queue:0,340,0 Proc:0,132,0 File:0,208,0 Plugin Queue:0,1,0 Threat:0,0,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:6763 Pending:0 RegSize:308636 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:17253654 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:9417 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:29294 TotalHits:16007 InstanceCacheInserts:484 InstanceCacheUpdates:0 InstanceCacheDeletes:359 InstanceCacheHits:6 InstanceCacheMisses:14550 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (535/172) Success: 172, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-16T20:53:17.538 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-16T20:53:17.538 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8} 2026-08-16T20:53:17.538 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269}\mpasbase.vdm in use, hr=0x80070020 2026-08-16T20:53:17.538 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-16T20:53:17.554 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T20:53:17.554 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-16T20:53:17.569 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{82C51205-ECD9-4599-A465-60DB4CC38C77} removed 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-16-2026 20:53:17 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-16-2026 20:53:17 2026-08-16T20:53:17.585 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-16T20:53:17.585 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-16T20:53:17.585 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-16T20:53:17.585 MdCoreSvc is supported in this platform and OS 2026-08-16T20:53:17.585 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-16-2026 20:53:17 Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.196.0 AV Signature Version: 1.457.196.0 ************************************************************ 2026-08-16T20:53:17.585 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-16T20:53:17.585 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\CB7D5E13-E0BF-4E60-A2C8-66D323A88F333754.1dd2dc12e3d8fc0 2026-08-16T20:53:17.647 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-16T20:53:17.647 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 08-16-2026 20:53:17 ************************************************************ 2026-08-16T20:53:17.772 Job Notification: Process exited from job (10852) 2026-08-16T20:53:17.772 Job Notification: Process exited from job (10872) 2026-08-16T20:53:17.975 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-16T20:53:17.975 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-16T20:53:17.975 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-16T20:53:17.991 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:17.991 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.007 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.022 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-16T20:53:18.038 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-16T20:53:18.038 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-16T20:53:18.038 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-16T20:53:18.038 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 [Engine] Engine 00007FF8D01084C0 no longer in use. Number of active engines: 1 2026-08-16T20:53:18.038 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T20:53:18.038 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.038 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-16T20:53:18.038 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 3992 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 9128 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 6472 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer_Service.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Program Files\TeamViewer\TeamViewer_Service.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\services.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\services.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\lsass.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\lsass.exe 2026-08-16T20:53:18.054 Engine:Process 14032 will be fully monitored because of injection from C:\Windows\System32\csrss.exe 2026-08-16T20:53:18.163 ProcessImageName: explorer.exe, Pid: 8768, TotalTime: 24969, Count: 238, MaxTime: 4984, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 19% 2026-08-16T20:53:18.163 ProcessImageName: update.exe, Pid: 14016, TotalTime: 6216, Count: 452, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\nss82C4.tmp\TvUpdateInfo.exe, EstimatedImpact: 16% 2026-08-16T20:53:18.163 ProcessImageName: wuauclt.exe, Pid: 3616, TotalTime: 3217, Count: 3, MaxTime: 3062, MaxTimeFile: \Device\HarddiskVolume3\Windows\SoftwareDistribution\Download\Install\AM_Base.exe, EstimatedImpact: 26% 2026-08-16T20:53:18.163 ProcessImageName: dllhost.exe, Pid: 11588, TotalTime: 3022, Count: 95, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\7CFM660V_509\A3ODPCC64C_84, EstimatedImpact: 45% 2026-08-16T20:53:18.163 ProcessImageName: AsPowerBar.exe, Pid: 7780, TotalTime: 2662, Count: 18, MaxTime: 1156, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 18% 2026-08-16T20:53:18.163 ProcessImageName: OneDriveUpdaterService.exe, Pid: 13404, TotalTime: 2216, Count: 5, MaxTime: 2171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe, EstimatedImpact: 9% 2026-08-16T20:53:18.163 ProcessImageName: MOM.exe, Pid: 13896, TotalTime: 1915, Count: 29, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 77% 2026-08-16T20:53:18.163 ProcessImageName: DipAwayMode.exe, Pid: 8356, TotalTime: 1832, Count: 32, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 26% 2026-08-16T20:53:18.163 ProcessImageName: AISuite3.exe, Pid: 8388, TotalTime: 1444, Count: 24, MaxTime: 578, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsMultiLang.dll, EstimatedImpact: 3% 2026-08-16T20:53:18.163 ProcessImageName: TeamViewer.exe, Pid: 6068, TotalTime: 1387, Count: 56, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\sciter.dll, EstimatedImpact: 29% 2026-08-16T20:53:18.163 ProcessImageName: TeamViewer_Service.exe, Pid: 4640, TotalTime: 1042, Count: 11, MaxTime: 484, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\Update\update.exe, EstimatedImpact: 7% 2026-08-16T20:53:18.163 ProcessImageName: websockify.exe, Pid: 13920, TotalTime: 727, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 63% 2026-08-16T20:53:18.163 ProcessImageName: WmiPrvSE.exe, Pid: 2776, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\monitor.inf, EstimatedImpact: 28% 2026-08-16T20:53:18.163 ProcessImageName: tv_x64.exe, Pid: 12088, TotalTime: 422, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\setupapi.dev.log, EstimatedImpact: 43% 2026-08-16T20:53:18.163 ProcessImageName: TeamViewer_Service.exe, Pid: 10608, TotalTime: 399, Count: 19, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\tv_w32.exe, EstimatedImpact: 11% 2026-08-16T20:53:18.210 [Engine] RSIG_UNLOADENGINE, 00007FF8D01084C0, err=0x0 2026-08-16T20:53:18.225 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{118688B2-ED06-4DE3-8932-3681E93B9269} removed 2026-08-16T20:53:19.585 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T20:53:19.596 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T20:53:19.596 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000157E1C80F859, sigsha=b4ad2eef9f25d86956089e5c7b86270317c9c842, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157EFA01FE66, sigsha=c7bd4195fd413c7bc1c606121f911477cbb71c8d, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E77F5387C, sigsha=a9faa5787c6e90b490871e267dfecd90fdc7e87f, cached=false, source=2, resourceid=0xd599fb49 Internal signature match:subtype=Lowfi, sigseq=0x0000157E2CFBB9EF, sigsha=add67a9722cd91fa4584b3ecab77ce42aa2cac55, cached=false, source=2, resourceid=0xd599fb49 2026-08-16T20:53:52.377 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #6796, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x211f41cf 2026-08-16T20:53:59.705 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:53:59.705 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:53:59.705 [Cloud] Queued cloud request. 2026-08-16T20:53:59.705 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:53:59.705 [Cloud] Dequeued cloud request. 2026-08-16T20:53:59.705 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3ea616d492226243db40c0244e159542f266e50f Dynamic Signature Compilation Timestamp:08-16-2026 20:53:47 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:00.049 [Cloud] End of cloud request. 2026-08-16T20:54:00.049 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 2026-08-16T20:54:00.205 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7133769a 2026-08-16T20:54:00.330 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:00.330 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:00.330 [Cloud] Queued cloud request. 2026-08-16T20:54:00.330 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:00.330 [Cloud] Dequeued cloud request. 2026-08-16T20:54:00.330 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:00.471 Dynamic signature received 2026-08-16T20:54:10.335 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\php\php8apache2_4.dll. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-16T20:54:10.429 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a883020 2026-08-16T20:54:10.570 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:10.570 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:10.570 [Cloud] Queued cloud request. 2026-08-16T20:54:10.570 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:10.570 [Cloud] Dequeued cloud request. 2026-08-16T20:54:10.570 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:10.761 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eb71f79b33054275dfabe3143c86ed1b4b8fc564 Dynamic Signature Compilation Timestamp:08-16-2026 20:53:58 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:10.777 [Cloud] End of cloud request. 2026-08-16T20:54:10.777 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7ccbb36f 2026-08-16T20:54:10.856 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:10.856 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:10.856 [Cloud] Queued cloud request. 2026-08-16T20:54:10.856 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:10.856 [Cloud] Dequeued cloud request. 2026-08-16T20:54:10.856 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:10.940 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:54:11.352 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f57ae74cc83e01551fdf37bc2af4b3044603752f Dynamic Signature Compilation Timestamp:08-16-2026 20:53:58 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:11.352 [Cloud] End of cloud request. 2026-08-16T20:54:11.352 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3dc12e4b 2026-08-16T20:54:11.602 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:11.602 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:11.602 [Cloud] Queued cloud request. 2026-08-16T20:54:11.602 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:11.602 [Cloud] Dequeued cloud request. 2026-08-16T20:54:11.602 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:11.821 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7545e8dc111430f42fb08e8e4e1357b4f393be59 Dynamic Signature Compilation Timestamp:08-16-2026 20:53:59 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:11.821 [Cloud] End of cloud request. 2026-08-16T20:54:11.821 RTSD:RTSD recieved, rescanning impacted resources 2026-08-16T20:54:11.867 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-08-16T20:54:12.073 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:12.073 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:12.073 [Cloud] Queued cloud request. 2026-08-16T20:54:12.073 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:12.073 [Cloud] Dequeued cloud request. 2026-08-16T20:54:12.073 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:12.530 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7949c82c0e01739604049af47f614d66894b9a7f Dynamic Signature Compilation Timestamp:08-16-2026 20:53:59 Persistence Type:Duration Time remaining:288000000 2026-08-16T20:54:12.530 [Cloud] End of cloud request. 2026-08-16T20:54:12.530 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c25bb8 2026-08-16T20:54:12.608 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:12.608 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:12.608 [Cloud] Queued cloud request. 2026-08-16T20:54:12.608 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:12.608 [Cloud] Dequeued cloud request. 2026-08-16T20:54:12.608 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:12.826 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c1bc1b332c0e5d2bdf34060ede44edb165502984 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:00 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:12.826 [Cloud] End of cloud request. 2026-08-16T20:54:12.826 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6ab8889 2026-08-16T20:54:12.936 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:12.936 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:12.952 [Cloud] Queued cloud request. 2026-08-16T20:54:12.952 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:12.952 [Cloud] Dequeued cloud request. 2026-08-16T20:54:12.952 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:13.045 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:54:13.139 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e222220dd42d0e2ffc8a0673bcf3c40d6cbd6b19 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:00 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:13.139 [Cloud] End of cloud request. 2026-08-16T20:54:13.155 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf20873eb 2026-08-16T20:54:13.202 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:13.202 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:13.202 [Cloud] Queued cloud request. 2026-08-16T20:54:13.202 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:13.202 [Cloud] Dequeued cloud request. 2026-08-16T20:54:13.202 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:13.389 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\51941555482b6c6515494d2601584829aad8c90b Dynamic Signature Compilation Timestamp:08-16-2026 20:54:00 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:13.389 [Cloud] End of cloud request. 2026-08-16T20:54:13.389 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb934f277 2026-08-16T20:54:13.436 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:13.436 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:13.436 [Cloud] Queued cloud request. 2026-08-16T20:54:13.436 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:13.436 [Cloud] Dequeued cloud request. 2026-08-16T20:54:13.436 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:13.639 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:54:13.764 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\69cf7af13c6bfb41a5447037db57f8df7c930b80 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:01 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:13.764 [Cloud] End of cloud request. 2026-08-16T20:54:13.764 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7c337a01 2026-08-16T20:54:13.827 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:13.827 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:13.827 [Cloud] Queued cloud request. 2026-08-16T20:54:13.827 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:13.827 [Cloud] Dequeued cloud request. 2026-08-16T20:54:13.827 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:14.108 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5281717d608eaccc24b789d7da1e88b596854777 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:01 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:14.123 [Cloud] End of cloud request. 2026-08-16T20:54:14.123 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe4e9c3ef 2026-08-16T20:54:14.155 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:14.155 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:14.155 [Cloud] Queued cloud request. 2026-08-16T20:54:14.155 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:14.155 [Cloud] Dequeued cloud request. 2026-08-16T20:54:14.155 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:14.280 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:54:14.342 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75d405221561e25dac7418dab83b79f344429b20 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:01 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:14.342 [Cloud] End of cloud request. 2026-08-16T20:54:14.342 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9cab2c6 2026-08-16T20:54:14.389 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:14.389 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:14.389 [Cloud] Queued cloud request. 2026-08-16T20:54:14.389 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:14.389 [Cloud] Dequeued cloud request. 2026-08-16T20:54:14.389 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:14.608 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a78bc39eb361b47bc41487ac751d3659f0506509 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:02 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:14.608 [Cloud] End of cloud request. 2026-08-16T20:54:14.608 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf05abbb8 2026-08-16T20:54:14.655 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-16T20:54:14.655 [Cloud] Start of cloud request. Passive mode: 0 2026-08-16T20:54:14.655 [Cloud] Queued cloud request. 2026-08-16T20:54:14.655 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-16T20:54:14.655 [Cloud] Dequeued cloud request. 2026-08-16T20:54:14.655 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-16T20:54:14.858 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:54:14.951 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\31f94e19e029043c269e9388bbeaa382de2d09a6 Dynamic Signature Compilation Timestamp:08-16-2026 20:54:02 Persistence Type:Duration Time remaining:50065408 2026-08-16T20:54:14.951 [Cloud] End of cloud request. 2026-08-16T20:54:14.951 RTSD:RTSD recieved, rescanning impacted resources 2026-08-16T20:54:15.455 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-16T20:55:07.327 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8238, FileId: 0x220000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.334 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8240, FileId: 0x230000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.341 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8241, FileId: 0xa000000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.341 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8242, FileId: 0x240000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.341 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8244, FileId: 0xa200000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.341 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8233, FileId: 0x210000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.348 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8243, FileId: 0xa100000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.369 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8246, FileId: 0xa300000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.369 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8245, FileId: 0x260000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.369 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8239, FileId: 0x9f00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8252, FileId: 0xa600000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8249, FileId: 0x280000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8247, FileId: 0x270000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8255, FileId: 0x2d0000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8248, FileId: 0xa400000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.376 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8253, FileId: 0xa900000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.390 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8256, FileId: 0xaa00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:07.390 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8250, FileId: 0xa500000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.216 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8303, FileId: 0x340000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.216 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8304, FileId: 0x29000000034bf4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.237 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8306, FileId: 0x2b000000034bf4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.237 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8305, FileId: 0x360000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.244 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8302, FileId: 0x26000000034bf4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.321 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8318, FileId: 0x380000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.321 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8320, FileId: 0x390000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.328 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8321, FileId: 0xad00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.342 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8319, FileId: 0x2f000000034bf4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.342 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8317, FileId: 0x2e000000034bf4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.356 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8314, FileId: 0x370000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.356 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8325, FileId: 0xae00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.363 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8327, FileId: 0xaf00000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.363 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8328, FileId: 0x3c0000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.377 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8326, FileId: 0x3b0000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.377 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8332, FileId: 0x3d0000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.391 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8323, FileId: 0x3a0000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.880 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8382, FileId: 0x420000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.880 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8383, FileId: 0xb200000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.886 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8380, FileId: 0x410000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.892 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8384, FileId: 0xb300000000d3c0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:08.892 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8385, FileId: 0x430000000349e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:11.096 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8579, FileId: 0x26000000034d2a, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:12.979 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\536c7a9c-742a-4388-a075-c1115cba47a8. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #8647, FileId: 0xe400000000c8fc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:12.993 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #8649, FileId: 0x20000000033885, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:17.935 Bm signature throttled:0x00002db31bed458f 2026-08-16T20:55:20.935 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #9039, FileId: 0x36000000035139, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0xc49fe01e 2026-08-16T20:55:21.998 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\Other15688.txt. Process: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe, Status: 0xc0000001, State: 0, ScanRequest #9203, FileId: 0x5e00000003514b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:25.123 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-16T20:55:27.530 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE827F8970. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9440, FileId: 0x30000000035d3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:27.877 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj982ED79B8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9441, FileId: 0x31000000035d3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:27.924 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj91AFC6943. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9463, FileId: 0x38000000035d3c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:28.002 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj57AC1196D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9466, FileId: 0x32000000035d3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:28.065 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5B2751902. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9470, FileId: 0x33000000035d3d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:30.838 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7E5E80946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9555, FileId: 0x33000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:30.854 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA72C779C8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9551, FileId: 0x15000000035f66, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:31.636 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDB8AA997F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9579, FileId: 0x34000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:32.136 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA90B93908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9596, FileId: 0x34000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:32.981 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj52E85A9F8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9630, FileId: 0x38000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:32.997 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD1813A92E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9634, FileId: 0xc6000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:33.216 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9D49F9975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9636, FileId: 0x3a000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:33.883 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3E2C2B927. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9654, FileId: 0xc7000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:33.898 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5E357A923. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9655, FileId: 0x38000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.055 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5C2F8F9EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9662, FileId: 0x3c000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.101 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj25E077930. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9665, FileId: 0xca000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.226 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4DC72E9DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9675, FileId: 0x46000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.430 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj93872F928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9684, FileId: 0x3e000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.664 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3B7B65969. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9695, FileId: 0x3f000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.742 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC85ED59C9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9697, FileId: 0x40000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.805 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8550BF990. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9699, FileId: 0x4a000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.820 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD06055908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9700, FileId: 0x41000000035f1f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:34.914 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj344D6E961. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9702, FileId: 0xcb000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.055 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45661F997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9704, FileId: 0xcc000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.070 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAA0F0D9FC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9705, FileId: 0xcd000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.133 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAA92F29AC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9709, FileId: 0xce000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.195 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD42B07921. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9710, FileId: 0xcf000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.635 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4DC42E9B0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9716, FileId: 0x53000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.635 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj910F4C97E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9715, FileId: 0xd0000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.814 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBD8B81901. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9723, FileId: 0x1e000000035f93, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.881 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF72FB594F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9726, FileId: 0x2ff000000000484, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.952 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD0E08599E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9732, FileId: 0xaf000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.952 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj216EE9932. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9731, FileId: 0xae000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.983 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3A12E6940. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9734, FileId: 0xb0000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:35.983 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj87B379975. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9735, FileId: 0xb1000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.087 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj86D71E90B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9740, FileId: 0xb2000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.120 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9C5516942. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9743, FileId: 0xb3000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.139 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj45585E950. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9745, FileId: 0xb4000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.248 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE0149795A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9757, FileId: 0x59000000035f1c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.373 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj39F77C9B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9767, FileId: 0xd3000000035f79, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.529 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECC9AC9AF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9776, FileId: 0x68000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.717 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB2B4FB946. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9786, FileId: 0x69000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:36.951 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj91DF15997. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9790, FileId: 0xb8000000004420, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.248 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB716F999C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9819, FileId: 0x8700000003607e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.342 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8B506B908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9825, FileId: 0x6c000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.435 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj942382917. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9830, FileId: 0x6d000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.467 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj61E6D2945. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9834, FileId: 0x6e000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.482 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7882E99C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9836, FileId: 0x6f000000035ffd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.967 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj84D0FF9FB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9865, FileId: 0x15000000036241, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:37.967 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj614BBC9C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9859, FileId: 0x4000000003626e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:38.201 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj631410980. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9879, FileId: 0x28000000036337, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:38.217 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4AA8C29E0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #9874, FileId: 0x4100000003626e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:48.970 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10065, FileId: 0x1ba000000004be9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:55:49.049 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #10082, FileId: 0x3000000001b9e7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-16T20:56:28.955 [RTP] [Mini-filter] OpenWithoutRead notification (1020, 10218, \Device\HarddiskVolume3\Windows\System32\backgroundTaskHost.exe) sent successfully. Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x447dc46d 2026-08-16T20:57:47.941 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO7D18.tmp` is 11390 units Internal signature match:subtype=Lowfi, sigseq=0x0000157EEDC1FDAA, sigsha=957d8fbfe7987111d93ac432453760da86bb5a7d, cached=false, source=2, resourceid=0x15142090 2026-08-16T20:57:58.571 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{20E5776D-2353-45C9-9720-C705EF5520B6}\MicrosoftEdge_X64_151.0.4129.86.exe` is 9625 units 2026-08-16T20:58:17.455 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-16T20:58:35.268 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5968 units 2026-08-16T20:59:22.111 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.86\msedge.dll` is 5640 units 2026-08-16T21:00:25.111 Timer callback: Initializating/verifying scheduled tasks ... 2026-08-16T21:00:25.111 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-08-16T21:00:25.205 Job Notification: New process added to job (2264) 2026-08-16T21:00:25.221 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-16T21:00:25.236 Job Notification: New process added to job (7044) 2026-08-16T21:00:25.299 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:2264] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7044]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T21:00:25.299 Aggressive catchup quick scan threshold: 52281241399502 / 25920000000000 2026-08-16T21:00:25.408 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 17558689(ms) from now at 03:53 (01:53 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-16T21:00:25.424 Job Notification: New process added to job (12328) 2026-08-16T21:00:25.440 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 1 -ScanTrigger 59) launched 2026-08-16T21:00:25.440 Running aggressive catchup quick scan: Scan -ScheduleJob -RestrictPrivileges -ScanType 1 -ScanTrigger 59 2026-08-16T21:00:25.455 Job Notification: New process added to job (11964) 2026-08-16T21:00:25.471 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:12328] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11964]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T21:00:25.580 Job Notification: New process added to job (1936) 2026-08-16T21:00:25.596 Job Notification: Process exited from job (12328) 2026-08-16T21:00:25.596 Job Notification: Process exited from job (11964) 2026-08-16T21:00:25.643 Created on demand scan context for ScanType:1. ScanTrigger:59, ScanId:F2B80771-D53A-4724-A779-1DDDF767C4FB, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-16T21:00:25.643 Scheduled scan with Id F2B80771-D53A-4724-A779-1DDDF767C4FB configured CPU priority: normal (LowCpuPriority: 0) 2026-08-16T21:00:25.643 Job Notification: New process added to job (1168) 2026-08-16T21:00:25.643 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-16T21:00:25.643 [SFC] System file cache build is not needed (already completed) 2026-08-16T21:00:25.658 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-16T21:00:25.690 Job Notification: New process added to job (812) 2026-08-16T21:00:25.690 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:1168] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:812]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-16T21:00:25.830 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-16T21:00:25.830 [RTP] Duplicating the current plugin configuration object... 2026-08-16T21:00:25.830 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T21:00:25.830 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-16T21:00:25.830 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T21:00:25.830 [RTP] No config change detected. Not updating plugin configuration. 2026-08-16T21:00:25.830 [RTP] No config changes found. No configuration switch. 2026-08-16T21:00:25.830 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-16T21:00:27.658 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:00:27.674 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T21:00:27.674 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:00:29.674 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:00:29.674 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T21:00:29.690 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:00:40.387 Job Notification: Process exited from job (1168) 2026-08-16T21:00:40.387 Job Notification: Process exited from job (812) 2026-08-16T21:00:40.403 Job Notification: Process exited from job (2264) 2026-08-16T21:00:40.418 Job Notification: Process exited from job (7044) 2026-08-16T21:00:46.298 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-16T21:01:13.814 Process scan (postsignatureupdatescan) started. 2026-08-16T21:01:24.904 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-08-16T21:01:24.904 [RTP] Duplicating the current plugin configuration object... 2026-08-16T21:01:24.904 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T21:01:24.904 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-16T21:01:24.904 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-16T21:01:24.904 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-16T21:01:24.919 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-08-16T21:01:26.325 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy5\System Volume Information\SPP\snapshot-2 2026-08-16T21:01:26.404 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2 2026-08-16T21:01:26.935 Process scan (postsignatureupdatescan) completed. 2026-08-16T21:01:44.256 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys 2026-08-16T21:01:45.725 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\pagefile.sys Internal signature match:subtype=Lowfi, sigseq=0x0000157EEDC1FDAA, sigsha=957d8fbfe7987111d93ac432453760da86bb5a7d, cached=false, source=2, resourceid=0xa88bd4ec 2026-08-16T21:02:01.393 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy8\pagefile.sys 2026-08-16T21:02:02.455 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{35DF9464-7738-4A47-9E47-F416B705B27C}\MicrosoftEdge_X64_151.0.4129.86.exe` is 11078 units 2026-08-16T21:02:02.689 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy8\pagefile.sys 2026-08-16T21:02:33.085 Engine:Triggered AR EMS scan 2026-08-16T21:02:33.085 Engine:EMS scan for process: lsass pid: 776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.100 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.116 Engine:EMS scan for process: svchost pid: 916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.131 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.131 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.272 Engine:EMS scan for process: svchost pid: 1256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.272 Engine:EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.272 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.272 Engine:EMS scan for process: svchost pid: 1372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.272 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.288 Engine:EMS scan for process: svchost pid: 1488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.288 Engine:EMS scan for process: svchost pid: 1568, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.288 Engine:EMS scan for process: svchost pid: 1612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.288 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.303 Engine:EMS scan for process: svchost pid: 1668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.303 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.303 Engine:EMS scan for process: svchost pid: 1856, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.303 Engine:EMS scan for process: svchost pid: 2024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.303 Engine:EMS scan for process: svchost pid: 2088, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.319 Engine:EMS scan for process: svchost pid: 2144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.319 Engine:EMS scan for process: svchost pid: 2252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.319 Engine:EMS scan for process: svchost pid: 2324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.319 Engine:EMS scan for process: svchost pid: 2376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.319 Engine:EMS scan for process: svchost pid: 2388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.335 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.335 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.335 Engine:EMS scan for process: svchost pid: 2604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.335 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.335 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.350 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.350 Engine:EMS scan for process: svchost pid: 3004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.350 Engine:EMS scan for process: svchost pid: 2396, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.366 Engine:EMS scan for process: svchost pid: 3024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.366 Engine:EMS scan for process: svchost pid: 3208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.366 Engine:EMS scan for process: svchost pid: 3792, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.506 Engine:EMS scan for process: svchost pid: 3928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.506 Engine:EMS scan for process: svchost pid: 3960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.506 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.506 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.506 Engine:EMS scan for process: svchost pid: 4024, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.538 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.538 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.538 Engine:EMS scan for process: svchost pid: 4188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.538 Engine:EMS scan for process: svchost pid: 4316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.553 Engine:EMS scan for process: svchost pid: 4360, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.553 Engine:EMS scan for process: svchost pid: 4548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.569 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.569 Engine:EMS scan for process: svchost pid: 4612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.569 Engine:EMS scan for process: svchost pid: 4724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.585 Engine:EMS scan for process: svchost pid: 5256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.585 Engine:EMS scan for process: svchost pid: 5520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.585 Engine:EMS scan for process: svchost pid: 5528, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.585 Engine:EMS scan for process: svchost pid: 5892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.585 Engine:EMS scan for process: svchost pid: 6128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.600 Engine:EMS scan for process: dllhost pid: 4948, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.600 Engine:EMS scan for process: svchost pid: 6268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.600 Engine:EMS scan for process: svchost pid: 7472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.600 Engine:EMS scan for process: svchost pid: 6972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.600 Engine:EMS scan for process: svchost pid: 8092, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.741 Engine:EMS scan for process: svchost pid: 8212, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.741 Engine:EMS scan for process: svchost pid: 8348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.756 Engine:EMS scan for process: explorer pid: 8768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.819 Engine:EMS scan for process: svchost pid: 8832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.819 Engine:EMS scan for process: svchost pid: 9048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.819 Engine:EMS scan for process: svchost pid: 9208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.835 Engine:EMS scan for process: svchost pid: 10184, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.835 Engine:EMS scan for process: svchost pid: 9372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.835 Engine:EMS scan for process: svchost pid: 8128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.835 Bm signature throttled:0x00002db31bed458f 2026-08-16T21:02:33.835 Engine:EMS scan for process: svchost pid: 6540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.975 Engine:EMS scan for process: svchost pid: 6956, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.975 Engine:EMS scan for process: dllhost pid: 11588, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.975 Engine:EMS scan for process: svchost pid: 11800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.975 Engine:EMS scan for process: svchost pid: 7192, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.991 Engine:EMS scan for process: svchost pid: 13764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.991 Engine:EMS scan for process: svchost pid: 11188, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:33.991 Engine:EMS scan for process: svchost pid: 580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.006 Engine:EMS scan for process: svchost pid: 5724, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.006 Engine:EMS scan for process: svchost pid: 7684, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.006 Engine:EMS scan for process: svchost pid: 14324, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.022 Engine:EMS scan for process: wuauclt pid: 9240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.022 Engine:EMS scan for process: svchost pid: 6480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.022 Engine:EMS scan for process: svchost pid: 9696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:02:34.022 Engine:EMS scan for process: svchost pid: 608, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-16T21:04:52.611 ExpensiveFile:Scan time for `\\?\C:\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5453 units 2026-08-16T21:10:30.115 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-16T21:13:13.799 QuickScan:ScanID:F2B80771-D53A-4724-A779-1DDDF767C4FB: Quick scan finished with error 0 2026-08-16T21:13:13.955 Job Notification: Process exited from job (1936) 2026-08-16T21:13:14.455 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-16T21:13:14.455 [RTP] Duplicating the current plugin configuration object... 2026-08-16T21:13:14.455 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-16T21:13:14.455 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-16T21:13:14.455 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-16T21:13:14.455 [RTP] No config change detected. Not updating plugin configuration. 2026-08-16T21:13:14.455 [RTP] No config changes found. No configuration switch. 2026-08-16T21:13:14.455 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-16T21:13:15.940 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:13:15.955 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T21:13:15.955 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:13:17.955 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:13:17.955 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-16T21:13:17.955 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-16T21:16:27.345 [AutoPurge] Routine task for Cache Maintenance has started. 2026-08-16T21:16:27.346 [AutoPurge] Routine task for Cache Maintenance ... 2026-08-16T21:16:27.346 [AutoPurge] Routine task for MpSFCBuild ... 2026-08-16T21:16:27.346 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-08-16T21:16:27.346 [AutoPurge] MpSignalMaintenanceMode ... 2026-08-16T21:16:27.354 Engine:EMS scan for process: lsass pid: 776, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.380 Engine:EMS scan for process: svchost pid: 972, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.407 Engine:EMS scan for process: svchost pid: 916, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.412 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.419 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.431 Engine:EMS scan for process: svchost pid: 1256, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.435 Engine:EMS scan for process: svchost pid: 1328, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.444 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.449 Engine:EMS scan for process: svchost pid: 1372, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.453 Engine:EMS scan for process: svchost pid: 1444, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.462 Engine:EMS scan for process: svchost pid: 1488, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.465 Engine:EMS scan for process: svchost pid: 1568, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.478 Engine:EMS scan for process: svchost pid: 1612, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.487 Engine:EMS scan for process: svchost pid: 1652, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.492 Engine:EMS scan for process: svchost pid: 1668, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.496 Engine:EMS scan for process: svchost pid: 1708, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.504 Engine:EMS scan for process: svchost pid: 1856, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.509 Engine:EMS scan for process: svchost pid: 2024, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.513 Engine:EMS scan for process: svchost pid: 2088, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.519 Engine:EMS scan for process: svchost pid: 2144, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.528 Engine:EMS scan for process: svchost pid: 2252, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.534 Engine:EMS scan for process: svchost pid: 2324, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.540 Engine:EMS scan for process: svchost pid: 2376, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.544 Engine:EMS scan for process: svchost pid: 2388, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.549 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.553 Engine:EMS scan for process: svchost pid: 2460, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.556 Engine:EMS scan for process: svchost pid: 2604, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.562 Engine:EMS scan for process: svchost pid: 2684, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.570 Engine:EMS scan for process: svchost pid: 2692, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.575 Engine:EMS scan for process: svchost pid: 2724, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.579 Engine:EMS scan for process: svchost pid: 3004, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.585 Engine:EMS scan for process: svchost pid: 2396, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.596 Engine:EMS scan for process: svchost pid: 3024, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.601 Engine:EMS scan for process: svchost pid: 3208, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.611 Engine:EMS scan for process: svchost pid: 3792, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.620 Engine:EMS scan for process: svchost pid: 3928, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.624 Engine:EMS scan for process: svchost pid: 3960, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.627 Engine:EMS scan for process: svchost pid: 3968, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.633 Engine:EMS scan for process: svchost pid: 4000, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.639 Engine:EMS scan for process: svchost pid: 4024, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.664 Engine:EMS scan for process: svchost pid: 4036, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.670 Engine:EMS scan for process: svchost pid: 4176, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.678 Engine:EMS scan for process: svchost pid: 4188, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.683 Engine:EMS scan for process: svchost pid: 4316, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.697 Engine:EMS scan for process: svchost pid: 4360, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.707 Engine:EMS scan for process: svchost pid: 4548, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.711 Engine:EMS scan for process: svchost pid: 4588, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.716 Engine:EMS scan for process: svchost pid: 4612, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.719 Engine:EMS scan for process: svchost pid: 4724, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.729 Engine:EMS scan for process: svchost pid: 5256, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.735 Engine:EMS scan for process: svchost pid: 5520, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.742 Engine:EMS scan for process: svchost pid: 5528, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.751 Engine:EMS scan for process: svchost pid: 5892, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.757 Engine:EMS scan for process: svchost pid: 6128, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.761 Engine:EMS scan for process: dllhost pid: 4948, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 2026-08-16T21:16:27.764 Engine:EMS scan for process: svchost pid: 6268, sigseq: 0x0, sendMemoryScanReport: 0, source: 18 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-19-2026 15:35:55 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/19/2026 15:35:55.249304300 UTC (21968 ms since boot) 2026-08-19T15:35:55.355 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-19T15:35:55.355 WARNING: the previous service shutdown was not expected. 2026-08-19T15:35:55.371 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:35:55.371 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 1, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:35:55.449 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260819-153555-00000003-fffffffeffffffff.bin ... 2026-08-19T15:35:55.464 [WPP] Trace session started - MpWppTracing-20260819-153555-00000003-fffffffeffffffff.bin 2026-08-19T15:35:55.480 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-19T15:35:55.480 [RbM] Rollback manager succesfully initialized. 2026-08-19T15:35:55.480 [RbM] Rollback manager EnableRollbackManager called. 2026-08-19T15:35:55.496 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-19T15:35:55.496 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 2026-08-19T15:35:55.496 MpWriteUupPlatformVersion 4.18.26050.15, hr = 0 2026-08-19T15:35:55.496 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-08-19T15:35:55.496 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-08-19T15:35:55.511 MdCoreSvc is supported in this platform and OS 2026-08-19T15:35:55.511 MdCoreSvc is supported in this platform and OS 2026-08-19T15:35:55.511 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-19T15:35:55.511 [PlatUpd] Starting MdCoreSvc service 2026-08-19T15:35:55.542 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0" 2026-08-19T15:36:00.214 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-19T15:36:00.214 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-08-19T15:36:00.214 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-19T15:36:00.214 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-19T15:36:00.214 [PlatUpd] CSP platform update started 2026-08-19T15:36:00.214 [PlatUpd] Defender MDM CSP platform update not required 2026-08-19T15:36:00.214 [PlatUpd] WMI/PS provider platform update started 2026-08-19T15:36:00.214 [PlatUpd] WMI/PS provider platform update not required 2026-08-19T15:36:00.214 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-19T15:36:00.214 MdCoreSvc is supported in this platform and OS 2026-08-19T15:36:00.214 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-19T15:36:00.214 [PlatUpd] Starting MdCoreSvc service 2026-08-19T15:36:00.214 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0): 10 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-19T15:36:00.214 [TS] Troubleshooting mode is not available! 2026-08-19T15:36:00.214 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-19T15:36:00.214 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-19T15:36:00.246 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-19T15:36:00.246 [Service] Enabling AutoLoggers ... 2026-08-19T15:36:00.246 DefenderApiLoggerLowPriv started successfully. 2026-08-19T15:36:00.246 [Service] Enabling AMSI registration ... 2026-08-19T15:36:00.246 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-19T15:36:00.261 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 34179 Number of invalid entries is 0 Number of inserts issued is 1599883 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6599 Number of lookups is 109017199 Number of lookup misses is 5244737 Number of fast lookup misses is 55574142 Number of false fast lookups is 5244732 Number of invalidations is 741537 Number of maintenance invalidations is 541193 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-19T15:36:00.261 Verifying license file... 2026-08-19T15:36:00.261 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\msmplics.dll] (file in cache) 2026-08-19T15:36:00.277 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-19T15:36:00.292 Loaded module#0 MpComServer. 2026-08-19T15:36:00.292 Loaded module#1 StartupPolicies. 2026-08-19T15:36:00.292 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-19T15:36:00.292 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-19T15:36:00.292 COM server initialized successfully. 2026-08-19T15:36:00.308 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-19T15:36:00.308 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll ... 2026-08-19T15:36:00.308 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mprtp.dll] due to PPL. 2026-08-19T15:36:00.324 [RTP] [RTP] FilterCommunicator object 0x0000016D21EC0C90 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-19T15:36:00.339 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-19T15:36:00.339 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:36:00.339 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:36:00.339 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-19T15:36:00.339 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-19T15:36:00.339 [RTP] [RTP] FilterCommunicator object 0x0000016D21EC0EA0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-19T15:36:00.339 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-19T15:36:00.339 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-19T15:36:00.339 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-19T15:36:00.339 [RTP] [RTP] StartCommunication 0x0000016D21EC0C90 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-19T15:36:00.339 [init][RTP] RTPPlugin initialization completed 2026-08-19T15:36:00.339 [NiPlugin] Skipping the NiPlugin initialization as C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mpnirtp.dll does not exist. 2026-08-19T15:36:00.339 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-19T15:36:00.339 OS boot count = 2 2026-08-19T15:36:00.339 OS Install = 0 2026-08-19T15:36:00.339 [ManagedAgent] HooksInitialize: starting 2026-08-19T15:36:00.339 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-19T15:36:00.339 [ManagedAgent] HooksInitialize: complete 2026-08-19T15:36:00.339 [init] MpAddMpUxRegistrationForToast failed (Ignored). hr = 0x8000401a 2026-08-19T15:36:00.339 [KSL] Entering CKSLEngine::Initialize. 2026-08-19T15:36:00.339 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-19T15:36:00.339 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-19T15:36:00.355 [KSL] MpInstallKslD: hr=0x1 2026-08-19T15:36:00.355 [KSL] MpRegisterKslD: hr=0 2026-08-19T15:36:00.355 [KSL] MpStartKslD: hr=0 2026-08-19T15:36:00.355 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:36:00.355 Loading engine... 2026-08-19T15:36:00.371 Verifying engine and signature files (source: 1) ... 2026-08-19T15:36:00.371 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpengine.dll] due to PPL. 2026-08-19T15:36:00.371 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasbase.vdm] (file in cache) 2026-08-19T15:36:00.371 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasdlta.vdm] (file in cache) 2026-08-19T15:36:00.371 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavbase.vdm] (file in cache) 2026-08-19T15:36:00.371 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavdlta.vdm] (file in cache) 2026-08-19T15:36:00.402 [Engine] IsHybridMode: 0 2026-08-19T15:36:00.402 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-19T15:36:00.433 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A2AA6B92914AB6DF8D99138A3D735D61A67B0FEF.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-19T15:36:05.871 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-19T15:36:05.871 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_Kernel_VetoCldFltRegSyncRoot hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnection hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNisExternalInboundConnectionThrottle hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableNriRiskIQDetect hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorTcp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFC_EnableRiskIQSensorUdp hr=0x8007007b IDynamicConfig::ReportError ECS value=MpFc_Kernel_DoNotResetExcludeOnModify hr=0x8007007b IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-19T15:36:05.886 [Engine] New active engine 00007FFB6A9355E0 (no old engine). Number of active engines: 1 2026-08-19T15:36:05.917 EngineInit:Global ASOC is enabled 2026-08-19T15:36:05.917 EngineInit:ASOO is enabled for developer volumes 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:36:06.042 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7949c82c0e01739604049af47f614d66894b9a7f Dynamic Signature Compilation Timestamp:08-16-2026 20:53:59 Persistence Type:Duration Time remaining:288000000 2026-08-19T15:36:06.042 Dynamic signature dropped 2026-08-19T15:36:06.058 MpWriteUupSignatureVersion 1.457.196.0, hr = 0 2026-08-19T15:36:06.058 [SigStatUpd] CSignatureStatus: back to good 2026-08-19T15:36:06.058 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-19T15:36:06.089 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-19T15:36:06.089 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:36:06.089 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-19T15:36:06.089 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-19T15:36:06.089 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-19T15:36:06.105 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-19T15:36:06.105 [Plugin] Initializing RTP plugin state... 2026-08-19T15:36:06.105 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2191 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:12581 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2782 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-19T15:36:06.105 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-19T15:36:06.105 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8} 2026-08-19T15:36:06.105 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:36:06.105 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:36:06.105 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:36:06.105 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-19T15:36:06.105 MdCoreSvc is supported in this platform and OS 2026-08-19T15:36:06.105 Engine loaded! 2026-08-19T15:36:06.105 [DLP] Create FeatureControlState instance 2026-08-19T15:36:06.121 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-19T15:36:06.121 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-19T15:36:06.121 RegisterSModeChangeListener: hr = 0x1 2026-08-19T15:36:06.121 RegisterHybridModeChangeListener: hr = 0 2026-08-19T15:36:06.136 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-19T15:36:06.136 [SigReleaseHb] Initialized with Stage 0 2026-08-19T15:36:06.136 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-19T15:36:06.136 [SCC][CID=32859_6092] Initializing ... 2026-08-19T15:36:06.136 [SCC][CID=32859_6092] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-19T15:36:06.136 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-19T15:36:06.136 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-19T15:36:06.136 [NRI] Stopping NIS service ... 2026-08-19T15:36:06.136 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-19T15:36:06.136 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26050.15 Service Version: 4.18.26050.15 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.196.0 AV Signature Version: 1.457.196.0 ************************************************************ 2026-08-19T15:36:06.136 Resource usage Monitoring is enabled 2026-08-19T15:36:06.152 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-19T15:36:06.152 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-19T15:36:06.152 Job Notification: New process added to job (5300) 2026-08-19T15:36:06.230 Job Notification: New process added to job (7920) 2026-08-19T15:36:06.246 Job Notification: New process added to job (7928) 2026-08-19T15:36:06.246 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpCmdRun.exe][Pid:7920] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7928]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-19T15:36:06.261 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-19T15:36:06.261 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-19T15:36:06.277 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-19T15:36:06.277 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-19T15:36:06.277 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-19T15:36:06.277 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:36:06.277 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:36:06.277 [RTP] Generating the base plugin configuration ... 2026-08-19T15:36:06.277 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-19T15:36:06.277 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:36:06.277 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-19T15:36:06.277 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-19T15:36:06.277 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:36:06.277 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-19T15:36:06.277 [RTP] [RTP] StartCommunication 0x0000016D21EC0EA0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-19T15:36:06.292 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-19T15:36:06.292 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-08-19T15:36:06.371 Job Notification: Process exited from job (7920) 2026-08-19T15:36:06.371 Job Notification: Process exited from job (7928) 2026-08-19T15:36:06.371 [PlatUpd] WMI MOF schema validation completed successfully 2026-08-19T15:36:06.574 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-19T15:36:06.574 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-19T15:36:06.574 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:36:06.636 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:06.792 [AutoPurge] Verification Routine tasks have started. 2026-08-19T15:36:06.792 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-19T15:36:07.074 EnsureProtectedFolderAcls(), hr = 0x0 2026-08-19T15:36:07.074 [AutoPurge] MpReinforceServiceAcls: 0 2026-08-19T15:36:07.105 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-08-19T15:36:07.496 Job Notification: New process added to job (6488) 2026-08-19T15:36:07.496 Task(GetDeviceTicket -AccessKey 1771E368-139B-31AE-E91A-F1137F4A3ECB ) launched as network service 2026-08-19T15:36:07.886 Job Notification: Process exited from job (6488) 2026-08-19T15:36:08.121 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-08-19T15:36:08.136 [Cloud] Start of cloud request. Passive mode: 0 2026-08-19T15:36:08.136 [Cloud] Queued cloud request. 2026-08-19T15:36:08.136 [Cloud] Dequeued cloud request. 2026-08-19T15:36:08.136 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-19T15:36:08.371 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-19T15:36:08.371 [Cloud] End of cloud request. 2026-08-19T15:36:08.433 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-08-19T15:36:08.433 [AutoPurge] Verification Routine tasks have ended. 2026-08-19T15:36:08.433 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-19T15:36:08.464 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:08.464 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 2 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 4096 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 4 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 8 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 16 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 2048 2026-08-19T15:36:08.464 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-19T15:36:08.464 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:36:08.464 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:36:08.464 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-19T15:36:08.464 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-19T15:36:08.464 [RTP] [RtpConfig] Config change detected, type: 64 2026-08-19T15:36:08.464 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:08.464 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:08.480 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:36:09.214 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:36:09.214 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:36:09.214 [RTP] Updating plugin configuration due to recent config changes (0x63e) ... 2026-08-19T15:36:09.214 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:36:09.214 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-19T15:36:09.214 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x63e, Changed: 0x208 2026-08-19T15:36:43.496 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-19T15:36:46.792 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-08-19T15:36:46.792 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:36:46.792 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:36:46.792 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-19T15:36:46.792 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-19T15:36:46.808 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-19T15:36:47.355 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-19T15:36:47.417 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-19T15:36:47.683 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-19T15:36:47.980 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-08-19T15:36:54.949 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5968 units 2026-08-19T15:36:55.027 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-19T15:37:02.511 Process scan (poststartupscan) started. 2026-08-19T15:37:02.511 Process scan (poststartupscan) completed. 2026-08-19T15:37:06.973 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.86\msedgewebview2.exe (PPID:10696:134316274235558223) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-08-19T15:37:06.988 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.86\msedgewebview2.exe (PPID:10744:134316274237928977) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-08-19T15:37:07.020 Engine:Process C:\Program Files (x86)\Microsoft\EdgeWebView\Application\151.0.4129.86\msedgewebview2.exe (PPID:10900:134316274242079400) is tainted: TaintType:0x8. TaintReason:C:\Program Files\TeamViewer\TeamViewer.exe, EnableCfa:1 2026-08-19T15:37:10.748 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-08-19T15:37:10.748 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-08-19T15:37:10.748 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-08-19T15:37:10.748 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-08-19T15:37:10.795 [PlatUpd] Verified C:\Windows\SystemTemp\92AED081-C476-4DBE-B4B2-5355EDE3C067\MpUpdate.dll. Calling MpUpdateStub(0) ... 2026-08-19T15:37:18.596 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-19T15:37:18.596 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:37:18.596 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-19T15:37:18.596 [NRI] Stopping NIS service ... 2026-08-19T15:37:18.612 [NRI] Stopping NIS service ... 2026-08-19T15:37:20.503 [PlatUpd] MpUpdateStub() succeeded. Stub DLL: C:\Windows\SystemTemp\92AED081-C476-4DBE-B4B2-5355EDE3C067\MpUpdate.dll. 2026-08-19T15:37:20.518 [KSL] Entering CKSLEngine::DisableKSL. 2026-08-19T15:37:20.518 [KSL] Entering CKSLEngine::shutdownImpl. 2026-08-19T15:37:20.643 [KSL] Leaving CKSLEngine::shutdownImpl(0). 2026-08-19T15:37:20.643 [KSL] Leaving CKSLEngine::DisableKSL(0). 2026-08-19T15:37:20.643 [KSL] OnPlatformUpdate: hr=[0x8000000a] Type=[1] KslServiceExists=[1] KslActive=[1] KslState=[2] 2026-08-19T15:37:20.675 [PlatUpd] DlpActive 0, CopyAccActive 0, WdAiNisDrvPending 0 2026-08-19T15:37:20.675 [PlatUpd] PlatformUpdate is now allowed. Resuming platform update from C:\Windows\SystemTemp\92AED081-C476-4DBE-B4B2-5355EDE3C067. 2026-08-19T15:37:20.675 [PlatUpd] NewLocation set to [C:\Windows\SystemTemp\92AED081-C476-4DBE-B4B2-5355EDE3C067] to indicate we are in the middle of an update. 2026-08-19T15:37:20.878 Job Notification: New process added to job (11832) 2026-08-19T15:37:20.893 Task(-RestartService) launched as PPL process 2026-08-19T15:37:21.034 Job Notification: New process added to job (11848) 2026-08-19T15:37:21.190 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-19T15:37:21.190 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-19T15:37:21.206 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:37:21.206 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-19T15:37:21.221 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-19T15:37:21.565 [NRI] Successfully updated NIS service with platform settings for enforcement level Log -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-19-2026 15:37:31 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/19/2026 15:37:31.830245000 UTC (118546 ms since boot) 2026-08-19T15:37:31.838 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-19T15:37:31.840 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:37:31.840 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:37:31.854 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260819-153731-00000003-fffffffeffffffff.bin ... 2026-08-19T15:37:31.860 [WPP] Trace session started - MpWppTracing-20260819-153731-00000003-fffffffeffffffff.bin 2026-08-19T15:37:31.865 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-19T15:37:31.865 [RbM] Rollback manager succesfully initialized. 2026-08-19T15:37:31.866 [RbM] Rollback manager EnableRollbackManager called. 2026-08-19T15:37:31.872 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-19T15:37:31.872 [PlatUpd] Stage 1 - Starting platform update from %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0 ... 2026-08-19T15:37:35.665 [PlatUpd] Updated service binary of WdNisSvc from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\NisSrv.exe" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0\NisSrv.exe" 2026-08-19T15:37:35.666 [PlatUpd] Stopping service WdAiNisDrv failed with 0x80070424. Ignored (attempt #0) 2026-08-19T15:37:35.667 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdAiNisDrv.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\Drivers\WdAiNisDrv.sys 2026-08-19T15:37:35.669 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdBoot.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\Drivers\WdBoot.sys 2026-08-19T15:37:35.670 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdFilter.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\Drivers\WdFilter.sys 2026-08-19T15:37:35.672 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdNisDrv.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\Drivers\WdNisDrv.sys 2026-08-19T15:37:36.245 [PlatUpd] Updated driver binary link C:\Windows\system32\drivers\wd\WdDevFlt.sys to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\Drivers\WdDevFlt.sys 2026-08-19T15:37:39.664 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpOav.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpOav.dll" 2026-08-19T15:37:39.665 [PlatUpd] Updated SOFTWARE\WOW6432Node\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocServer32[(default)] from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\X86\MpOav.dll" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\X86\MpOav.dll" 2026-08-19T15:37:39.680 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-19T15:37:39.680 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0. 2026-08-19T15:37:39.680 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-19T15:37:39.680 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-19T15:37:39.680 [PlatUpd] CSP platform update started 2026-08-19T15:37:39.680 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{195B4D07-3DE2-4744-BBF2-D90121AE785B}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\DefenderCSP.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0\DefenderCSP.dll" 2026-08-19T15:37:39.680 [PlatUpd] CSP version com.microsoft/1.3/MDM/Defender update not required. 2026-08-19T15:37:39.680 [PlatUpd] WMI/PS provider platform update started 2026-08-19T15:37:39.680 [PlatUpd] Powershell module update started: ConfigDefender -> C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ConfigDefender 2026-08-19T15:37:39.694 [PlatUpd] Powershell module update completed: ConfigDefender -> C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ConfigDefender 2026-08-19T15:37:39.694 [PlatUpd] Powershell module update started: ConfigDefender -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\ConfigDefender 2026-08-19T15:37:39.707 [PlatUpd] Powershell module update completed: ConfigDefender -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\ConfigDefender 2026-08-19T15:37:39.708 [PlatUpd] Powershell module update started: ConfigDefenderPerformance -> C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ConfigDefenderPerformance 2026-08-19T15:37:39.709 [PlatUpd] Powershell module update completed: ConfigDefenderPerformance -> C:\Windows\system32\WindowsPowerShell\v1.0\Modules\ConfigDefenderPerformance 2026-08-19T15:37:39.709 [PlatUpd] Powershell module update started: ConfigDefenderPerformance -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\ConfigDefenderPerformance 2026-08-19T15:37:39.709 [PlatUpd] Powershell module update completed: ConfigDefenderPerformance -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\ConfigDefenderPerformance 2026-08-19T15:37:40.276 [PlatUpd] WMI repository update completed 2026-08-19T15:37:40.277 [PlatUpd] Updated SOFTWARE\Classes\CLSID\{A7C452EF-8E9F-42EB-9F2B-245613CA0DC9}\InprocServer32[(default)] from "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26050.15-0\ProtectionManagement.dll" to "%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0\ProtectionManagement.dll" 2026-08-19T15:37:40.277 [PlatUpd] Unload current WMI provider so that new instance can be loaded 2026-08-19T15:37:40.417 [PlatUpd] WMI/PS provider platform update completed 2026-08-19T15:37:40.417 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-19T15:37:40.417 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-19T15:37:40.417 MdCoreSvc is supported in this platform and OS 2026-08-19T15:37:40.417 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-19T15:37:40.417 [PlatUpd] Updated service binary of MDCoreSvc from "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\MpDefenderCoreService.exe" to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpDefenderCoreService.exe" 2026-08-19T15:37:40.417 [PlatUpd] Because we updated service binary, and MdCoreSvc service was already running, we need to restart the service 2026-08-19T15:37:41.540 [PlatUpd] Firewall rules updated for %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MsMpEng.exe 2026-08-19T15:37:41.540 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0): 11 items checked, 7 required update. hrMui: 0x1 hrEtw: 0 2026-08-19T15:37:41.540 [PlatUpd] Stage 1 - NewLocation updated from C:\Windows\SystemTemp\92AED081-C476-4DBE-B4B2-5355EDE3C067 to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 to indicate we are in the middle of an update 2026-08-19T15:37:41.540 [PlatUpd] Stage 1 - Service binary path updated to "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MsMpEng.exe". 2026-08-19T15:37:41.540 [PlatUpd] Stage 1 - Removed BlockedLocation [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0] to indicate we are loaded successfully. 2026-08-19T15:37:41.578 Task(-RestartService) launched as PPL process 2026-08-19T15:37:41.578 MpPostPlatformUpdate is requesting a service restart. We will abort the current service start -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-19-2026 15:37:41 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/19/2026 15:37:41.810055900 UTC (128515 ms since boot) 2026-08-19T15:37:41.803 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-19T15:37:41.818 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:37:41.818 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:37:41.818 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260819-153741-00000003-fffffffeffffffff.bin ... 2026-08-19T15:37:41.834 [WPP] Trace session started - MpWppTracing-20260819-153741-00000003-fffffffeffffffff.bin 2026-08-19T15:37:41.834 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-19T15:37:41.834 [RbM] Rollback manager succesfully initialized. 2026-08-19T15:37:41.834 [RbM] Rollback manager EnableRollbackManager called. 2026-08-19T15:37:41.834 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-19T15:37:41.834 [PlatUpd] Stage 2 - Service started from new location. Removed NewLocation value: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 2026-08-19T15:37:41.865 [PlatUpd] [Catalog] Installed catalog file : C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\catalogs\MpExtDeps.cat as wd_mpextdeps.cat. 2026-08-19T15:37:41.865 [PlatUpd] Stage 2 - Updated BackupLocation to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-08-19T15:37:41.881 [PlatUpd] MpRemoveMpUxRegistration failed (Ignored). hr = 0x800401f0 2026-08-19T15:37:41.881 [RbM] Platform LKG candidate becoming LKG: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0. 2026-08-19T15:37:42.178 EnsureProtectedFolderAcls(), hr = 0x0 2026-08-19T15:37:42.178 [PlatUpd] Stage 2 - ReinforceServiceAcl (hr = 0) 2026-08-19T15:37:42.178 [PlatUpd] Stage 2 - Readded platform files to MOAC after ACL and Trust Label enforcement. hr=0 2026-08-19T15:37:42.178 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-19T15:37:45.695 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-19T15:37:45.695 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0. 2026-08-19T15:37:45.695 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-19T15:37:45.695 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-19T15:37:45.695 [PlatUpd] CSP platform update started 2026-08-19T15:37:45.695 [PlatUpd] Defender MDM CSP platform update not required 2026-08-19T15:37:45.695 [PlatUpd] WMI/PS provider platform update started 2026-08-19T15:37:45.695 [PlatUpd] WMI/PS provider platform update not required 2026-08-19T15:37:45.695 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-19T15:37:45.695 MdCoreSvc is supported in this platform and OS 2026-08-19T15:37:45.695 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-19T15:37:45.695 [PlatUpd] Starting MdCoreSvc service 2026-08-19T15:37:45.695 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0): 11 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-19T15:37:45.695 [TS] Troubleshooting mode is not available! 2026-08-19T15:37:45.695 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-19T15:37:45.695 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-19T15:37:45.710 Service is asked to be reenabled. 2026-08-19T15:37:45.773 Task(-EnableService) launched as PPL process 2026-08-19T15:37:45.773 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-19T15:37:45.773 [Service] Enabling AutoLoggers ... 2026-08-19T15:37:45.773 DefenderApiLogger stopped successfully. 2026-08-19T15:37:45.773 DefenderApiLogger stopped successfully. 2026-08-19T15:37:45.773 DefenderApiLogger started successfully. 2026-08-19T15:37:45.773 DefenderApiLoggerLowPriv started successfully. 2026-08-19T15:37:45.773 [Service] Enabling AMSI registration ... 2026-08-19T15:37:45.773 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-19T15:37:45.788 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 34464 Number of invalid entries is 0 Number of inserts issued is 1600411 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6599 Number of lookups is 109024724 Number of lookup misses is 5244854 Number of fast lookup misses is 55577750 Number of false fast lookups is 5244849 Number of invalidations is 741780 Number of maintenance invalidations is 541193 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-19T15:37:45.788 Verifying license file... 2026-08-19T15:37:45.788 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\msmplics.dll]. File not in cache (0x1) 2026-08-19T15:37:45.788 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\msmplics.dll] 2026-08-19T15:37:45.804 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-19T15:37:45.820 Loaded module#0 MpComServer. 2026-08-19T15:37:45.820 Loaded module#1 StartupPolicies. 2026-08-19T15:37:45.820 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-19T15:37:45.820 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-19T15:37:45.820 COM server initialized successfully. 2026-08-19T15:37:45.820 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-19T15:37:45.835 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll ... 2026-08-19T15:37:45.835 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll] due to PPL. 2026-08-19T15:37:45.898 [RTP] [RTP] FilterCommunicator object 0x000001965932A4B0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-19T15:37:45.913 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-19T15:37:45.913 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:37:45.913 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:37:45.913 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-19T15:37:45.913 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-19T15:37:45.913 [RTP] [RTP] FilterCommunicator object 0x000001965932A6B0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-19T15:37:45.913 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-19T15:37:45.913 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-19T15:37:45.913 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-19T15:37:45.913 [RTP] [RTP] StartCommunication 0x000001965932A4B0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-19T15:37:45.913 [init][RTP] RTPPlugin initialization completed 2026-08-19T15:37:45.913 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mpnirtp.dll] due to PPL. 2026-08-19T15:37:45.960 [RTP] [NiRTP] CNiRtpPlugin::Initialize completed successfully 2026-08-19T15:37:45.960 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-19T15:37:45.960 OS boot count = 2 2026-08-19T15:37:45.960 OS Install = 0 2026-08-19T15:37:45.976 [ManagedAgent] HooksInitialize: starting 2026-08-19T15:37:45.976 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-19T15:37:45.976 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-19T15:37:45.976 [ManagedAgent] HooksInitialize: complete 2026-08-19T15:37:46.023 [init] MpAddMpUxRegistrationForToast succeeded 2026-08-19T15:37:46.023 [KSL] Entering CKSLEngine::Initialize. 2026-08-19T15:37:46.023 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-19T15:37:46.023 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-19T15:37:46.023 [KSL] MpInstallKslD: hr=0 2026-08-19T15:37:46.023 [KSL] MpRegisterKslD: hr=0 2026-08-19T15:37:46.038 [KSL] MpStartKslD: hr=0 2026-08-19T15:37:46.038 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:37:46.038 Loading engine... 2026-08-19T15:37:46.038 Verifying engine and signature files (source: 1) ... 2026-08-19T15:37:46.038 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpengine.dll] due to PPL. 2026-08-19T15:37:46.038 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasbase.vdm] (file in cache) 2026-08-19T15:37:46.038 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasdlta.vdm] (file in cache) 2026-08-19T15:37:46.038 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavbase.vdm] (file in cache) 2026-08-19T15:37:46.038 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpavdlta.vdm] (file in cache) 2026-08-19T15:37:46.054 [Engine] IsHybridMode: 0 2026-08-19T15:37:46.054 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-19T15:37:46.070 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DD9CE4AE8DC7FBC3A51EA9CDD77C9AE507145320.bin): 0x00000002 2026-08-19T15:37:46.101 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DD9CE4AE8DC7FBC3A51EA9CDD77C9AE507145320.bin) 2026-08-19T15:37:46.101 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-19T15:37:46.101 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-19T15:37:46.101 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-19T15:37:46.101 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-19T15:38:00.159 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-19T15:38:00.159 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_AcceptedSources new=3 old7 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-19T15:38:00.174 [Engine] New active engine 00007FFB129B55E0 (no old engine). Number of active engines: 1 2026-08-19T15:38:00.174 EngineInit:Global ASOC is enabled 2026-08-19T15:38:00.174 EngineInit:ASOO is enabled for developer volumes 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:00.253 MpWriteUupSignatureVersion 1.457.196.0, hr = 0 2026-08-19T15:38:00.253 [SigStatUpd] CSignatureStatus: back to good 2026-08-19T15:38:00.253 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-19T15:38:00.284 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-19T15:38:00.284 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:38:00.284 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-19T15:38:00.284 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-19T15:38:00.284 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-19T15:38:00.315 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-19T15:38:00.315 [Plugin] Initializing RTP plugin state... 2026-08-19T15:38:00.315 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2225 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:3924 TotalHits:0 InstanceCacheInserts:14 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:2371 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-19T15:38:00.315 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-19T15:38:00.315 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8} 2026-08-19T15:38:00.315 [SCC][CID=147031_9728] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"} 2026-08-19T15:38:00.331 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:00.331 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:00.331 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:00.331 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:00.331 MdCoreSvc is supported in this platform and OS 2026-08-19T15:38:00.331 MdCoreSvc is supported in this platform and OS 2026-08-19T15:38:00.331 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-19T15:38:00.331 [PlatUpd] Starting MdCoreSvc service 2026-08-19T15:38:00.331 Engine loaded! 2026-08-19T15:38:00.331 [DLP] Create FeatureControlState instance 2026-08-19T15:38:00.331 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-19T15:38:00.331 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-19T15:38:00.331 RegisterSModeChangeListener: hr = 0x1 2026-08-19T15:38:00.331 RegisterHybridModeChangeListener: hr = 0 2026-08-19T15:38:00.346 [PlatUpd] Updated install location from C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\ to C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\ 2026-08-19T15:38:00.346 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-19T15:38:00.346 [SigReleaseHb] Initialized with Stage 0 2026-08-19T15:38:00.346 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-19T15:38:00.346 [SCC][CID=147031_9728] Initializing ... 2026-08-19T15:38:00.346 [SCC][CID=147031_9728] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-19T15:38:00.346 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-19T15:38:00.346 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-19T15:38:00.362 [NRI] Stopping NIS service ... 2026-08-19T15:38:00.362 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-19T15:38:00.362 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). 2026-08-19T15:38:00.378 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-19T15:38:00.378 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-19T15:38:00.409 Updated service WdAiNisDrv start type from: 3, to: 4 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.196.0 AV Signature Version: 1.457.196.0 ************************************************************ 2026-08-19T15:38:00.409 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-19T15:38:00.409 Trying to initialize resource usage monitoring... 2026-08-19T15:38:00.409 Resource usage Monitoring is enabled 2026-08-19T15:38:00.409 Job Notification: New process added to job (11960) 2026-08-19T15:38:00.487 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-19T15:38:00.487 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-19T15:38:00.503 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-19T15:38:00.503 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-19T15:38:00.503 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-19T15:38:00.503 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:38:00.503 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:38:00.503 [RTP] Generating the base plugin configuration ... 2026-08-19T15:38:00.503 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-19T15:38:00.503 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:38:00.503 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-19T15:38:00.503 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-19T15:38:00.503 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:38:00.503 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-19T15:38:00.503 [RTP] [RTP] StartCommunication 0x000001965932A6B0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-19T15:38:00.518 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-19T15:38:00.518 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\drivers\wd\WdNisDrv.sys 2026-08-19T15:38:00.799 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b IDynamicConfig::ReportChange value=EnableSmsEmsOnArm64_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableWDClipHelper new=0 old1 IDynamicConfig::ReportChange value=MpFC_EnableNetPromptMemscan new=0 old1 IDynamicConfig::ReportChange value=MpFC_SCC_AcceptedSources new=7 old3 IDynamicConfig::ReportChange value=MpFC_CoreSvcEnableUpdateLogging new=0 old1 IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue 2026-08-19T15:38:00.815 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_AcceptedSources new=3 old7 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-19T15:38:00.831 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-19T15:38:00.831 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-19T15:38:00.831 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:38:00.831 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-19T15:38:00.831 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-19T15:38:00.831 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:38:01.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:01.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:01.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:01.034 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:01.065 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:02.424 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:02.440 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:02.440 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:03.628 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:38:03.628 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:38:03.628 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-08-19T15:38:03.628 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-19T15:38:03.628 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-08-19T15:38:04.440 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:04.440 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:04.440 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:05.831 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\0C4B625C-3A53-4382-8668-CCC1A6F60E0B19e0.1dd2ff0b91ed5b8 2026-08-19T15:38:06.034 Verifying engine and signature files (source: 0) ... 2026-08-19T15:38:06.034 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpengine.dll] due to PPL. 2026-08-19T15:38:06.034 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasbase.vdm] (file in cache) 2026-08-19T15:38:06.034 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-19T15:38:06.049 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasdlta.vdm] 2026-08-19T15:38:06.049 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpavbase.vdm] (file in cache) 2026-08-19T15:38:06.049 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-19T15:38:06.299 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpavdlta.vdm] 2026-08-19T15:38:06.456 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:06.456 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:06.456 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:06.534 [Engine] IsHybridMode: 0 2026-08-19T15:38:06.534 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-19T15:38:06.534 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1DF37D113FFFC961F8EECE3154C101A16B95E738.bin): 0x00000002 2026-08-19T15:38:06.549 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1DF37D113FFFC961F8EECE3154C101A16B95E738.bin) 2026-08-19T15:38:06.549 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-19T15:38:06.549 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-19T15:38:06.549 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-19T15:38:06.549 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-08-19T15:38:08.471 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:08.471 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:08.471 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:10.471 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:10.471 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:10.471 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:12.487 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:12.487 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:12.487 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-19T15:38:19.924 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-19T15:38:19.924 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_SCC_AcceptedSources new=3 old7 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-19T15:38:19.924 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB129B55E0, lRefCount: 6, hr=0 2026-08-19T15:38:19.924 [Engine] New active engine 00007FFB081555E0 replacing engine 00007FFB129B55E0. Number of active engines: 2 2026-08-19T15:38:19.940 EngineInit:Global ASOC is enabled 2026-08-19T15:38:19.940 EngineInit:ASOO is enabled for developer volumes 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-19T15:38:20.003 MpWriteUupSignatureVersion 1.457.244.0, hr = 0 2026-08-19T15:38:20.003 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-19T15:38:20.034 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-19T15:38:20.034 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-19T15:38:20.034 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-19T15:38:20.034 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-19T15:38:20.034 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-19T15:38:20.049 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-19T15:38:20.049 [Plugin] Initializing RTP plugin state... 2026-08-19T15:38:20.049 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-19T15:38:20.049 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎19‎-‎2026 17:38:00 Last Perf:‎08‎-‎19‎-‎2026 17:38:00 First RTP Scan:‎08‎-‎19‎-‎2026 17:38:00 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:104 Misses:238 BM Queue:0,30,0 Proc:0,30,0 File:0,7,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:368 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:475482 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:2455 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:4483 TotalHits:683 InstanceCacheInserts:28 InstanceCacheUpdates:0 InstanceCacheDeletes:16 InstanceCacheHits:0 InstanceCacheMisses:2947 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:9ms (58/6) Success: 6, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-19T15:38:20.049 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F} 2026-08-19T15:38:20.049 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-19T15:38:20.049 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4111F5BB-D2DF-46D9-B3FF-3A78B263BBF4} removed 2026-08-19T15:38:20.049 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8}\mpasbase.vdm in use, hr=0x80070020 2026-08-19T15:38:20.049 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.049 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.049 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-19-2026 15:38:20 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-19-2026 15:38:20 2026-08-19T15:38:20.065 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-19T15:38:20.065 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-19T15:38:20.065 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:38:20.065 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-19T15:38:20.065 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T15:38:20.065 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-19T15:38:20.065 MdCoreSvc is supported in this platform and OS 2026-08-19T15:38:20.065 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-19T15:38:20.065 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-19-2026 15:38:20 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.244.0 AV Signature Version: 1.457.244.0 ************************************************************ 2026-08-19T15:38:20.065 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-19T15:38:20.065 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\0C4B625C-3A53-4382-8668-CCC1A6F60E0B19e0.1dd2ff0b91ed5b8 2026-08-19T15:38:20.143 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-19T15:38:20.143 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-19T15:38:20.518 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-19T15:38:20.518 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-19T15:38:20.518 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T15:38:20.565 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-19T15:38:20.565 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-19T15:38:20.565 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-19T15:38:20.565 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-19T15:38:20.565 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-19T15:38:20.581 [Engine] Engine 00007FFB129B55E0 no longer in use. Number of active engines: 1 2026-08-19T15:38:20.581 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:38:20.581 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-19T15:38:20.706 ProcessImageName: CCC.exe, Pid: 11380, TotalTime: 8579, Count: 87, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.DeviceProperty.Graphics.Dashboard.Shared.dll, EstimatedImpact: 79% 2026-08-19T15:38:20.706 ProcessImageName: svchost.exe, Pid: 4548, TotalTime: 1843, Count: 2, MaxTime: 1234, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-08-19T15:38:20.706 ProcessImageName: explorer.exe, Pid: 8476, TotalTime: 1577, Count: 3, MaxTime: 1281, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 26% 2026-08-19T15:38:20.706 ProcessImageName: svchost.exe, Pid: 5004, TotalTime: 311, Count: 3, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 100% 2026-08-19T15:38:20.706 ProcessImageName: brynhildr.exe, Pid: 4980, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.enc, EstimatedImpact: 0% 2026-08-19T15:38:20.737 [Engine] RSIG_UNLOADENGINE, 00007FFB129B55E0, err=0x0 2026-08-19T15:38:20.753 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6BCC090E-9705-42E3-8E0D-C2C5A758A3E8} removed 2026-08-19T15:38:22.065 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:22.065 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:38:22.065 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:38:45.799 Process scan (postsignatureupdatescan) started. 2026-08-19T15:38:46.315 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-19T15:38:46.331 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-19T15:38:48.909 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:38:48.909 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:38:48.909 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-08-19T15:38:48.909 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-19T15:38:48.909 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-08-19T15:38:49.612 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-19T15:39:06.315 Process scan (postsignatureupdatescan) completed. 2026-08-19T15:41:06.509 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1724, FileId: 0x2b000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.517 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1731, FileId: 0x2d000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.517 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1735, FileId: 0x2f000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.525 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1734, FileId: 0xb2000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.525 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1732, FileId: 0xb1000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.525 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1733, FileId: 0x2e000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1737, FileId: 0x30000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:06.565 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1736, FileId: 0xb3000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.077 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1774, FileId: 0x98000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.077 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1773, FileId: 0x420000000b6c40, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.085 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1778, FileId: 0x440000000b6c40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.085 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1772, FileId: 0x1a0000000b6c5b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.117 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1775, FileId: 0x430000000b6c40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.125 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1776, FileId: 0x99000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.149 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1779, FileId: 0x9a000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.189 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1788, FileId: 0xcd000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.197 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1790, FileId: 0x9f000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.245 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1789, FileId: 0x9e000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.245 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1771, FileId: 0x410000000b6c40, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.277 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1791, FileId: 0xce000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.293 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1794, FileId: 0xd2000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.301 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1802, FileId: 0xd5000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.301 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1801, FileId: 0xa3000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.301 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1798, FileId: 0xd3000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.301 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1800, FileId: 0xd4000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.301 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1803, FileId: 0xa4000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.309 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1799, FileId: 0xa2000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.765 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1877, FileId: 0xa7000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.765 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1876, FileId: 0xd8000000010f36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:07.773 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #1878, FileId: 0xa8000000034a80, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:09.001 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2056, FileId: 0x180000000b6c68, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:09.001 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2055, FileId: 0x140000000b6c69, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:09.009 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2057, FileId: 0x150000000b6c69, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:10.345 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\852bda35-3092-4fd5-b551-44648905a9a9. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #2193, FileId: 0x5d00000000accc, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:10.353 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2195, FileId: 0x29000000034306, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.697 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2233, FileId: 0x40000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.697 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2235, FileId: 0x17000000058eaa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.697 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2237, FileId: 0x1d000000058eaa, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.697 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2239, FileId: 0x4b000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.705 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2232, FileId: 0x3f000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.705 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2234, FileId: 0x44000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.705 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2238, FileId: 0x4a000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:11.721 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2236, FileId: 0x48000000034e2b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:12.370 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #2276, FileId: 0x1c0000000b6c5b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:12.378 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\982a89df-b493-49cd-a1bf-5412a3b10c30. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #2275, FileId: 0xf40000000033bf, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:15.828 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj39E392928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2452, FileId: 0x4700000000eb4e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:15.828 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj052619957. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2484, FileId: 0x160000000b6ca7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:15.836 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7B7A469BF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2451, FileId: 0x160000000b6ca6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.264 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj11F99B9FF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2449, FileId: 0x150000000b6ca6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.264 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj05FC5E93E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2476, FileId: 0x4a00000000eb4e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.326 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4B8C6A9D7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2500, FileId: 0x1c0000000b6ca6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.483 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0E94D79CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2518, FileId: 0x23000000090333, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.717 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj626A4395C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2511, FileId: 0x2e000000034306, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.819 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3F0087982. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2533, FileId: 0x194000000002872, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:16.975 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj249E3C90A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2542, FileId: 0x1c00000000b4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:18.356 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj758E9199E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2611, FileId: 0x670000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:18.380 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj90A497905. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2612, FileId: 0x560000000092f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:18.864 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1515E99AC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2634, FileId: 0x690000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.127 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBC7ABE928. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2650, FileId: 0x1230000000028e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.229 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE3B15997A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2654, FileId: 0x1240000000028e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.231 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj781CCA9A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2655, FileId: 0xfd000000000eb9, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.280 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9D82BD9B6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2657, FileId: 0x1250000000028e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.491 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5B43CE9CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2674, FileId: 0x8d000000007373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.569 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj87F1A69EC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2680, FileId: 0x94000000004a41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.569 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8C5EE5908. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2678, FileId: 0x93000000004a41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.662 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj29591F989. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2686, FileId: 0x95000000004a41, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.968 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj55DDF7996. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2698, FileId: 0x12b0000000028e8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.990 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2D419C9C6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2702, FileId: 0x8e000000007373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.990 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEBF36899C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2703, FileId: 0x8f000000007373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:19.990 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDC8D549AF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2697, FileId: 0x2d700000000031e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.021 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBA224897F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2708, FileId: 0x90000000007373, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.099 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB319B9907. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2714, FileId: 0x114000000008302, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.287 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj16A18D98A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2721, FileId: 0x115000000008302, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.630 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjEBDF59959. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2746, FileId: 0x14e00000000a629, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.708 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9E70989EA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2751, FileId: 0x14f00000000a629, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.755 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4FDC569A8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2754, FileId: 0x15000000000a629, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:20.974 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1498AC90D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2763, FileId: 0x15200000000a629, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.224 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj483E6E939. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2776, FileId: 0x11d000000008302, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.255 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj02189596A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2777, FileId: 0x770000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.287 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5AE936994. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2779, FileId: 0x780000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.302 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E4AEA974. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2783, FileId: 0x790000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.333 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj17DC5D9F5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2786, FileId: 0x7a0000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.412 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0D7C4996D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2791, FileId: 0x7b0000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.472 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj55E7DE955. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2800, FileId: 0x7c0000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.824 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD733C5956. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2821, FileId: 0xe0000000005189, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:21.871 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj49231797C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #2827, FileId: 0x7f0000000092d0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:29.357 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #3083, FileId: 0x2d000000011a12, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:29.779 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #3094, FileId: 0x130000000b6ca2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:36.701 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #3170, FileId: 0x150000000b6c97, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:41:39.685 Bm signature throttled:0x00002db31bed458f 2026-08-19T15:41:39.732 Bm signature throttled:0x00002db31bed458f 2026-08-19T15:41:42.826 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #3276, FileId: 0x310000000068ac, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x19e79d18 2026-08-19T15:42:19.951 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-19T15:42:19.951 [RTP] 5 newly mounted volumes accumulated, forcing a config update ... 2026-08-19T15:42:19.951 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:42:19.951 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:42:19.951 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-19T15:42:19.951 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-19T15:42:19.951 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-19T15:42:20.373 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-19T15:42:20.638 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-19T15:42:20.966 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-08-19T15:42:29.341 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5562 units 2026-08-19T15:42:30.123 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8528, FileId: 0x1cb000000006c10, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:42:43.154 [RTP] [Mini-filter] OpenWithoutRead notification (420, 11468, \Device\HarddiskVolume3\Windows\System32\wbem\WMIADAP.exe) sent successfully. 2026-08-19T15:43:00.357 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T15:43:19.998 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-19T15:47:56.544 [AutoPurge] Cleanup Routine tasks have started. 2026-08-19T15:47:56.544 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-08-19T15:47:56.544 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-08-19T15:47:56.544 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:08-19-2026 15:47:56 2026-08-19T15:47:56.560 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20936, FileId: 0x2700000000b4f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-19-2026 15:47:56 2026-08-19T15:47:56.560 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-08-19T15:47:56.560 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 ... 2026-08-19T15:47:56.560 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-08-19T15:47:56.560 [PlatUpd] Deleting orphaned platform update directory C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0 ... 2026-08-19T15:47:56.716 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-08-19T15:47:56.716 [AutoPurge] Cleanup Routine tasks have ended. 2026-08-19T15:47:59.373 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:ED590E2E-BA7C-4F26-9943-A880A046BCE4, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-19T15:47:59.373 Scheduled scan with Id ED590E2E-BA7C-4F26-9943-A880A046BCE4 configured CPU priority: normal (LowCpuPriority: 0) 2026-08-19T15:47:59.373 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-19T15:47:59.373 [SFC] System file cache build is not needed (already completed) 2026-08-19T15:48:00.169 [AutoPurge] Routine task for Cache Maintenance has started. 2026-08-19T15:48:00.185 [AutoPurge] Routine task for Cache Maintenance ... 2026-08-19T15:48:00.185 [AutoPurge] Routine task for MpSFCBuild ... 2026-08-19T15:48:00.185 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-08-19T15:48:00.185 [AutoPurge] MpSignalMaintenanceMode ... 2026-08-19T15:48:00.310 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libaudiobargraph_a_plugin.dll", hr=0x0 2026-08-19T15:48:00.357 Timer callback: Initializating/verifying scheduled tasks ... 2026-08-19T15:48:00.357 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-08-19T15:48:00.498 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\misc\libgnutls_plugin.dll", hr=0x0 2026-08-19T15:48:00.560 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 41925754(ms) from now at 05:26 (03:26 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-19T15:48:00.607 Engine:Setting original file name "grb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\grb.rs.mui", hr=0x0 2026-08-19T15:48:00.701 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_pl-pl_4e97c380224fe5bf\pl-pl_bitlockertogo.exe.mui", hr=0x0 2026-08-19T15:48:00.716 Engine:Setting original file name "powershell.exe" for "c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-08-19T15:48:00.779 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-t..iprovider.resources_31bf3856ad364e35_10.0.22000.1_de-de_f2163101a039bd0d\rdpsign.exe.mui", hr=0x0 2026-08-19T15:48:00.857 Engine:Setting original file name "atiuxpag.dll" for "c:\windows\system32\atiuxp64.dll", hr=0x800710da 2026-08-19T15:48:00.873 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_synch_l1_1_0.dll", hr=0x0 2026-08-19T15:48:01.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libextract_plugin.dll", hr=0x0 2026-08-19T15:48:01.373 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:48:01.388 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:48:01.388 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:48:01.451 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x0 2026-08-19T15:48:01.451 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-08-19T15:48:01.701 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_smem_plugin.dll", hr=0x0 2026-08-19T15:48:01.919 Engine:Setting original file name "bluetooth.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\665dc8659816c4b74a6b6286f2d19fbf\bthprops.cpl.mui", hr=0x0 2026-08-19T15:48:02.388 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:48:02.716 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-08-19T15:48:02.794 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-08-19T15:48:02.810 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-08-19T15:48:03.435 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-08-19T15:48:03.513 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-08-19T15:48:03.623 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-19T15:48:03.638 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-08-19T15:48:03.810 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-08-19T15:48:03.857 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-08-19T15:48:03.919 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-08-19T15:48:03.966 Engine:Setting original file name "accbdc.dll" for "c:\program files\microsoft office\root\vfs\windows\assembly\gac_64\microsoft.office.access.businessdatacatalog\16.0.0.0__71e9bce111e9429c\microsoft.office.access.businessdatacatalog.dll", hr=0x800710da 2026-08-19T15:48:04.076 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-08-19T15:48:04.248 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-08-19T15:48:04.388 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-08-19T15:48:04.544 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-08-19T15:48:04.560 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:04.591 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-08-19T15:48:04.685 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-08-19T15:48:04.732 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-08-19T15:48:05.279 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-08-19T15:48:05.529 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-08-19T15:48:05.560 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-08-19T15:48:05.857 Job Notification: New process added to job (7248) 2026-08-19T15:48:05.935 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-08-19T15:48:06.123 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-08-19T15:48:06.576 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-19T15:48:06.591 Job Notification: New process added to job (7544) 2026-08-19T15:48:06.591 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:7248] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:7544]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-19T15:48:06.763 Job Notification: New process added to job (2332) 2026-08-19T15:48:06.779 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-19T15:48:06.779 Job Notification: New process added to job (10220) 2026-08-19T15:48:06.794 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:2332] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10220]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-19T15:48:06.904 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:06.935 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-19T15:48:07.029 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:07.310 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-08-19T15:48:07.435 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-08-19T15:48:07.623 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-08-19T15:48:07.873 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-08-19T15:48:07.966 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-08-19T15:48:07.982 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-08-19T15:48:08.029 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-19T15:48:08.060 Aggressive catchup quick scan threshold: 2404622760078 / 25920000000000 2026-08-19T15:48:08.248 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-08-19T15:48:08.326 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-08-19T15:48:08.419 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-19T15:48:08.419 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:48:08.419 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:48:08.419 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-19T15:48:08.419 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:48:08.419 [RTP] No config change detected. Not updating plugin configuration. 2026-08-19T15:48:08.419 [RTP] No config changes found. No configuration switch. 2026-08-19T15:48:08.419 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-19T15:48:08.498 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-cryptuiwizard-dll_31bf3856ad364e35_10.0.22000.653_none_b669db893df55d5d\cryptuiwizard.dll.mun", hr=0x800710da 2026-08-19T15:48:08.638 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-08-19T15:48:09.263 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-08-19T15:48:09.294 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-08-19T15:48:09.623 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-08-19T15:48:09.701 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-08-19T15:48:10.357 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-08-19T15:48:10.419 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-08-19T15:48:10.435 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-08-19T15:48:10.451 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-08-19T15:48:10.560 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-08-19T15:48:10.654 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-08-19T15:48:10.794 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-08-19T15:48:11.216 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-08-19T15:48:11.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-08-19T15:48:11.716 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:11.748 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2620.102.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-08-19T15:48:11.810 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-08-19T15:48:11.951 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-08-19T15:48:12.013 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-08-19T15:48:12.029 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-08-19T15:48:12.044 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-08-19T15:48:12.341 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-themecpl_31bf3856ad364e35_10.0.22000.708_none_f25033ff8b8abbac\themecpl.dll.mun", hr=0x800710da 2026-08-19T15:48:12.638 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-08-19T15:48:12.638 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-08-19T15:48:12.810 Job Notification: Process exited from job (2332) 2026-08-19T15:48:12.810 Job Notification: Process exited from job (10220) 2026-08-19T15:48:12.841 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-08-19T15:48:12.888 Job Notification: Process exited from job (7248) 2026-08-19T15:48:12.904 Job Notification: Process exited from job (7544) 2026-08-19T15:48:13.263 Engine:Setting original file name "Annot.api" for "c:\program files\adobe\acrobat dc\acrobat\plug_ins\annots.api", hr=0x800710da 2026-08-19T15:48:13.451 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-08-19T15:48:13.669 Engine:Setting original file name "metrocnv.dll" for "c:\program files\microsoft office\root\office16\wordcnv.dll", hr=0x800710da 2026-08-19T15:48:13.779 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-08-19T15:48:13.857 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-08-19T15:48:14.154 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack.resources_31bf3856ad364e35_11.0.22000.1_de-de_62c7dd3adf60d646\ieadvpack.dll.mui", hr=0x800710da 2026-08-19T15:48:14.185 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-08-19T15:48:14.544 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-08-19T15:48:14.638 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-08-19T15:48:14.654 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-08-19T15:48:14.732 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-08-19T15:48:14.748 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-08-19T15:48:14.779 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-08-19T15:48:15.201 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-08-19T15:48:15.263 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-19T15:48:15.373 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-08-19T15:48:15.419 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-08-19T15:48:15.607 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edgewebview\application\151.0.4129.86\dual_engine_adapter_x64.dll", hr=0x800710da 2026-08-19T15:48:15.669 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-08-19T15:48:15.998 Engine:Setting original file name "secinit" for "c:\windows\winsxs\wow64_microsoft-windows-secinit.resources_31bf3856ad364e35_10.0.22000.1_de-de_347266eadfe8fb70\secinit.exe.mui", hr=0x800710da 2026-08-19T15:48:16.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-08-19T15:48:16.107 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-08-19T15:48:16.263 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-08-19T15:48:16.607 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:16.919 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-08-19T15:48:16.982 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-08-19T15:48:16.998 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:17.091 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:17.607 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:17.732 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:18.091 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\winsxs\amd64_microsoft-windows-s..rationmanagement-ui_31bf3856ad364e35_10.0.22000.2360_none_db38d1a2fe57b8de\wsecedit.dll.mun", hr=0x800710da 2026-08-19T15:48:18.123 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-08-19T15:48:18.294 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-08-19T15:48:18.388 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-08-19T15:48:18.435 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-08-19T15:48:18.451 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-08-19T15:48:18.794 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-08-19T15:48:18.888 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-08-19T15:48:18.982 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-08-19T15:48:19.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-08-19T15:48:19.107 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-08-19T15:48:19.232 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-08-19T15:48:19.404 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-08-19T15:48:19.529 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-08-19T15:48:19.623 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-08-19T15:48:19.638 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-08-19T15:48:19.904 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-08-19T15:48:19.919 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-08-19T15:48:20.107 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-08-19T15:48:21.966 Engine:Setting original file name "AdobeScCore.dll" for "c:\program files\adobe\acrobat dc\acrobat\sccore.dll", hr=0x800710da 2026-08-19T15:48:22.107 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-08-19T15:48:22.419 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-08-19T15:48:22.466 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-08-19T15:48:22.888 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-08-19T15:48:22.951 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-08-19T15:48:23.013 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-08-19T15:48:23.373 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-08-19T15:48:23.513 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-08-19T15:48:23.513 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-08-19T15:48:23.701 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-08-19T15:48:23.873 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-08-19T15:48:24.107 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-08-19T15:48:24.263 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-08-19T15:48:24.623 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-08-19T15:48:24.779 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-08-19T15:48:24.919 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-08-19T15:48:25.248 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai\sdk\npudetect.dll", hr=0x800710da 2026-08-19T15:48:25.373 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-08-19T15:48:25.419 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-08-19T15:48:25.560 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-n..rity-domain-clients_31bf3856ad364e35_10.0.22000.653_none_1622474f7778ce4a\ipsecsnp.dll.mun", hr=0x800710da 2026-08-19T15:48:25.576 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-08-19T15:48:25.701 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-08-19T15:48:25.779 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-08-19T15:48:25.951 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-08-19T15:48:26.076 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-08-19T15:48:26.076 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:26.388 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-08-19T15:48:26.716 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\winsxs\wow64_microsoft-windows-i..egacyshim.resources_31bf3856ad364e35_10.0.22000.1_de-de_db1ba179635e4dbe\imapi.dll.mui", hr=0x800710da 2026-08-19T15:48:26.779 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-08-19T15:48:26.841 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-19T15:48:26.966 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-08-19T15:48:27.263 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-08-19T15:48:27.341 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:27.373 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-08-19T15:48:27.482 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:28.373 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-08-19T15:48:28.513 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-08-19T15:48:28.638 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\winsxs\wow64_microsoft-onecore-a..ore-other.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab95fc8d3333238f\msacm32.drv.mui", hr=0x800710da 2026-08-19T15:48:29.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-08-19T15:48:29.107 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-08-19T15:48:29.123 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-08-19T15:48:29.466 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-08-19T15:48:29.623 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-08-19T15:48:29.669 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-08-19T15:48:29.841 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-08-19T15:48:30.029 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-08-19T15:48:30.044 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-08-19T15:48:30.326 Engine:Setting original file name "libcrypto" for "c:\program files\microsoft onedrive\26.139.0720.0007\libcrypto-3-x64.dll", hr=0x800710da 2026-08-19T15:48:30.513 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-08-19T15:48:32.623 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-08-19T15:48:33.185 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-08-19T15:48:34.607 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-19T15:48:35.201 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-08-19T15:48:35.263 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-08-19T15:48:35.263 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-08-19T15:48:35.373 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-08-19T15:48:35.435 Engine:Setting original file name "dwmscenei" for "c:\program files\microsoft office\root\office16\winappsdk\dwmscenei.dll", hr=0x800710da 2026-08-19T15:48:36.013 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-08-19T15:48:36.404 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-08-19T15:48:36.482 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-08-19T15:48:36.513 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-08-19T15:48:36.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-08-19T15:48:36.982 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-08-19T15:48:37.029 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-08-19T15:48:37.169 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:37.263 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-08-19T15:48:37.435 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-08-19T15:48:37.560 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-08-19T15:48:37.638 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-08-19T15:48:37.732 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-08-19T15:48:37.763 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-08-19T15:48:37.873 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-08-19T15:48:38.904 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-08-19T15:48:39.388 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-08-19T15:48:39.435 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-19T15:48:39.529 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-08-19T15:48:40.248 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-08-19T15:48:40.763 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-08-19T15:48:40.841 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-08-19T15:48:41.060 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-08-19T15:48:41.341 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-08-19T15:48:41.388 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-08-19T15:48:41.732 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-08-19T15:48:41.794 Engine:Setting original file name "mmcbase.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..-management-console_31bf3856ad364e35_10.0.22000.653_none_0abb1686fae5501d\mmcbase.dll.mun", hr=0x800710da 2026-08-19T15:48:41.857 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-08-19T15:48:41.904 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-08-19T15:48:42.013 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-08-19T15:48:42.576 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:48:42.873 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-08-19T15:48:42.951 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-08-19T15:48:43.560 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-19T15:48:43.873 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-08-19T15:48:44.029 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-08-19T15:48:44.388 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-08-19T15:48:44.482 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:44.529 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-08-19T15:48:44.529 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:44.591 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-08-19T15:48:44.701 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-08-19T15:48:44.779 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-08-19T15:48:44.857 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-08-19T15:48:44.982 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-08-19T15:48:45.013 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-08-19T15:48:45.029 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-08-19T15:48:45.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-08-19T15:48:45.107 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-08-19T15:48:45.451 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-19T15:48:45.451 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-08-19T15:48:45.498 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-08-19T15:48:45.591 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-08-19T15:48:45.716 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-08-19T15:48:45.951 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-08-19T15:48:46.248 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:48:46.529 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-08-19T15:48:46.685 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-08-19T15:48:46.763 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:47.169 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-moricons_31bf3856ad364e35_10.0.22000.1_none_3b5e861fe96a031e\moricons.dll.mun", hr=0x800710da 2026-08-19T15:48:47.498 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-08-19T15:48:47.654 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-08-19T15:48:47.810 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-08-19T15:48:47.982 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-08-19T15:48:48.419 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-08-19T15:48:48.529 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-08-19T15:48:48.669 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-08-19T15:48:48.701 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-08-19T15:48:48.716 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-08-19T15:48:48.794 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-08-19T15:48:49.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-08-19T15:48:49.107 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-08-19T15:48:49.185 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-process-l1-1-0.dll", hr=0x800710da 2026-08-19T15:48:49.701 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-08-19T15:48:49.841 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-08-19T15:48:50.466 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-08-19T15:48:50.701 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-08-19T15:48:50.779 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-08-19T15:48:50.841 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-08-19T15:48:51.326 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-19T15:48:51.623 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-08-19T15:48:52.357 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-08-19T15:48:52.435 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\winsxs\amd64_microsoft-windows-m..console-nodemanager_31bf3856ad364e35_10.0.22000.1042_none_f97f033358978780\mmcndmgr.dll.mun", hr=0x800710da 2026-08-19T15:48:52.763 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-08-19T15:48:53.763 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-08-19T15:48:53.904 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-08-19T15:48:54.013 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-08-19T15:48:54.107 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-08-19T15:48:54.201 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-08-19T15:48:54.248 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-08-19T15:48:54.529 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-08-19T15:48:54.638 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-08-19T15:48:54.873 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-08-19T15:48:54.951 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-08-19T15:48:55.654 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-08-19T15:48:56.029 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-08-19T15:48:56.154 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:56.310 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-08-19T15:48:56.748 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-08-19T15:48:56.888 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-08-19T15:48:56.966 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-08-19T15:48:57.013 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-08-19T15:48:57.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-08-19T15:48:57.107 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:57.248 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-08-19T15:48:57.294 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-08-19T15:48:57.607 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-08-19T15:48:57.685 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-08-19T15:48:57.873 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:48:57.998 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-08-19T15:48:58.435 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-08-19T15:48:58.701 Engine:Setting original file name " " for "c:\program files (x86)\microsoft\edge\application\151.0.4129.93\dxcompiler.dll", hr=0x800710da 2026-08-19T15:48:58.732 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-08-19T15:48:58.935 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-08-19T15:48:59.263 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-08-19T15:48:59.591 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-08-19T15:48:59.669 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-08-19T15:48:59.951 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-08-19T15:49:00.404 Engine:Setting original file name "dmdskres.dll" for "c:\windows\winsxs\amd64_microsoft-windows-diskmanagement_31bf3856ad364e35_10.0.22000.653_none_fcdf812df50050c3\dmdskres.dll.mun", hr=0x800710da 2026-08-19T15:49:00.841 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-08-19T15:49:01.216 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-08-19T15:49:01.373 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-08-19T15:49:01.498 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-08-19T15:49:02.404 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-08-19T15:49:02.669 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-08-19T15:49:02.716 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-08-19T15:49:02.810 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-08-19T15:49:02.826 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-08-19T15:49:02.826 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-08-19T15:49:03.607 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-08-19T15:49:03.654 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-08-19T15:49:03.763 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-08-19T15:49:04.123 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-08-19T15:49:04.154 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-08-19T15:49:04.419 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-08-19T15:49:04.560 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-08-19T15:49:04.638 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-08-19T15:49:04.669 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-08-19T15:49:04.982 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-08-19T15:49:05.826 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-08-19T15:49:06.294 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-08-19T15:49:06.294 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-08-19T15:49:06.357 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-08-19T15:49:06.576 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-08-19T15:49:07.154 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-08-19T15:49:07.169 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-08-19T15:49:07.169 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-08-19T15:49:07.326 Engine:Setting original file name "MAPI32.DLL" for "c:\program files\microsoft office\root\office16\olmapi32.dll", hr=0x800710da 2026-08-19T15:49:07.357 Engine:Setting original file name "1E.Client.DataBridge" for "c:\program files\teamviewer\1e.client.databridge.dll", hr=0x800710da 2026-08-19T15:49:07.513 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-08-19T15:49:07.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-08-19T15:49:08.091 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-08-19T15:49:08.201 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-08-19T15:49:08.310 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-08-19T15:49:08.341 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-08-19T15:49:09.326 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-08-19T15:49:09.544 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-08-19T15:49:09.607 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-08-19T15:49:09.826 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-08-19T15:49:09.888 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-08-19T15:49:09.966 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-08-19T15:49:10.044 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:10.138 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-08-19T15:49:10.154 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-08-19T15:49:10.185 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-08-19T15:49:10.357 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-08-19T15:49:10.404 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-19T15:49:10.482 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-08-19T15:49:10.513 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-08-19T15:49:10.529 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-08-19T15:49:10.841 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-08-19T15:49:10.982 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-19T15:49:11.044 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-08-19T15:49:11.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-08-19T15:49:11.310 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-08-19T15:49:11.435 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:11.451 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:11.466 Engine:Setting original file name "scrnsave" for "c:\windows\winsxs\wow64_microsoft-windows-scrnsave.resources_31bf3856ad364e35_10.0.22000.1_de-de_00bf267f31c8d34e\scrnsave.scr.mui", hr=0x800710da 2026-08-19T15:49:11.513 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-08-19T15:49:11.794 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-08-19T15:49:12.201 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-08-19T15:49:12.310 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-08-19T15:49:12.482 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-08-19T15:49:12.607 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-19T15:49:13.107 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-08-19T15:49:13.232 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-08-19T15:49:13.310 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-08-19T15:49:13.326 Engine:Triggered AR EMS scan 2026-08-19T15:49:13.326 Engine:EMS scan for process: lsass pid: 852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.357 Engine:EMS scan for process: svchost pid: 988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.373 Engine:EMS scan for process: svchost pid: 908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.388 Engine:EMS scan for process: svchost pid: 1068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.388 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.388 Engine:EMS scan for process: svchost pid: 1288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.404 Engine:EMS scan for process: svchost pid: 1348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.404 Engine:EMS scan for process: svchost pid: 1356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.404 Engine:EMS scan for process: svchost pid: 1464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.419 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.419 Engine:EMS scan for process: svchost pid: 1520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.419 Engine:EMS scan for process: svchost pid: 1544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.419 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-08-19T15:49:13.435 Engine:EMS scan for process: svchost pid: 1584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.435 Engine:EMS scan for process: svchost pid: 1700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.435 Engine:EMS scan for process: svchost pid: 1832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.451 Engine:EMS scan for process: svchost pid: 1944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.451 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.451 Engine:EMS scan for process: svchost pid: 2064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.466 Engine:EMS scan for process: svchost pid: 2200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.466 Engine:EMS scan for process: svchost pid: 2356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.466 Engine:EMS scan for process: svchost pid: 2364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.482 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.482 Engine:EMS scan for process: svchost pid: 2512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.498 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.513 Engine:EMS scan for process: svchost pid: 2748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.513 Engine:EMS scan for process: svchost pid: 2756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.513 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.513 Engine:EMS scan for process: svchost pid: 2864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.513 Engine:EMS scan for process: svchost pid: 2944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.529 Engine:EMS scan for process: svchost pid: 2968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.529 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.544 Engine:EMS scan for process: svchost pid: 3108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.544 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.560 Engine:EMS scan for process: svchost pid: 3392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.560 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-08-19T15:49:13.560 Engine:EMS scan for process: svchost pid: 3564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.576 Engine:EMS scan for process: svchost pid: 3612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.576 Engine:EMS scan for process: svchost pid: 3660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.591 Engine:EMS scan for process: svchost pid: 3784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.607 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.623 Engine:EMS scan for process: svchost pid: 4012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.623 Engine:EMS scan for process: svchost pid: 4356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.623 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-08-19T15:49:13.623 Engine:EMS scan for process: svchost pid: 4364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.638 Engine:EMS scan for process: svchost pid: 4412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.638 Engine:EMS scan for process: svchost pid: 4420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.638 Engine:EMS scan for process: svchost pid: 4468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.654 Engine:EMS scan for process: svchost pid: 4524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.654 Engine:EMS scan for process: svchost pid: 4548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.654 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-08-19T15:49:13.685 Engine:EMS scan for process: svchost pid: 4916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.685 Engine:EMS scan for process: svchost pid: 4988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.701 Engine:EMS scan for process: svchost pid: 5004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.716 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.716 Engine:EMS scan for process: svchost pid: 5144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.716 Engine:EMS scan for process: svchost pid: 5196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.732 Engine:EMS scan for process: svchost pid: 5268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.732 Engine:EMS scan for process: dllhost pid: 6536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.732 Engine:EMS scan for process: svchost pid: 7144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.748 Engine:EMS scan for process: svchost pid: 5512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.748 Engine:EMS scan for process: svchost pid: 7364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.748 Engine:EMS scan for process: svchost pid: 7644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.763 Engine:EMS scan for process: svchost pid: 7576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.763 Engine:EMS scan for process: svchost pid: 6488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.763 Engine:EMS scan for process: svchost pid: 7788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.779 Engine:EMS scan for process: svchost pid: 2108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.779 Engine:EMS scan for process: svchost pid: 6604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.810 Engine:EMS scan for process: svchost pid: 7376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.810 Engine:EMS scan for process: svchost pid: 8256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.810 Engine:EMS scan for process: explorer pid: 8476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.904 Engine:EMS scan for process: svchost pid: 8616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.904 Engine:EMS scan for process: svchost pid: 8764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.904 Engine:EMS scan for process: svchost pid: 9052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.919 Engine:EMS scan for process: svchost pid: 9372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.919 Engine:EMS scan for process: dllhost pid: 9632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.919 Bm signature throttled:0x00002db31bed458f 2026-08-19T15:49:13.919 Engine:EMS scan for process: svchost pid: 5376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.935 Engine:EMS scan for process: svchost pid: 11080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.935 Engine:EMS scan for process: svchost pid: 11984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.935 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.951 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.951 Bm signature throttled:0x00002db31bed458f 2026-08-19T15:49:13.966 Engine:EMS scan for process: svchost pid: 9556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.982 Engine:EMS scan for process: svchost pid: 11152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.998 Engine:EMS scan for process: svchost pid: 4600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.998 Engine:EMS scan for process: svchost pid: 7316, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:49:13.998 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-08-19T15:49:14.107 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-08-19T15:49:14.123 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-08-19T15:49:14.138 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-08-19T15:49:15.279 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-08-19T15:49:15.466 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-08-19T15:49:15.560 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-08-19T15:49:15.779 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-08-19T15:49:16.138 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-08-19T15:49:16.169 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:16.779 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-08-19T15:49:16.904 Engine:Setting original file name "msdxm.ocx" for "c:\windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_10.0.22000.593_none_10daf75208ddff90\dxmasf.dll", hr=0x800710da 2026-08-19T15:49:17.326 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-08-19T15:49:17.404 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-08-19T15:49:17.544 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:17.560 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-08-19T15:49:17.701 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_flac_plugin.dll", hr=0x800710da 2026-08-19T15:49:17.841 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\windows\system32\de-de\wsepno.dll.mui", hr=0x800710da 2026-08-19T15:49:18.248 Engine:Setting original file name "iscsiexe.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a56629be7473c8fd73a9fa129c67ea10\iscsiexe.dll.mui", hr=0x800710da 2026-08-19T15:49:18.419 Engine:Setting original file name "nlsbres.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\11a533a2a1579c078648dff16787f54d\winnlsres.dll.mui", hr=0x800710da 2026-08-19T15:49:18.669 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_udp_plugin.dll", hr=0x800710da 2026-08-19T15:49:18.669 Engine:Setting original file name "hgclientservice.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\3bbe55bd039ee800ee6a295dceb66af6\hgclientservice.dll.mui", hr=0x800710da 2026-08-19T15:49:18.779 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\bcf69d5438188e70293457b0ada7ebac\aeevts.dll.mui", hr=0x800710da 2026-08-19T15:49:18.826 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\system32\devobj.dll", hr=0x800710da 2026-08-19T15:49:19.701 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\websockify\melt command websocket.vshost.exe", hr=0x800710da 2026-08-19T15:49:19.748 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libudp_plugin.dll", hr=0x800710da 2026-08-19T15:49:19.919 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\libmarq_plugin.dll", hr=0x800710da 2026-08-19T15:49:19.951 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-file-l2-1-0.dll", hr=0x800710da 2026-08-19T15:49:20.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libasf_plugin.dll", hr=0x800710da 2026-08-19T15:49:20.123 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.devices.winmd", hr=0x800710da 2026-08-19T15:49:20.357 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-08-19T15:49:21.076 Engine:Setting original file name "srprop.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-s..pertypage.resources_31bf3856ad364e35_10.0.22000.1_de-de_d550522784983fe6\srrstr.dll.mui", hr=0x800710da 2026-08-19T15:49:21.576 Engine:Setting original file name "osloader.exe" for "c:\windows\system32\winload.efi", hr=0x800710da 2026-08-19T15:49:21.591 Engine:Setting original file name "cero.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\98cdc00c482fa11e470323b59e42694c\cero.rs.mui", hr=0x800710da 2026-08-19T15:49:21.591 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-08-19T15:49:21.951 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_bridge_plugin.dll", hr=0x800710da 2026-08-19T15:49:22.091 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-08-19T15:49:22.294 Engine:Setting original file name "extractr.exe" for "c:\windows\system32\wimserv.exe", hr=0x800710da 2026-08-19T15:49:22.341 Engine:Setting original file name "AppHostNameRegistrationVerifier.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\baf91a75f57ca8730dd9a6f926a58dd0\apphostregistrationverifier.exe.mui", hr=0x800710da 2026-08-19T15:49:22.357 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-08-19T15:49:22.419 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sv-se_346b79c8fc538206\sv-se_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:22.498 Engine:Setting original file name "nsisvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-usermodensi.resources_31bf3856ad364e35_10.0.22000.1_de-de_e9a3ddd5f5be3a28_nsisvc.dll.mui_237a741f", hr=0x800710da 2026-08-19T15:49:22.623 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\misc\libxml_plugin.dll", hr=0x800710da 2026-08-19T15:49:22.779 Engine:Setting original file name "MSCOREE.DLL" for "c:\windows\winsxs\amd64_netfx-mscoree_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_3883f23c2565b28f\mscoree.tlb", hr=0x800710da 2026-08-19T15:49:22.794 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libt140_plugin.dll", hr=0x800710da 2026-08-19T15:49:22.888 Engine:Setting original file name "Mirage" for "c:\windows\winsxs\amd64_microsoft-windows-mirage.resources_31bf3856ad364e35_10.0.22000.1_de-de_ae2416e19901f019\windows.mirage.dll.mui", hr=0x800710da 2026-08-19T15:49:23.044 Engine:Setting original file name "officeimm.odf" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\office.odf", hr=0x800710da 2026-08-19T15:49:23.076 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-08-19T15:49:23.201 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.foundation.winmd", hr=0x800710da 2026-08-19T15:49:23.326 Engine:Setting original file name "SyncCenter.dll" for "c:\windows\winsxs\amd64_microsoft-windows-mobsync_31bf3856ad364e35_10.0.22000.1_none_4bb344a74e2a385b\synccenter.dll.mun", hr=0x800710da 2026-08-19T15:49:23.326 Engine:Setting original file name "EngineShared.dll.mui" for "c:\windows\system32\en-us\mccsengineshared.dll.mui", hr=0x800710da 2026-08-19T15:49:23.341 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libmpc_plugin.dll", hr=0x800710da 2026-08-19T15:49:23.466 Engine:Setting original file name ""MTF.DYNLINK"" for "c:\windows\winsxs\wow64_microsoft-windows-mtf_31bf3856ad364e35_10.0.22000.1_none_091b60229487573c\mtf.dll", hr=0x800710da 2026-08-19T15:49:23.904 Engine:Setting original file name "PhoneExperienceHost.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\phoneexperiencehost.exe", hr=0x800710da 2026-08-19T15:49:23.919 Engine:Setting original file name "Speech_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\speech\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:24.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libcvdsub_plugin.dll", hr=0x800710da 2026-08-19T15:49:24.169 Engine:Setting original file name "TAPISRV.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\165dcc7dc32c9d4c50ac41e982c83cf0\tapisrv.dll.mui", hr=0x800710da 2026-08-19T15:49:24.544 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-08-19T15:49:24.591 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_tr-tr_dd78c40feb0f83f7\tr-tr_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:24.748 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_timezone_l1_1_0.dll", hr=0x800710da 2026-08-19T15:49:24.794 Engine:Setting original file name "resutils" for "c:\windows\system32\de-de\resutils.dll.mui", hr=0x800710da 2026-08-19T15:49:24.794 Engine:Setting original file name "la57setup.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ec428185df2994f7d7954c1efe1b2738\la57setup.exe.mui", hr=0x800710da 2026-08-19T15:49:25.654 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_sysinfo_l1_1_0.dll", hr=0x800710da 2026-08-19T15:49:25.779 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_lv-lv_c622371055824f07\lv-lv_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:26.076 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\libvlc.dll", hr=0x800710da 2026-08-19T15:49:26.123 Engine:Setting original file name "pcbp.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pcbp.rs.mui", hr=0x800710da 2026-08-19T15:49:26.294 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\libaudiobargraph_v_plugin.dll", hr=0x800710da 2026-08-19T15:49:26.607 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libcrystalhd_plugin.dll", hr=0x800710da 2026-08-19T15:49:26.826 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libsimple_channel_mixer_plugin.dll", hr=0x800710da 2026-08-19T15:49:26.919 Engine:Setting original file name "BITS_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bits\el-gr\941b90f17785e60e38b52b350b0ea815\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:26.919 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_10_p010_plugin.dll", hr=0x800710da 2026-08-19T15:49:26.951 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libidummy_plugin.dll", hr=0x800710da 2026-08-19T15:49:27.279 Engine:Setting original file name "evcreate.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\3b9f72c52eae9608ccf0b7ac937854f7\eventcreate.exe.mui", hr=0x800710da 2026-08-19T15:49:27.529 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libwave_plugin.dll", hr=0x800710da 2026-08-19T15:49:27.888 Engine:Setting original file name "ASFErr.Dll.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ec43bde4126b47843ef5a0cf30d6471f\asferror.dll.mui", hr=0x800710da 2026-08-19T15:49:27.888 Engine:Setting original file name "winnt" for "c:\windows\system32\de-de\adsnt.dll.mui", hr=0x800710da 2026-08-19T15:49:28.060 Engine:Setting original file name "Apphelp" for "c:\windows\syswow64\apphelp.dll", hr=0x800710da 2026-08-19T15:49:28.498 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libripple_plugin.dll", hr=0x800710da 2026-08-19T15:49:28.685 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libposterize_plugin.dll", hr=0x800710da 2026-08-19T15:49:28.685 Engine:Setting original file name "c2wtsres" for "c:\windows\winsxs\amd64_c2wtsres.resources_31bf3856ad364e35_10.0.22000.1_de-de_894fd8770015f17e\c2wtsres.dll.mui", hr=0x800710da 2026-08-19T15:49:29.013 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\he-il_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:29.373 Engine:Setting original file name "davsvc.dll.mui" for "c:\windows\system32\de-de\webclnt.dll.mui", hr=0x800710da 2026-08-19T15:49:29.419 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-08-19T15:49:29.466 Engine:Setting original file name "mscxpl32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a5e0e586a01cc984f654761a81ef508e\mscpxl32.dll.mui", hr=0x800710da 2026-08-19T15:49:29.576 Engine:Setting original file name "Power_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\power\de-de\797b6e868207f55b4ec1c073c9864371\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:29.951 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_private_l1_1_0.dll", hr=0x800710da 2026-08-19T15:49:29.966 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libyuv_plugin.dll", hr=0x800710da 2026-08-19T15:49:30.044 Engine:Setting original file name "SharedPC.CredentialProvider.dll.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\18f29df98b1c0fc0de40c5ffd4dcc5db\windows.sharedpc.credentialprovider.dll.mui", hr=0x800710da 2026-08-19T15:49:30.076 Engine:Setting original file name "opnfiles.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7a7a0c4823d85684e9d948f6e8e2a7bf\openfiles.exe.mui", hr=0x800710da 2026-08-19T15:49:30.107 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.ui.winmd", hr=0x800710da 2026-08-19T15:49:30.373 Engine:Setting original file name "d2d1" for "c:\windows\system32\d2d1.dll", hr=0x800710da 2026-08-19T15:49:30.419 Engine:Setting original file name "HvsiEvaluator.dll" for "c:\windows\system32\hvsigpext.dll", hr=0x800710da 2026-08-19T15:49:30.607 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libpsychedelic_plugin.dll", hr=0x800710da 2026-08-19T15:49:30.966 Engine:Setting original file name "System.EnterpriseServices.dll" for "c:\windows\microsoft.net\framework64\v2.0.50727\system.enterpriseservices.tlb", hr=0x800710da 2026-08-19T15:49:31.091 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libscene_plugin.dll", hr=0x800710da 2026-08-19T15:49:31.326 Engine:Setting original file name "F12Chooser.exe.mui" for "c:\windows\system32\f12\de-de\iechooser.exe.mui", hr=0x800710da 2026-08-19T15:49:31.466 Engine:Setting original file name "dmdskres.dll.mui" for "c:\windows\system32\de-de\dmdskres2.dll.mui", hr=0x800710da 2026-08-19T15:49:31.466 Engine:Setting original file name "MFC40.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bf8ce2a53903d9e6d302aee07de95dd9\mfc40u.dll.mui", hr=0x800710da 2026-08-19T15:49:31.607 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-08-19T15:49:31.607 Engine:Setting original file name "UsoClientImpl" for "c:\windows\uus\amd64\usoclientimpl.dll", hr=0x800710da 2026-08-19T15:49:31.654 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\47874cdd5d5fee86afcd293f7d3cfc1c\kernel32.dll.mui", hr=0x800710da 2026-08-19T15:49:32.404 Engine:Setting original file name "ir41_32.ax.mui" for "c:\windows\syswow64\de-de\ir41_32original.dll.mui", hr=0x800710da 2026-08-19T15:49:32.623 Engine:Setting original file name "msfltr32.acm" for "c:\windows\winsxs\wow64_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_10.0.22000.1_none_417dd1171a334446\msacm32.dll", hr=0x800710da 2026-08-19T15:49:32.701 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_neutral_el-gr_8wekyb3d8bbwe\el-gr\msointlimm.dll", hr=0x800710da 2026-08-19T15:49:33.216 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemux_cdg_plugin.dll", hr=0x800710da 2026-08-19T15:49:33.373 Engine:Setting original file name "MSIDENT.DLL.MUI" for "c:\windows\system32\de-de\msidntld.dll.mui", hr=0x800710da 2026-08-19T15:49:33.544 Engine:Setting original file name "fpb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d422bce5d0ee85e0e0fedd28277db936\fpb.rs.mui", hr=0x800710da 2026-08-19T15:49:33.591 Engine:Setting original file name "dnscmmc" for "c:\windows\system32\de-de\dnscmmc.dll.mui", hr=0x800710da 2026-08-19T15:49:33.638 Engine:Setting original file name "VBoxProxyStub .dll" for "c:\program files\oracle\virtualbox\vboxproxystub.dll", hr=0x800710da 2026-08-19T15:49:33.716 Engine:Setting original file name "DolbyAtmosDecMFT.dll" for "c:\windows\syswow64\dolbydecmft.dll", hr=0x800710da 2026-08-19T15:49:33.888 Engine:Setting original file name "ACTIONCENTERCPL.DLL" for "c:\windows\winsxs\amd64_microsoft-windows-healthcentercpl_31bf3856ad364e35_10.0.22000.653_none_4becb94a22e5a3ef\actioncentercpl.dll.mun", hr=0x800710da 2026-08-19T15:49:33.982 Engine:Setting original file name "Windows.Graphics.Internal.Printing.WorkflowService.dll.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56a14f59841393da2d48b6eafb2a2d61\printworkflowservice.dll.mui", hr=0x800710da 2026-08-19T15:49:34.279 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_wav_plugin.dll", hr=0x800710da 2026-08-19T15:49:34.466 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-08-19T15:49:34.576 Engine:Setting original file name "KeyboardDiagnostic_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\keyboard\el-gr\6307a8dace61e8ff6b447bca298f4be9\diagpackage.dll.mui", hr=0x800710da 2026-08-19T15:49:34.669 Engine:Setting original file name "Windows.Graphics.Internal.Printing.WorkflowService.dll.MUI" for "c:\windows\system32\de-de\printworkflowservice.dll.mui", hr=0x800710da 2026-08-19T15:49:34.748 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\system32\setup\rasmigplugin.dll", hr=0x800710da 2026-08-19T15:49:35.279 Engine:Setting original file name "imm32" for "c:\windows\system32\imm32.dll", hr=0x800710da 2026-08-19T15:49:35.544 Engine:Setting original file name "AzureAttest.dll" for "c:\windows\system32\azureattestnormal.dll", hr=0x800710da 2026-08-19T15:49:35.623 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_multibyte_l1_1_0.dll", hr=0x800710da 2026-08-19T15:49:35.654 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_lt-lt_c554c88c56040e17\lt-lt_bitlockertogo.exe.mui", hr=0x800710da 2026-08-19T15:49:35.685 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_ec721459bafff720\msprivs.dll.mui", hr=0x800710da 2026-08-19T15:49:35.763 OriginalFileName Maintenance::9795 files in Moac, 0 skipped (cached), 10 filename set 2026-08-19T15:49:35.763 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-08-19T15:50:45.763 ExpensiveFile:Scan time for `\\?\C:\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5796 units 2026-08-19T15:51:30.388 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #22997, FileId: 0x350000000100f7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:51:31.060 RPC Rundown called on ScanID: ED590E2E-BA7C-4F26-9943-A880A046BCE4 2026-08-19T15:51:31.060 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:ED590E2E-BA7C-4F26-9943-A880A046BCE4. bRemoveFromList(ClientKilled):1 2026-08-19T15:51:31.060 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ED590E2E-BA7C-4F26-9943-A880A046BCE4 2026-08-19T15:51:31.060 QuickScan:ScanID:ED590E2E-BA7C-4F26-9943-A880A046BCE4: User scan error=000003e3 2026-08-19T15:51:31.060 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ED590E2E-BA7C-4F26-9943-A880A046BCE4 2026-08-19T15:51:31.060 QuickScan:ScanID:ED590E2E-BA7C-4F26-9943-A880A046BCE4: Quick scan aborted by callback after end stage 2026-08-19T15:51:31.060 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:ED590E2E-BA7C-4F26-9943-A880A046BCE4 2026-08-19T15:51:31.060 OnDemandScanWorker: Scan Cancelled! scanId:ED590E2E-BA7C-4F26-9943-A880A046BCE4, hr = 0x80508018 2026-08-19T15:51:31.998 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #23033, FileId: 0x7b000000010115, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:51:33.060 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:51:33.076 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:51:33.076 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:51:44.591 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #23664, FileId: 0x19f0000000060c3, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:55:32.982 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:999F9C71-0DDC-4ED0-B0D4-BA4F58730012, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-19T15:55:32.982 Scheduled scan with Id 999F9C71-0DDC-4ED0-B0D4-BA4F58730012 configured CPU priority: normal (LowCpuPriority: 0) 2026-08-19T15:55:32.998 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-19T15:55:32.998 [SFC] System file cache build is not needed (already completed) 2026-08-19T15:55:34.654 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24016, FileId: 0xcb000000013de8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T15:55:35.013 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:55:35.029 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T15:55:35.029 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T15:55:37.873 Engine:Triggered AR EMS scan 2026-08-19T15:55:37.873 Engine:EMS scan for process: lsass pid: 852, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.904 Engine:EMS scan for process: svchost pid: 988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.935 Engine:EMS scan for process: svchost pid: 908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.935 Engine:EMS scan for process: svchost pid: 1068, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.935 Engine:EMS scan for process: svchost pid: 1208, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.935 Engine:EMS scan for process: svchost pid: 1288, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.951 Engine:EMS scan for process: svchost pid: 1348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.951 Engine:EMS scan for process: svchost pid: 1356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.951 Engine:EMS scan for process: svchost pid: 1464, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.966 Engine:EMS scan for process: svchost pid: 1508, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.966 Engine:EMS scan for process: svchost pid: 1520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.982 Engine:EMS scan for process: svchost pid: 1544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.982 Engine:EMS scan for process: svchost pid: 1584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.982 Engine:EMS scan for process: svchost pid: 1700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.998 Engine:EMS scan for process: svchost pid: 1832, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.998 Engine:EMS scan for process: svchost pid: 1944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.998 Engine:EMS scan for process: svchost pid: 1408, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.998 Engine:EMS scan for process: svchost pid: 2064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:37.998 Engine:EMS scan for process: svchost pid: 2200, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.013 Engine:EMS scan for process: svchost pid: 2356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.013 Engine:EMS scan for process: svchost pid: 2364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.013 Engine:EMS scan for process: svchost pid: 2468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.029 Engine:EMS scan for process: svchost pid: 2512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.029 Engine:EMS scan for process: svchost pid: 2704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.029 Engine:EMS scan for process: svchost pid: 2748, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.029 Engine:EMS scan for process: svchost pid: 2756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.029 Engine:EMS scan for process: svchost pid: 2764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.044 Engine:EMS scan for process: svchost pid: 2864, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.044 Engine:EMS scan for process: svchost pid: 2944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.044 Engine:EMS scan for process: svchost pid: 2968, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.044 Engine:EMS scan for process: svchost pid: 2280, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.060 Engine:EMS scan for process: svchost pid: 3108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.060 Engine:EMS scan for process: svchost pid: 3124, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.076 Engine:EMS scan for process: svchost pid: 3392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.076 Engine:EMS scan for process: svchost pid: 3564, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.091 Engine:EMS scan for process: svchost pid: 3612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.091 Engine:EMS scan for process: svchost pid: 3660, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.107 Engine:EMS scan for process: svchost pid: 3784, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.107 Engine:EMS scan for process: svchost pid: 3908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.107 Engine:EMS scan for process: svchost pid: 4012, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.107 Engine:EMS scan for process: svchost pid: 4356, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.123 Engine:EMS scan for process: svchost pid: 4364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.138 Engine:EMS scan for process: svchost pid: 4412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.138 Engine:EMS scan for process: svchost pid: 4420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.154 Engine:EMS scan for process: svchost pid: 4468, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.154 Engine:EMS scan for process: svchost pid: 4524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.154 Engine:EMS scan for process: svchost pid: 4548, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.185 Engine:EMS scan for process: svchost pid: 4916, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.185 Engine:EMS scan for process: svchost pid: 4988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.201 Engine:EMS scan for process: svchost pid: 5004, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.201 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.216 Engine:EMS scan for process: svchost pid: 5144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.216 Engine:EMS scan for process: svchost pid: 5196, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.232 Engine:EMS scan for process: svchost pid: 5268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.232 Engine:EMS scan for process: dllhost pid: 6536, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.232 Engine:EMS scan for process: svchost pid: 7144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.232 Engine:EMS scan for process: svchost pid: 7364, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.248 Engine:EMS scan for process: svchost pid: 7644, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.248 Engine:EMS scan for process: svchost pid: 7576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.263 Engine:EMS scan for process: svchost pid: 6488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.310 Engine:EMS scan for process: svchost pid: 7788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.310 Engine:EMS scan for process: svchost pid: 2108, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.326 Engine:EMS scan for process: svchost pid: 6604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.357 Engine:EMS scan for process: svchost pid: 7376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.357 Engine:EMS scan for process: svchost pid: 8256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.357 Engine:EMS scan for process: explorer pid: 8476, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.482 Engine:EMS scan for process: svchost pid: 8616, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.482 Engine:EMS scan for process: svchost pid: 8764, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.482 Engine:EMS scan for process: svchost pid: 9052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.498 Engine:EMS scan for process: svchost pid: 9372, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.498 Engine:EMS scan for process: dllhost pid: 9632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.498 Engine:EMS scan for process: svchost pid: 5376, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.498 Engine:EMS scan for process: svchost pid: 11080, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.513 Engine:EMS scan for process: svchost pid: 11984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.513 Engine:EMS scan for process: svchost pid: 2480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.544 Engine:EMS scan for process: svchost pid: 8544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.544 Engine:EMS scan for process: svchost pid: 9556, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:55:38.560 Engine:EMS scan for process: svchost pid: 4600, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-19T15:58:05.357 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T15:59:59.435 QuickScan:ScanID:999F9C71-0DDC-4ED0-B0D4-BA4F58730012: Quick scan finished with error 0 2026-08-19T15:59:59.966 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-19T15:59:59.966 [RTP] Duplicating the current plugin configuration object... 2026-08-19T15:59:59.966 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-19T15:59:59.966 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-19T15:59:59.966 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-19T15:59:59.966 [RTP] No config change detected. Not updating plugin configuration. 2026-08-19T15:59:59.966 [RTP] No config changes found. No configuration switch. 2026-08-19T15:59:59.966 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-19T16:00:01.466 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T16:00:01.482 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-19T16:00:01.482 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-19T16:06:40.637 Bm signature throttled:0x00002db31bed458f 2026-08-19T16:06:41.762 Bm signature throttled:0x00002db31bed458f 2026-08-19T16:07:49.929 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #40196, FileId: 0x9a000000002d16, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T16:07:51.976 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-08-19T16:07:53.351 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy6\System Volume Information\SPP\snapshot-2 2026-08-19T16:07:53.460 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy7\System Volume Information\SPP\snapshot-2 2026-08-19T16:08:05.554 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy8\pagefile.sys 2026-08-19T16:08:06.257 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy8\pagefile.sys 2026-08-19T16:13:10.346 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T16:28:06.430 Bm signature throttled:0x00002db31bed458f 2026-08-19T16:28:15.350 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T16:28:46.843 Bm signature throttled:0x00002db31bed458f 2026-08-19T16:32:11.124 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #41601, FileId: 0x9d000000002d16, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T16:35:59.031 [NRI] Successfully updated NIS service with platform settings for enforcement level Log IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=MpFC_SCC_AcceptedSources new=7 old3 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 2026-08-19T16:35:59.062 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-19T16:35:59.062 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-19T16:35:59.062 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-19T16:35:59.077 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-19T16:35:59.077 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-19T16:35:59.077 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-19T16:35:59.077 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-19T16:35:59.077 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-19T16:35:59.077 MdCoreSvc is supported in this platform and OS 2026-08-19T16:35:59.546 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-19T16:35:59.546 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-19T16:35:59.546 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-19T16:43:20.353 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T16:44:13.119 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #45524, FileId: 0x1070000000051cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T16:49:05.494 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #45559, FileId: 0x5900000000fbdb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T16:49:05.525 Bm signature throttled:0x000045b3435c1067 2026-08-19T16:49:05.525 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #45572, FileId: 0x7100000000f136, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T16:58:25.361 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T17:13:30.361 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T17:28:35.360 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-19T17:32:14.500 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #45837, FileId: 0xab0000000178fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-19T17:38:19.936 ProcessImageName: explorer.exe, Pid: 8476, TotalTime: 15406, Count: 118, MaxTime: 5562, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: setup.exe, Pid: 11564, TotalTime: 13259, Count: 604, MaxTime: 4796, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.93\msedge.dll, EstimatedImpact: 15% 2026-08-19T17:38:19.936 ProcessImageName: AggregatorHost.exe, Pid: 6320, TotalTime: 5566, Count: 144, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\win32kfull.sys, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: AcroCEF.exe, Pid: 3584, TotalTime: 4638, Count: 174, MaxTime: 406, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 30% 2026-08-19T17:38:19.936 ProcessImageName: SrTasks.exe, Pid: 2020, TotalTime: 3600, Count: 399, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{12144d5d-226d-4071-90a4-62e72600e6c5}_OnDiskSnapshotProp, EstimatedImpact: 14% 2026-08-19T17:38:19.936 ProcessImageName: DeviceCensus.exe, Pid: 7900, TotalTime: 3027, Count: 6, MaxTime: 1546, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 36% 2026-08-19T17:38:19.936 ProcessImageName: setup.exe, Pid: 3208, TotalTime: 3009, Count: 361, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.93\Locales\copilot_overlay_strings_kk.pak, EstimatedImpact: 10% 2026-08-19T17:38:19.936 ProcessImageName: firefox.exe, Pid: 9676, TotalTime: 2847, Count: 195, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\updates.xml, EstimatedImpact: 42% 2026-08-19T17:38:19.936 ProcessImageName: OneDrive.Sync.Service.exe, Pid: 6980, TotalTime: 2310, Count: 101, MaxTime: 921, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\26.139.0720.0007\OneDrive.Sync.Service.dll, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: Acrobat.exe, Pid: 6272, TotalTime: 2142, Count: 31, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatRes.dll, EstimatedImpact: 24% 2026-08-19T17:38:19.936 ProcessImageName: SDXHelper.exe, Pid: 9996, TotalTime: 1995, Count: 168, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 3% 2026-08-19T17:38:19.936 ProcessImageName: Acrobat.exe, Pid: 11184, TotalTime: 1870, Count: 9, MaxTime: 1593, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll, EstimatedImpact: 17% 2026-08-19T17:38:19.936 ProcessImageName: svchost.exe, Pid: 4508, TotalTime: 1549, Count: 50, MaxTime: 765, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DO20B.tmp, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: svchost.exe, Pid: 11196, TotalTime: 1464, Count: 10, MaxTime: 1296, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 7% 2026-08-19T17:38:19.936 ProcessImageName: WmiPrvSE.exe, Pid: 9572, TotalTime: 617, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\http.sys, EstimatedImpact: 94% 2026-08-19T17:38:19.936 ProcessImageName: sdiagnhost.exe, Pid: 4280, TotalTime: 493, Count: 25, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_cdcfa5b3-85b4-40f3-acea-46a1de123d4e\CL_Utility.ps1, EstimatedImpact: 26% 2026-08-19T17:38:19.936 ProcessImageName: powershell.exe, Pid: 7612, TotalTime: 430, Count: 32, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 17% 2026-08-19T17:38:19.936 ProcessImageName: firefox.exe, Pid: 6268, TotalTime: 421, Count: 29, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\948fbcee-087b-423d-9619-e735ebca8c41, EstimatedImpact: 5% 2026-08-19T17:38:19.936 ProcessImageName: firefox.exe, Pid: 8420, TotalTime: 420, Count: 83, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log, EstimatedImpact: 32% 2026-08-19T17:38:19.936 ProcessImageName: svchost.exe, Pid: 1508, TotalTime: 378, Count: 21, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: AdobeCollabSync.exe, Pid: 10472, TotalTime: 349, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: backgroundTaskHost.exe, Pid: 7272, TotalTime: 270, Count: 25, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\88000165\1786913770, EstimatedImpact: 21% 2026-08-19T17:38:19.936 ProcessImageName: MicrosoftEdgeUpdate.exe, Pid: 11712, TotalTime: 250, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B62919C2-5C7B-4DA7-AD85-E8CD099396A0}\MicrosoftEdge_X64_151.0.4129.93_151.0.4129.86.exe, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: PhoneExperienceHost.exe, Pid: 9316, TotalTime: 225, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: backgroundTaskHost.exe, Pid: 6520, TotalTime: 225, Count: 27, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 7% 2026-08-19T17:38:19.936 ProcessImageName: OfficeC2RClient.exe, Pid: 6284, TotalTime: 198, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll, EstimatedImpact: 2% 2026-08-19T17:38:19.936 ProcessImageName: taskhostw.exe, Pid: 2560, TotalTime: 196, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\SDIAG_cdcfa5b3-85b4-40f3-acea-46a1de123d4e\result\results.xsl->(SCRIPT0000), EstimatedImpact: 66% 2026-08-19T17:38:19.936 ProcessImageName: OfficeClickToRun.exe, Pid: 8984, TotalTime: 166, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\repoman.dll, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: MicrosoftEdge_X64_151.0.4129.93_151.0.4129.86.exe, Pid: 11580, TotalTime: 155, Count: 2, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{B62919C2-5C7B-4DA7-AD85-E8CD099396A0}\EDGEMITMP_653D0.tmp\setup.exe, EstimatedImpact: 66% 2026-08-19T17:38:19.936 ProcessImageName: SDXHelper.exe, Pid: 2424, TotalTime: 153, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll, EstimatedImpact: 3% 2026-08-19T17:38:19.936 ProcessImageName: taskhostw.exe, Pid: 3968, TotalTime: 138, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 52% 2026-08-19T17:38:19.936 ProcessImageName: dasHost.exe, Pid: 3872, TotalTime: 135, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: AdobeARM.exe, Pid: 5952, TotalTime: 105, Count: 11, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB, EstimatedImpact: 0% 2026-08-19T17:38:19.936 ProcessImageName: OfficeC2RClient.exe, Pid: 3168, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140_1.dll, EstimatedImpact: 1% 2026-08-19T17:38:19.936 ProcessImageName: MicrosoftEdge_X64_151.0.4129.93_151.0.4129.86.exe, Pid: 2440, TotalTime: 93, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{9ADA2C94-0858-43BE-9D82-6D49FAE24A91}\EDGEMITMP_A91F0.tmp\setup.exe, EstimatedImpact: 45% 2026-08-19T17:38:19.936 ProcessImageName: AcroCEF.exe, Pid: 2120, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_2, EstimatedImpact: 9% -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-20-2026 07:00:09 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/20/2026 07:00:09.488132700 UTC (13203 ms since boot) 2026-08-20T07:00:09.500 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-20T07:00:09.530 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T07:00:09.530 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T07:00:09.590 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260820-070009-00000003-fffffffeffffffff.bin ... 2026-08-20T07:00:09.745 [WPP] Trace session started - MpWppTracing-20260820-070009-00000003-fffffffeffffffff.bin 2026-08-20T07:00:09.750 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-20T07:00:09.755 [RbM] Rollback manager succesfully initialized. 2026-08-20T07:00:09.755 [RbM] Rollback manager EnableRollbackManager called. 2026-08-20T07:00:09.760 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-20T07:00:09.760 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 2026-08-20T07:00:09.765 MpWriteUupPlatformVersion 4.18.26070.9, hr = 0 2026-08-20T07:00:09.765 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-08-20T07:00:09.765 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-08-20T07:00:09.765 MdCoreSvc is supported in this platform and OS 2026-08-20T07:00:09.770 MdCoreSvc is supported in this platform and OS 2026-08-20T07:00:09.770 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-20T07:00:09.770 [PlatUpd] Starting MdCoreSvc service 2026-08-20T07:00:09.845 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0" 2026-08-20T07:00:16.080 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-20T07:00:16.080 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0. 2026-08-20T07:00:16.080 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-20T07:00:16.080 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-20T07:00:16.080 [PlatUpd] CSP platform update started 2026-08-20T07:00:16.080 [PlatUpd] Defender MDM CSP platform update not required 2026-08-20T07:00:16.080 [PlatUpd] WMI/PS provider platform update started 2026-08-20T07:00:16.080 [PlatUpd] WMI/PS provider platform update not required 2026-08-20T07:00:16.080 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-20T07:00:16.080 MdCoreSvc is supported in this platform and OS 2026-08-20T07:00:16.080 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-20T07:00:16.080 [PlatUpd] Starting MdCoreSvc service 2026-08-20T07:00:16.080 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0): 11 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-20T07:00:16.095 [TS] Troubleshooting mode is not available! 2026-08-20T07:00:16.095 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-20T07:00:16.095 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-20T07:00:16.111 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-20T07:00:16.111 [Service] Enabling AutoLoggers ... 2026-08-20T07:00:16.126 DefenderApiLoggerLowPriv started successfully. 2026-08-20T07:00:16.126 [Service] Enabling AMSI registration ... 2026-08-20T07:00:16.126 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-20T07:00:16.142 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43173 Number of invalid entries is 0 Number of inserts issued is 1609458 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6606 Number of lookups is 109144227 Number of lookup misses is 5250464 Number of fast lookup misses is 55657534 Number of false fast lookups is 5250459 Number of invalidations is 742113 Number of maintenance invalidations is 541193 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-20T07:00:16.142 Verifying license file... 2026-08-20T07:00:16.142 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\msmplics.dll] (file in cache) 2026-08-20T07:00:16.158 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-20T07:00:16.158 Loaded module#0 MpComServer. 2026-08-20T07:00:16.158 Loaded module#1 StartupPolicies. 2026-08-20T07:00:16.158 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-20T07:00:16.173 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-20T07:00:16.173 COM server initialized successfully. 2026-08-20T07:00:16.189 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-20T07:00:16.205 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll ... 2026-08-20T07:00:16.205 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll] due to PPL. 2026-08-20T07:00:16.220 [RTP] [RTP] FilterCommunicator object 0x000001D507C830C0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-20T07:00:16.236 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-20T07:00:16.236 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T07:00:16.236 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T07:00:16.236 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-20T07:00:16.236 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-20T07:00:16.236 [RTP] [RTP] FilterCommunicator object 0x000001D507C832C0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-20T07:00:16.236 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-20T07:00:16.236 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-20T07:00:16.236 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-20T07:00:16.236 [RTP] [RTP] StartCommunication 0x000001D507C830C0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-20T07:00:16.236 [init][RTP] RTPPlugin initialization completed 2026-08-20T07:00:16.236 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mpnirtp.dll] due to PPL. 2026-08-20T07:00:16.251 [RTP] [NiRTP] CNiRtpPlugin::Initialize completed successfully 2026-08-20T07:00:16.251 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-20T07:00:16.251 OS boot count = 2 2026-08-20T07:00:16.251 OS Install = 0 2026-08-20T07:00:16.267 [ManagedAgent] HooksInitialize: starting 2026-08-20T07:00:16.267 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-20T07:00:16.267 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-20T07:00:16.267 [ManagedAgent] HooksInitialize: complete 2026-08-20T07:00:16.314 [init] MpAddMpUxRegistrationForToast succeeded 2026-08-20T07:00:16.314 [KSL] Entering CKSLEngine::Initialize. 2026-08-20T07:00:16.314 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-20T07:00:16.314 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-20T07:00:16.314 [KSL] MpInstallKslD: hr=0x1 2026-08-20T07:00:16.314 [KSL] MpRegisterKslD: hr=0 2026-08-20T07:00:16.330 [KSL] MpStartKslD: hr=0 2026-08-20T07:00:16.330 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T07:00:16.330 Loading engine... 2026-08-20T07:00:16.345 Verifying engine and signature files (source: 1) ... 2026-08-20T07:00:16.345 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpengine.dll] due to PPL. 2026-08-20T07:00:16.345 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasbase.vdm] (file in cache) 2026-08-20T07:00:16.345 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasdlta.vdm] (file in cache) 2026-08-20T07:00:16.345 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpavbase.vdm] (file in cache) 2026-08-20T07:00:16.345 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpavdlta.vdm] (file in cache) 2026-08-20T07:00:16.392 [Engine] IsHybridMode: 0 2026-08-20T07:00:16.392 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-20T07:00:16.423 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-1DF37D113FFFC961F8EECE3154C101A16B95E738.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-20T07:00:23.724 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-20T07:00:23.724 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T07:00:23.739 [Engine] New active engine 00007FFB05DE55E0 (no old engine). Number of active engines: 1 2026-08-20T07:00:23.755 EngineInit:Global ASOC is enabled 2026-08-20T07:00:23.755 EngineInit:ASOO is enabled for developer volumes 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T07:00:23.849 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:00:23.864 MpWriteUupSignatureVersion 1.457.244.0, hr = 0 2026-08-20T07:00:23.880 [SigStatUpd] CSignatureStatus: back to good 2026-08-20T07:00:23.880 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-20T07:00:23.911 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-20T07:00:23.911 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T07:00:23.911 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-20T07:00:23.911 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-20T07:00:23.911 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T07:00:23.927 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-20T07:00:23.927 [Plugin] Initializing RTP plugin state... 2026-08-20T07:00:23.927 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:(null) First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,1,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3488 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:15891 TotalHits:0 InstanceCacheInserts:125 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:4112 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-20T07:00:23.927 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-20T07:00:23.942 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F} 2026-08-20T07:00:23.942 [SCC][CID=27656_1016] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"} 2026-08-20T07:00:23.942 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:00:23.942 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:00:23.942 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-20T07:00:23.942 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-20T07:00:23.942 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:00:23.942 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T07:00:23.942 MdCoreSvc is supported in this platform and OS 2026-08-20T07:00:23.942 Engine loaded! 2026-08-20T07:00:23.942 [DLP] Create FeatureControlState instance 2026-08-20T07:00:23.942 RegisterSModeChangeListener: hr = 0x1 2026-08-20T07:00:23.942 RegisterHybridModeChangeListener: hr = 0 2026-08-20T07:00:23.958 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-20T07:00:23.958 [SigReleaseHb] Initialized with Stage 0 2026-08-20T07:00:23.958 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-20T07:00:23.974 [SCC][CID=27656_1016] Initializing ... 2026-08-20T07:00:23.974 [SCC][CID=27656_1016] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-20T07:00:23.974 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-20T07:00:23.974 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-20T07:00:23.974 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-20T07:00:23.974 [NRI] Stopping NIS service ... 2026-08-20T07:00:23.974 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-20T07:00:23.974 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.244.0 AV Signature Version: 1.457.244.0 ************************************************************ 2026-08-20T07:00:23.974 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-20T07:00:23.974 Trying to initialize resource usage monitoring... 2026-08-20T07:00:23.989 Resource usage Monitoring is enabled 2026-08-20T07:00:23.989 Job Notification: New process added to job (4364) 2026-08-20T07:00:24.052 Job Notification: New process added to job (5624) 2026-08-20T07:00:24.052 Job Notification: New process added to job (5636) 2026-08-20T07:00:24.067 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-20T07:00:24.067 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-20T07:00:24.067 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:5624] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5636]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T07:00:24.083 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-20T07:00:24.083 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-20T07:00:24.083 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-20T07:00:24.083 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T07:00:24.083 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T07:00:24.083 [RTP] Generating the base plugin configuration ... 2026-08-20T07:00:24.083 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-20T07:00:24.083 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T07:00:24.083 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-20T07:00:24.083 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-20T07:00:24.083 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T07:00:24.083 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-20T07:00:24.083 [RTP] [RTP] StartCommunication 0x000001D507C832C0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-20T07:00:24.114 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-20T07:00:24.130 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_526.21100.40.0_x64__cw5n1h2txyewy\Dashboard\WebContent\node_modules\@fluentui\react\lib\components\Persona\PersonaCoin\PersonaCoin.base.js 2026-08-20T07:00:24.239 Job Notification: New process added to job (9232) 2026-08-20T07:00:24.255 Job Notification: New process added to job (9240) 2026-08-20T07:00:24.427 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b IDynamicConfig::ReportChange value=EnableSmsEmsOnArm64_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableWDClipHelper new=0 old1 IDynamicConfig::ReportChange value=EnableGetCmdComponentsV2_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableNetPromptMemscan new=0 old1 IDynamicConfig::ReportChange value=MpFC_CoreSvcEnableUpdateLogging new=0 old1 IDynamicConfig::ReportChange value=MpFC_EnforceMpUxAgentHostParentCheck new=0 old1 IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue 2026-08-20T07:00:24.442 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T07:00:24.442 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T07:00:24.442 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T07:00:24.442 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T07:00:24.442 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T07:00:24.442 [KSL] Leaving CKSLEngine::EnableKsl(0). IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T07:00:24.442 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:00:24.458 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:00:24.458 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:00:24.474 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:00:24.474 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:00:25.053 Job Notification: Process exited from job (9232) 2026-08-20T07:00:25.053 Job Notification: Process exited from job (9240) 2026-08-20T07:00:25.131 Job Notification: Process exited from job (5624) 2026-08-20T07:00:25.131 [PlatUpd] WMI MOF schema validation completed successfully 2026-08-20T07:00:25.147 Job Notification: Process exited from job (5636) 2026-08-20T07:00:27.015 [RTP] Duplicating the current plugin configuration object... 2026-08-20T07:00:27.015 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T07:00:27.015 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-08-20T07:00:27.015 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-20T07:00:27.015 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-08-20T07:00:53.671 Bm signature throttled:0x00002db31bed458f 2026-08-20T07:01:16.155 Process scan (poststartupscan) started. 2026-08-20T07:01:16.171 Process scan (poststartupscan) completed. 2026-08-20T07:01:16.655 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-20T07:01:16.655 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-20T07:01:19.233 [RTP] Duplicating the current plugin configuration object... 2026-08-20T07:01:19.233 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T07:01:19.233 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-08-20T07:01:19.233 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-20T07:01:19.233 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-08-20T07:01:27.095 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.095 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.110 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.110 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.126 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.142 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.142 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.157 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.157 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.173 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.189 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.189 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.189 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.189 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.204 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.204 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.204 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:27.220 Engine:Process 11416 will be fully monitored because of injection from C:\Windows\System32\sihost.exe 2026-08-20T07:01:43.891 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-08-20T07:01:43.891 [RTP] Duplicating the current plugin configuration object... 2026-08-20T07:01:43.891 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T07:01:43.891 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-20T07:01:43.891 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-20T07:01:43.891 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-20T07:01:43.891 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-20T07:01:44.469 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-20T07:01:44.938 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-20T07:01:45.391 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-08-20T07:01:54.110 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 6046 units 2026-08-20T07:02:12.188 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T07:02:12.188 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T07:02:12.188 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T07:02:34.281 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\44DF05CF-E45D-4D62-B801-95DE3EE47FAF668.1dd3071dee31142 2026-08-20T07:02:34.375 Verifying engine and signature files (source: 0) ... 2026-08-20T07:02:34.375 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpengine.dll] due to PPL. 2026-08-20T07:02:34.375 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasbase.vdm]. File not in cache (0x1) 2026-08-20T07:02:35.141 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasbase.vdm] 2026-08-20T07:02:35.141 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-20T07:02:35.172 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasdlta.vdm] 2026-08-20T07:02:35.172 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavbase.vdm]. File not in cache (0x1) 2026-08-20T07:02:35.516 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavbase.vdm] 2026-08-20T07:02:35.516 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-20T07:02:35.532 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavdlta.vdm] 2026-08-20T07:02:35.688 [Engine] IsHybridMode: 0 2026-08-20T07:02:35.688 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-20T07:02:35.703 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C6839E973D69494B021839139A4339BABA433447.bin): 0x00000002 2026-08-20T07:02:35.703 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C6839E973D69494B021839139A4339BABA433447.bin) 2026-08-20T07:02:35.703 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-20T07:02:35.703 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-20T07:02:35.703 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-20T07:02:35.703 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-20T07:02:45.875 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-20T07:02:45.875 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T07:02:45.891 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB05DE55E0, lRefCount: 6, hr=0 2026-08-20T07:02:45.891 [Engine] New active engine 00007FFAACE055E0 replacing engine 00007FFB05DE55E0. Number of active engines: 2 2026-08-20T07:02:45.891 EngineInit:Global ASOC is enabled 2026-08-20T07:02:45.891 EngineInit:ASOO is enabled for developer volumes 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T07:02:45.969 MpWriteUupSignatureVersion 1.457.252.0, hr = 0 2026-08-20T07:02:45.969 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-20T07:02:45.985 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-20T07:02:45.985 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T07:02:45.985 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-20T07:02:45.985 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-20T07:02:45.985 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T07:02:46.016 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-20T07:02:46.016 [Plugin] Initializing RTP plugin state... 2026-08-20T07:02:46.016 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-20T07:02:46.016 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎20‎-‎2026 09:00:24 Last Perf:‎08‎-‎20‎-‎2026 09:00:23 First RTP Scan:‎08‎-‎20‎-‎2026 09:00:24 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2270 Misses:7065 BM Queue:0,164,0 Proc:0,122,0 File:0,73,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:9522 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:16378956 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:10267 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:28510 TotalHits:24293 InstanceCacheInserts:308 InstanceCacheUpdates:0 InstanceCacheDeletes:196 InstanceCacheHits:0 InstanceCacheMisses:13361 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:4ms (506/109) Success: 109, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-20T07:02:46.016 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55} 2026-08-20T07:02:46.016 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F}\mpasbase.vdm in use, hr=0x80070020 2026-08-20T07:02:46.016 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-20T07:02:46.016 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0CFBD4A3-840F-48BB-A1BF-8C1E62E19DCD} removed 2026-08-20T07:02:46.016 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.016 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.016 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.016 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.016 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-20-2026 07:02:46 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-20-2026 07:02:46 2026-08-20T07:02:46.016 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-20T07:02:46.016 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-20T07:02:46.016 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T07:02:46.016 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-20T07:02:46.031 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T07:02:46.031 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.031 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.031 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.031 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T07:02:46.031 MdCoreSvc is supported in this platform and OS 2026-08-20T07:02:46.031 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-20T07:02:46.031 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-20-2026 07:02:46 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.252.0 AV Signature Version: 1.457.252.0 ************************************************************ 2026-08-20T07:02:46.031 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-20T07:02:46.031 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\44DF05CF-E45D-4D62-B801-95DE3EE47FAF668.1dd3071dee31142 2026-08-20T07:02:46.094 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-20T07:02:46.094 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-20T07:02:46.438 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-20T07:02:46.438 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-20T07:02:46.438 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-20T07:02:46.438 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T07:02:46.438 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T07:02:46.453 [Engine] Engine 00007FFB05DE55E0 no longer in use. Number of active engines: 1 2026-08-20T07:02:46.453 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T07:02:46.453 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-20T07:02:46.500 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T07:02:46.500 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T07:02:46.500 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T07:02:46.563 ProcessImageName: CCC.exe, Pid: 12132, TotalTime: 26223, Count: 377, MaxTime: 1390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 41% 2026-08-20T07:02:46.563 ProcessImageName: explorer.exe, Pid: 7128, TotalTime: 17323, Count: 158, MaxTime: 6046, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 28% 2026-08-20T07:02:46.563 ProcessImageName: DipAwayMode.exe, Pid: 6400, TotalTime: 2940, Count: 29, MaxTime: 453, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 45% 2026-08-20T07:02:46.563 ProcessImageName: AsPowerBar.exe, Pid: 9648, TotalTime: 2726, Count: 18, MaxTime: 1109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 37% 2026-08-20T07:02:46.563 ProcessImageName: MOM.exe, Pid: 11644, TotalTime: 1758, Count: 30, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 56% 2026-08-20T07:02:46.563 ProcessImageName: dllhost.exe, Pid: 7808, TotalTime: 1754, Count: 54, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\C1QHBR189R_105, EstimatedImpact: 72% 2026-08-20T07:02:46.563 ProcessImageName: AISuite3.exe, Pid: 6408, TotalTime: 1630, Count: 25, MaxTime: 656, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 10% 2026-08-20T07:02:46.563 ProcessImageName: svchost.exe, Pid: 3508, TotalTime: 1421, Count: 2, MaxTime: 1390, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 3% 2026-08-20T07:02:46.563 ProcessImageName: websockify.exe, Pid: 11668, TotalTime: 1019, Count: 18, MaxTime: 140, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 72% 2026-08-20T07:02:46.563 ProcessImageName: TeamViewer.exe, Pid: 8148, TotalTime: 359, Count: 2, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 7% 2026-08-20T07:02:46.563 ProcessImageName: WhatsApp.Root.exe, Pid: 6616, TotalTime: 316, Count: 37, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\1031\StructuredQuerySchema.bin, EstimatedImpact: 1% 2026-08-20T07:02:46.563 ProcessImageName: brynhildr.exe, Pid: 3996, TotalTime: 186, Count: 4, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-20T07:02:46.563 ProcessImageName: CLIStart.exe, Pid: 11604, TotalTime: 92, Count: 4, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pci.sys, EstimatedImpact: 74% 2026-08-20T07:02:46.563 ProcessImageName: runonce.exe, Pid: 9080, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\desktop.ini, EstimatedImpact: 3% 2026-08-20T07:02:46.563 ProcessImageName: svchost.exe, Pid: 6148, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\ConnectedDevicesPlatform\e0926eca9796fcb8\ActivitiesCache.db-shm, EstimatedImpact: 0% 2026-08-20T07:02:46.563 ProcessImageName: svchost.exe, Pid: 2040, TotalTime: 75, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\042DAB8CC792B670CFA0C1C9B65448D2C8F5D961, EstimatedImpact: 35% 2026-08-20T07:02:46.594 [Engine] RSIG_UNLOADENGINE, 00007FFB05DE55E0, err=0x0 2026-08-20T07:02:46.610 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0582BAA6-4361-493F-84DA-7413F380F87F} removed 2026-08-20T07:02:48.032 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T07:02:48.032 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T07:02:48.032 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T07:03:51.141 [RTP] [Mini-filter] OpenWithoutRead notification (1846, 10054, \Device\HarddiskVolume3\Windows\System32\backgroundTaskHost.exe) sent successfully. 2026-08-20T07:05:16.047 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #10465, FileId: 0x7800000000cb8c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:05:23.969 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T07:06:33.926 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10661, FileId: 0x1b90000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.067 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10667, FileId: 0x1bf0000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.082 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10668, FileId: 0x1e000000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.082 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10665, FileId: 0x1df00000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.082 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10666, FileId: 0x1be0000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.082 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10673, FileId: 0x1e200000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.098 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10672, FileId: 0x1c10000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.098 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10670, FileId: 0x1c00000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.098 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10671, FileId: 0x1e100000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.349 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #10705, FileId: 0x1c70000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:06:34.349 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\065c337a-9e3d-4f04-a573-851623c5f145. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #10707, FileId: 0x55000000041d18, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:07:45.945 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-20T07:10:23.961 Timer callback: Initializating/verifying scheduled tasks ... 2026-08-20T07:10:23.961 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-08-20T07:10:23.976 Job Notification: New process added to job (7620) 2026-08-20T07:10:23.976 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-20T07:10:23.992 Job Notification: New process added to job (5760) 2026-08-20T07:10:24.008 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:7620] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:5760]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T07:10:24.086 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 69572766(ms) from now at 04:29 (02:29 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-20T07:10:24.101 Job Notification: New process added to job (7252) 2026-08-20T07:10:24.101 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-20T07:10:24.101 Job Notification: New process added to job (8176) 2026-08-20T07:10:24.117 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:7252] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:8176]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T07:10:29.680 Job Notification: Process exited from job (7252) 2026-08-20T07:10:29.680 Job Notification: Process exited from job (8176) 2026-08-20T07:10:29.805 Job Notification: Process exited from job (7620) 2026-08-20T07:10:29.805 Job Notification: Process exited from job (5760) 2026-08-20T07:10:31.336 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #11842, FileId: 0xa40000000134de, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:11:16.180 Process scan (postsignatureupdatescan) started. 2026-08-20T07:11:19.508 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-20T07:11:35.664 Process scan (postsignatureupdatescan) completed. 2026-08-20T07:11:53.461 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #13770, FileId: 0x1e500000000fad2, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:11:55.601 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\System Volume Information\SPP\OnlineMetadataCache\{98b7b84b-a23a-4813-8109-a3622ba84049}_OnDiskSnapshotProp 2026-08-20T07:11:55.601 [RTP] 4 newly mounted volumes accumulated, forcing a config update ... 2026-08-20T07:11:55.601 [RTP] Duplicating the current plugin configuration object... 2026-08-20T07:11:55.601 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T07:11:55.601 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-20T07:11:55.601 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-20T07:11:55.601 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-20T07:11:56.930 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-08-20T07:11:57.039 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-08-20T07:11:57.086 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy1\System Volume Information\SPP\snapshot-2 2026-08-20T07:12:41.273 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4DD08E94F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14166, FileId: 0x260000000135d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.304 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3BB0CD929. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14170, FileId: 0x280000000135d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.335 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0A9E4592F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14176, FileId: 0x8d0000000135e6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.351 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4E124F992. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14168, FileId: 0x360000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.398 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjCA121798D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14175, FileId: 0x380000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.460 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj968261984. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14198, FileId: 0x3b0000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.491 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6668A4906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14225, FileId: 0x270000000135f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.569 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE51C2A9D0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14256, FileId: 0x2b0000000135f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.601 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB37971965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14259, FileId: 0x2c0000000135f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:41.616 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0951FF912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14264, FileId: 0x2d0000000135f1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:55.801 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14454, FileId: 0xd9000000013572, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:55.941 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14458, FileId: 0x28000000013594, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:12:56.160 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14462, FileId: 0x5a0000000135ca, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:13:56.254 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #14473, FileId: 0xfd000000004097, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T07:15:17.675 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #14519, FileId: 0xa10000000002fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-20-2026 14:41:48 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/20/2026 14:41:48.958292300 UTC (13671 ms since boot) 2026-08-20T14:41:48.974 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-20T14:41:49.025 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T14:41:49.025 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T14:41:49.089 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260820-144149-00000003-fffffffeffffffff.bin ... 2026-08-20T14:41:49.194 [WPP] Trace session started - MpWppTracing-20260820-144149-00000003-fffffffeffffffff.bin 2026-08-20T14:41:49.199 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-20T14:41:49.199 [RbM] Rollback manager succesfully initialized. 2026-08-20T14:41:49.199 [RbM] Rollback manager EnableRollbackManager called. 2026-08-20T14:41:49.209 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-20T14:41:49.209 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 2026-08-20T14:41:49.209 MpWriteUupPlatformVersion 4.18.26070.9, hr = 0 2026-08-20T14:41:49.209 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-08-20T14:41:49.209 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-08-20T14:41:49.214 MdCoreSvc is supported in this platform and OS 2026-08-20T14:41:49.214 MdCoreSvc is supported in this platform and OS 2026-08-20T14:41:49.214 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-20T14:41:49.214 [PlatUpd] Starting MdCoreSvc service 2026-08-20T14:41:49.279 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0" 2026-08-20T14:41:54.654 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-20T14:41:54.654 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0. 2026-08-20T14:41:54.654 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-20T14:41:54.654 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-20T14:41:54.654 [PlatUpd] CSP platform update started 2026-08-20T14:41:54.654 [PlatUpd] Defender MDM CSP platform update not required 2026-08-20T14:41:54.654 [PlatUpd] WMI/PS provider platform update started 2026-08-20T14:41:54.654 [PlatUpd] WMI/PS provider platform update not required 2026-08-20T14:41:54.654 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-20T14:41:54.654 MdCoreSvc is supported in this platform and OS 2026-08-20T14:41:54.654 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-20T14:41:54.654 [PlatUpd] Starting MdCoreSvc service 2026-08-20T14:41:54.654 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0): 11 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-20T14:41:54.669 [TS] Troubleshooting mode is not available! 2026-08-20T14:41:54.669 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-20T14:41:54.669 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-20T14:41:54.700 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-20T14:41:54.700 [Service] Enabling AutoLoggers ... 2026-08-20T14:41:54.716 DefenderApiLoggerLowPriv started successfully. 2026-08-20T14:41:54.716 [Service] Enabling AMSI registration ... 2026-08-20T14:41:54.716 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-20T14:41:54.732 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43279 Number of invalid entries is 0 Number of inserts issued is 1614012 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6613 Number of lookups is 109174425 Number of lookup misses is 5259931 Number of fast lookup misses is 55665920 Number of false fast lookups is 5259926 Number of invalidations is 746561 Number of maintenance invalidations is 541193 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-20T14:41:54.732 Verifying license file... 2026-08-20T14:41:54.732 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\msmplics.dll] (file in cache) 2026-08-20T14:41:54.763 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-20T14:41:54.763 Loaded module#0 MpComServer. 2026-08-20T14:41:54.763 Loaded module#1 StartupPolicies. 2026-08-20T14:41:54.763 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-20T14:41:54.763 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-20T14:41:54.763 COM server initialized successfully. 2026-08-20T14:41:54.794 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-20T14:41:54.810 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll ... 2026-08-20T14:41:54.810 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll] due to PPL. 2026-08-20T14:41:54.825 [RTP] [RTP] FilterCommunicator object 0x0000018A968C19B0 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-20T14:41:54.825 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-20T14:41:54.825 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T14:41:54.825 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T14:41:54.825 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-20T14:41:54.825 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-20T14:41:54.825 [RTP] [RTP] FilterCommunicator object 0x0000018A968C1BB0 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-20T14:41:54.825 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-20T14:41:54.825 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-20T14:41:54.841 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-20T14:41:54.841 [RTP] [RTP] StartCommunication 0x0000018A968C19B0 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-20T14:41:54.841 [init][RTP] RTPPlugin initialization completed 2026-08-20T14:41:54.841 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mpnirtp.dll] due to PPL. 2026-08-20T14:41:54.857 [RTP] [NiRTP] CNiRtpPlugin::Initialize completed successfully 2026-08-20T14:41:54.857 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-20T14:41:54.857 OS boot count = 2 2026-08-20T14:41:54.857 OS Install = 0 2026-08-20T14:41:54.872 [ManagedAgent] HooksInitialize: starting 2026-08-20T14:41:54.872 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-20T14:41:54.872 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-20T14:41:54.872 [ManagedAgent] HooksInitialize: complete 2026-08-20T14:41:54.919 [init] MpAddMpUxRegistrationForToast succeeded 2026-08-20T14:41:54.919 [KSL] Entering CKSLEngine::Initialize. 2026-08-20T14:41:54.919 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-20T14:41:54.919 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-20T14:41:54.919 [KSL] MpInstallKslD: hr=0x1 2026-08-20T14:41:54.919 [KSL] MpRegisterKslD: hr=0 2026-08-20T14:41:54.935 [KSL] MpStartKslD: hr=0 2026-08-20T14:41:54.935 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T14:41:54.935 Loading engine... 2026-08-20T14:41:54.950 Verifying engine and signature files (source: 1) ... 2026-08-20T14:41:54.950 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpengine.dll] due to PPL. 2026-08-20T14:41:54.950 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasbase.vdm] (file in cache) 2026-08-20T14:41:54.950 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasdlta.vdm] (file in cache) 2026-08-20T14:41:54.950 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavbase.vdm] (file in cache) 2026-08-20T14:41:54.950 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpavdlta.vdm] (file in cache) 2026-08-20T14:41:54.997 [Engine] IsHybridMode: 0 2026-08-20T14:41:54.997 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-20T14:41:55.029 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-C6839E973D69494B021839139A4339BABA433447.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-20T14:42:05.555 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-20T14:42:05.555 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T14:42:05.555 [Engine] New active engine 00007FF89FB255E0 (no old engine). Number of active engines: 1 2026-08-20T14:42:05.586 EngineInit:Global ASOC is enabled 2026-08-20T14:42:05.586 EngineInit:ASOO is enabled for developer volumes 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.794 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:42:05.810 MpWriteUupSignatureVersion 1.457.252.0, hr = 0 2026-08-20T14:42:05.810 [SigStatUpd] CSignatureStatus: back to good 2026-08-20T14:42:05.810 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-20T14:42:05.857 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T14:42:05.857 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-20T14:42:05.857 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-20T14:42:05.857 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T14:42:05.904 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-20T14:42:05.904 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-20T14:42:05.904 [Plugin] Initializing RTP plugin state... 2026-08-20T14:42:05.904 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-20T14:42:05.904 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55} 2026-08-20T14:42:05.904 [SCC][CID=30625_4740] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"} 2026-08-20T14:42:05.919 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:42:05.919 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:42:05.919 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:42:05.919 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T14:42:05.919 MdCoreSvc is supported in this platform and OS 2026-08-20T14:42:05.919 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:2,2,0 SetEngine:1,1,0 SetState:1,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3322 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:16990 TotalHits:0 InstanceCacheInserts:43 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3649 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-20T14:42:05.919 Engine loaded! 2026-08-20T14:42:05.919 [DLP] Create FeatureControlState instance 2026-08-20T14:42:05.919 RegisterSModeChangeListener: hr = 0x1 2026-08-20T14:42:05.919 RegisterHybridModeChangeListener: hr = 0 2026-08-20T14:42:05.935 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-20T14:42:05.935 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-20T14:42:05.982 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-20T14:42:05.982 [SigReleaseHb] Initialized with Stage 0 2026-08-20T14:42:05.982 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-20T14:42:05.997 [SCC][CID=30625_4740] Initializing ... 2026-08-20T14:42:05.997 [SCC][CID=30625_4740] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-20T14:42:05.997 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-20T14:42:05.997 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-20T14:42:05.997 [NRI] Stopping NIS service ... 2026-08-20T14:42:05.997 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-20T14:42:05.997 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.252.0 AV Signature Version: 1.457.252.0 ************************************************************ 2026-08-20T14:42:06.013 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-20T14:42:06.044 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-20T14:42:06.091 Trying to initialize resource usage monitoring... 2026-08-20T14:42:06.091 Resource usage Monitoring is enabled 2026-08-20T14:42:06.154 Job Notification: New process added to job (4348) 2026-08-20T14:42:06.232 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:10804] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10824]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T14:42:06.279 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-20T14:42:06.279 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-20T14:42:06.294 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-20T14:42:06.294 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-20T14:42:06.294 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-20T14:42:06.294 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T14:42:06.294 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T14:42:06.294 [RTP] Generating the base plugin configuration ... 2026-08-20T14:42:06.294 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-20T14:42:06.294 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:42:06.294 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-20T14:42:06.310 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-20T14:42:06.310 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:42:06.310 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-20T14:42:06.310 [RTP] [RTP] StartCommunication 0x0000018A968C1BB0 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-20T14:42:06.326 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-20T14:42:06.482 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\OneCoreUAPCommonProxyStub.dll 2026-08-20T14:42:06.529 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b IDynamicConfig::ReportChange value=EnableSmsEmsOnArm64_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableWDClipHelper new=0 old1 IDynamicConfig::ReportChange value=EnableGetCmdComponentsV2_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableNetPromptMemscan new=0 old1 IDynamicConfig::ReportChange value=MpFC_CoreSvcEnableUpdateLogging new=0 old1 IDynamicConfig::ReportChange value=MpFC_EnforceMpUxAgentHostParentCheck new=0 old1 IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T14:42:06.529 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T14:42:06.529 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T14:42:06.529 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T14:42:06.529 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T14:42:06.529 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T14:42:06.529 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T14:42:06.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:42:06.826 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:42:06.841 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:42:06.841 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:42:06.857 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:42:08.544 [PlatUpd] WMI MOF schema validation completed successfully 2026-08-20T14:42:09.529 [RTP] Duplicating the current plugin configuration object... 2026-08-20T14:42:09.529 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T14:42:09.529 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-08-20T14:42:09.529 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-20T14:42:09.529 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-08-20T14:42:54.742 Process scan (poststartupscan) started. 2026-08-20T14:42:54.758 Process scan (poststartupscan) completed. 2026-08-20T14:42:55.258 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-20T14:42:55.273 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-20T14:42:57.851 [RTP] Duplicating the current plugin configuration object... 2026-08-20T14:42:57.851 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T14:42:57.851 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-08-20T14:42:57.851 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-20T14:42:57.851 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 2026-08-20T14:42:59.179 Bm signature throttled:0x00002db31bed458f 2026-08-20T14:43:32.178 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-08-20T14:43:32.178 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-08-20T14:43:32.178 [RTP] Duplicating the current plugin configuration object... 2026-08-20T14:43:32.178 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T14:43:32.178 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-20T14:43:32.178 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-20T14:43:32.178 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-20T14:43:32.522 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #2705, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7133769a 2026-08-20T14:43:39.803 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-20T14:43:39.803 [Cloud] Start of cloud request. Passive mode: 0 2026-08-20T14:43:39.803 [Cloud] Queued cloud request. 2026-08-20T14:43:39.803 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-20T14:43:39.803 [Cloud] Dequeued cloud request. 2026-08-20T14:43:39.803 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-20T14:43:40.163 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a38723b93c4d8643f8cecb438af2ab50c4757c00 Dynamic Signature Compilation Timestamp:08-20-2026 14:43:27 Persistence Type:Duration Time remaining:50065408 2026-08-20T14:43:40.178 [Cloud] End of cloud request. 2026-08-20T14:43:40.178 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-08-20T14:43:40.678 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:43:41.069 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-20T14:43:41.069 [Cloud] Start of cloud request. Passive mode: 0 2026-08-20T14:43:41.069 [Cloud] Queued cloud request. 2026-08-20T14:43:41.069 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-20T14:43:41.069 [Cloud] Dequeued cloud request. 2026-08-20T14:43:41.069 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-20T14:43:41.741 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\94f82da0c2af6be7f3fbcfcffec06b284ceb580a Dynamic Signature Compilation Timestamp:08-20-2026 14:43:28 Persistence Type:Duration Time remaining:288000000 2026-08-20T14:43:41.756 RTSD:RTSD recieved, rescanning impacted resources 2026-08-20T14:43:41.756 [Cloud] End of cloud request. 2026-08-20T14:43:42.256 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:43:51.794 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:43:51.794 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T14:43:51.794 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:46:51.806 Bm signature throttled:0x00002db31bed458f 2026-08-20T14:46:54.791 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4546, FileId: 0x3400000001a187, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:47:05.607 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-20T14:47:05.983 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4657, FileId: 0x15d00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4658, FileId: 0x15e00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4659, FileId: 0x1cc0000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4660, FileId: 0x24c00000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4663, FileId: 0x196000000001a7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.184 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4664, FileId: 0x16300000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4656, FileId: 0x1ca0000000034f4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4666, FileId: 0x16400000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4667, FileId: 0x198000000001a7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4665, FileId: 0x197000000001a7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4669, FileId: 0x16600000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4661, FileId: 0x195000000001a7b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.231 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4668, FileId: 0x16500000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.246 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4662, FileId: 0x16200000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:48:33.559 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0a2f125d-e843-4c57-9a09-8cc2313b6bab. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #4689, FileId: 0x15f0000000014bb, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:51:52.812 [AutoPurge] Verification Routine tasks have started. 2026-08-20T14:51:52.812 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD. 2026-08-20T14:51:52.812 [AutoPurge] Cleanup Routine tasks have started. 2026-08-20T14:51:52.812 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T14:51:52.827 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-08-20T14:51:52.827 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 0, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:08-20-2026 14:51:52 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-20-2026 14:51:52 2026-08-20T14:51:52.843 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-08-20T14:51:52.843 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 ... 2026-08-20T14:51:52.843 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-08-20T14:51:52.843 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-08-20T14:51:52.859 [AutoPurge] Cleanup Routine tasks have ended. 2026-08-20T14:51:52.874 [AutoPurge] Routine task for Cache Maintenance has started. 2026-08-20T14:51:52.874 [AutoPurge] Routine task for Cache Maintenance ... 2026-08-20T14:51:52.874 [AutoPurge] Routine task for MpSFCBuild ... 2026-08-20T14:51:52.874 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-08-20T14:51:52.874 [AutoPurge] MpSignalMaintenanceMode ... 2026-08-20T14:51:52.874 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-08-20T14:51:52.890 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:0E7DE8A1-8BD7-4057-8554-80C314E392F8, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-20T14:51:52.890 Scheduled scan with Id 0E7DE8A1-8BD7-4057-8554-80C314E392F8 configured CPU priority: normal (LowCpuPriority: 0) 2026-08-20T14:51:52.890 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-20T14:51:52.890 [SFC] System file cache build is not needed (already completed) 2026-08-20T14:51:53.077 EnsureProtectedFolderAcls(), hr = 0x0 2026-08-20T14:51:53.093 [AutoPurge] MpReinforceServiceAcls: 0 2026-08-20T14:51:53.124 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-08-20T14:51:53.140 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-08-20T14:51:53.140 [AutoPurge] Verification Routine tasks have ended. 2026-08-20T14:51:54.187 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5463, FileId: 0x640000000102c8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:51:54.890 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:51:54.890 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T14:51:54.906 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:51:58.265 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-20T14:52:05.995 Timer callback: Initializating/verifying scheduled tasks ... 2026-08-20T14:52:05.995 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-08-20T14:52:06.010 Job Notification: New process added to job (4220) 2026-08-20T14:52:06.026 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-20T14:52:06.026 Aggressive catchup quick scan threshold: 825930321446 / 25920000000000 2026-08-20T14:52:06.026 Job Notification: New process added to job (1608) 2026-08-20T14:52:06.041 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:4220] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:1608]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T14:52:06.120 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 35148033(ms) from now at 02:37 (00:37 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-20T14:52:06.135 Job Notification: New process added to job (7692) 2026-08-20T14:52:06.151 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-20T14:52:06.151 Job Notification: New process added to job (4484) 2026-08-20T14:52:06.166 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:7692] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:4484]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-20T14:52:06.557 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-20T14:52:06.573 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:06.588 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 2 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 4096 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 4 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 8 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 16 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 2048 2026-08-20T14:52:06.588 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-20T14:52:06.588 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T14:52:06.588 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T14:52:06.588 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-20T14:52:06.588 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-20T14:52:06.588 [RTP] [RtpConfig] Config change detected, type: 64 2026-08-20T14:52:06.588 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:06.588 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:06.604 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:09.166 [RTP] Duplicating the current plugin configuration object... 2026-08-20T14:52:09.166 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T14:52:09.166 [RTP] Updating plugin configuration due to recent config changes (0x43e) ... 2026-08-20T14:52:09.166 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:52:09.166 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-20T14:52:09.166 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x43e, Changed: 0x208 2026-08-20T14:52:18.234 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\29A42F0A-C90A-4789-BAFC-75A1945E173A828.1dd30b37dca9be3 2026-08-20T14:52:18.344 Verifying engine and signature files (source: 0) ... 2026-08-20T14:52:18.344 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpengine.dll] due to PPL. 2026-08-20T14:52:18.344 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpasbase.vdm]. File not in cache (0x1) 2026-08-20T14:52:19.156 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpasbase.vdm] 2026-08-20T14:52:19.156 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-20T14:52:19.172 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpasdlta.vdm] 2026-08-20T14:52:19.172 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpavbase.vdm]. File not in cache (0x1) 2026-08-20T14:52:19.531 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpavbase.vdm] 2026-08-20T14:52:19.531 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-20T14:52:19.547 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A}\mpavdlta.vdm] 2026-08-20T14:52:19.750 [Engine] IsHybridMode: 0 2026-08-20T14:52:19.750 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-20T14:52:19.750 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D7A60B7529CFA42E9E1591492D27B1258132FDE3.bin): 0x00000002 2026-08-20T14:52:19.766 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-D7A60B7529CFA42E9E1591492D27B1258132FDE3.bin) 2026-08-20T14:52:19.766 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-20T14:52:19.766 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-20T14:52:19.766 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-20T14:52:19.766 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-20T14:52:30.811 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-20T14:52:30.811 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T14:52:30.826 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF89FB255E0, lRefCount: 10, hr=0 2026-08-20T14:52:30.826 [Engine] New active engine 00007FF83D3955E0 replacing engine 00007FF89FB255E0. Number of active engines: 2 2026-08-20T14:52:30.826 EngineInit:Global ASOC is enabled 2026-08-20T14:52:30.826 EngineInit:ASOO is enabled for developer volumes 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T14:52:30.905 MpWriteUupSignatureVersion 1.457.258.0, hr = 0 2026-08-20T14:52:30.905 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-20T14:52:30.936 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-20T14:52:30.936 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T14:52:30.936 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-20T14:52:30.936 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-20T14:52:30.936 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T14:52:30.951 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-20T14:52:30.951 [Plugin] Initializing RTP plugin state... 2026-08-20T14:52:30.951 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎20‎-‎2026 16:42:06 Last Perf:‎08‎-‎20‎-‎2026 16:42:05 First RTP Scan:‎08‎-‎20‎-‎2026 16:42:06 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:2153 Misses:3403 BM Queue:0,263,0 Proc:0,108,0 File:0,169,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:5790 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:13152038 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:6936 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:27513 TotalHits:27576 InstanceCacheInserts:444 InstanceCacheUpdates:0 InstanceCacheDeletes:293 InstanceCacheHits:150 InstanceCacheMisses:8135 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (717/186) Success: 186, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-20T14:52:30.951 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-20T14:52:30.967 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0C00CC0D-7DBF-47C3-B597-43B6D641BD1A} 2026-08-20T14:52:30.967 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-20T14:52:30.967 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{30B637B7-EE5F-44BF-BBFD-165A972D62CA} removed 2026-08-20T14:52:30.967 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55}\mpasbase.vdm in use, hr=0x80070020 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-20-2026 14:52:30 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-20-2026 14:52:30 2026-08-20T14:52:30.967 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:52:30.967 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-20T14:52:30.967 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-20T14:52:30.967 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-20T14:52:30.967 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.967 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-20T14:52:30.983 MdCoreSvc is supported in this platform and OS 2026-08-20T14:52:30.983 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-20T14:52:30.983 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-20-2026 14:52:30 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.258.0 AV Signature Version: 1.457.258.0 ************************************************************ 2026-08-20T14:52:30.983 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-20T14:52:30.983 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\29A42F0A-C90A-4789-BAFC-75A1945E173A828.1dd30b37dca9be3 2026-08-20T14:52:31.061 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-20T14:52:31.061 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 Signature updated via MicrosoftUpdateServer on 08-20-2026 14:52:31 ************************************************************ 2026-08-20T14:52:31.092 Job Notification: Process exited from job (7692) 2026-08-20T14:52:31.092 Job Notification: Process exited from job (4484) 2026-08-20T14:52:31.170 Job Notification: Process exited from job (4220) 2026-08-20T14:52:31.186 Job Notification: Process exited from job (1608) 2026-08-20T14:52:31.405 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-20T14:52:31.405 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-20T14:52:31.405 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-20T14:52:31.436 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-20T14:52:31.436 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-20T14:52:31.436 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-20T14:52:31.436 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-20T14:52:31.436 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-20T14:52:31.451 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:52:31.451 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-20T14:52:32.983 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:52:32.998 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T14:52:32.998 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:52:54.764 Process scan (postsignatureupdatescan) started. 2026-08-20T14:52:58.280 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-20T14:53:17.643 Process scan (postsignatureupdatescan) completed. Internal signature match:subtype=Lowfi, sigseq=0x0000B77859487154, sigsha=b5063f9ba9f5be806d35212cc733d642c9219aef, cached=false, source=0, resourceid=0x466a3311 Internal signature match:subtype=Lowfi, sigseq=0x0000B77859487154, sigsha=b5063f9ba9f5be806d35212cc733d642c9219aef, cached=false, source=0, resourceid=0x7feaa923 2026-08-20T14:53:50.596 Engine:Triggered AR EMS scan 2026-08-20T14:53:50.596 Engine:EMS scan for process: lsass pid: 772, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.658 Engine:EMS scan for process: svchost pid: 988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.690 Engine:EMS scan for process: svchost pid: 796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.705 Engine:EMS scan for process: svchost pid: 1052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.705 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.737 Engine:EMS scan for process: svchost pid: 1248, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.737 Engine:EMS scan for process: svchost pid: 1404, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.752 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.752 Engine:EMS scan for process: svchost pid: 1420, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.768 Engine:EMS scan for process: svchost pid: 1432, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.768 Engine:EMS scan for process: svchost pid: 1500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.768 Engine:EMS scan for process: svchost pid: 1520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.783 Engine:EMS scan for process: svchost pid: 1592, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.799 Engine:EMS scan for process: svchost pid: 1656, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.815 Engine:EMS scan for process: svchost pid: 1700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.815 Engine:EMS scan for process: svchost pid: 1884, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.830 Engine:EMS scan for process: svchost pid: 1944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.830 Engine:EMS scan for process: svchost pid: 2000, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.830 Engine:EMS scan for process: svchost pid: 2060, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.846 Engine:EMS scan for process: svchost pid: 2096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.846 Engine:EMS scan for process: svchost pid: 2144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.862 Engine:EMS scan for process: svchost pid: 2240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.862 Engine:EMS scan for process: svchost pid: 2328, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.862 Engine:EMS scan for process: svchost pid: 2344, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.877 Engine:EMS scan for process: svchost pid: 2352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.877 Engine:EMS scan for process: svchost pid: 2380, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.893 Engine:EMS scan for process: svchost pid: 2580, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.893 Engine:EMS scan for process: svchost pid: 2632, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.893 Engine:EMS scan for process: svchost pid: 2652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.893 Engine:EMS scan for process: svchost pid: 2672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.908 Engine:EMS scan for process: svchost pid: 2936, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.924 Engine:EMS scan for process: svchost pid: 3032, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.955 Engine:EMS scan for process: svchost pid: 3040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.987 Engine:EMS scan for process: svchost pid: 3400, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:50.987 Engine:EMS scan for process: svchost pid: 3416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.002 Engine:EMS scan for process: svchost pid: 3460, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.002 Engine:EMS scan for process: svchost pid: 3488, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.049 Engine:EMS scan for process: svchost pid: 3520, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.065 Engine:EMS scan for process: svchost pid: 3984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.080 Engine:EMS scan for process: svchost pid: 4072, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.080 Engine:EMS scan for process: svchost pid: 3268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.096 Engine:EMS scan for process: svchost pid: 2932, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.112 Engine:EMS scan for process: svchost pid: 3264, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.127 Engine:EMS scan for process: svchost pid: 4232, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.143 Engine:EMS scan for process: svchost pid: 4240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.158 Engine:EMS scan for process: svchost pid: 4292, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.158 Engine:EMS scan for process: svchost pid: 4424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.174 Engine:EMS scan for process: svchost pid: 4960, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.174 Engine:EMS scan for process: svchost pid: 5696, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.190 Engine:EMS scan for process: dllhost pid: 5732, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.190 Engine:EMS scan for process: svchost pid: 6256, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.190 Engine:EMS scan for process: svchost pid: 6388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.221 Engine:EMS scan for process: svchost pid: 6440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.315 Engine:EMS scan for process: svchost pid: 6620, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.330 Engine:EMS scan for process: svchost pid: 6680, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.330 Engine:EMS scan for process: svchost pid: 6800, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.330 Engine:EMS scan for process: svchost pid: 6020, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.346 Engine:EMS scan for process: svchost pid: 6040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.346 Engine:EMS scan for process: svchost pid: 6796, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.362 Engine:EMS scan for process: explorer pid: 7228, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.877 Engine:EMS scan for process: svchost pid: 7452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.893 Engine:EMS scan for process: svchost pid: 7544, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.924 Engine:EMS scan for process: svchost pid: 8140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.940 Engine:EMS scan for process: svchost pid: 6532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.971 Engine:EMS scan for process: svchost pid: 7540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.971 Engine:EMS scan for process: svchost pid: 8204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.987 Engine:EMS scan for process: svchost pid: 8652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:51.987 Engine:EMS scan for process: dllhost pid: 9812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.002 Engine:EMS scan for process: svchost pid: 8444, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.002 Engine:EMS scan for process: svchost pid: 10532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.002 Engine:EMS scan for process: svchost pid: 12904, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.018 Engine:EMS scan for process: svchost pid: 13164, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.049 Engine:EMS scan for process: svchost pid: 1384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.065 Engine:EMS scan for process: svchost pid: 12768, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.065 Engine:EMS scan for process: svchost pid: 12876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.096 Engine:EMS scan for process: svchost pid: 11128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.096 Engine:EMS scan for process: svchost pid: 6272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.112 Engine:EMS scan for process: svchost pid: 10244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:52.127 Engine:EMS scan for process: svchost pid: 1480, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-20T14:53:54.925 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj32B956991. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6304, FileId: 0x8f00000001b1c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:54.959 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj907D049BF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6312, FileId: 0x3b00000001ad51, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:54.959 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7764C49DE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6311, FileId: 0x13d00000001d9fb, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:54.990 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDA1FFA97D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6314, FileId: 0x9100000001b1c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.037 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjECB0329CB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6319, FileId: 0x9200000001b1c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.240 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0F684399C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6344, FileId: 0x9500000001b1c5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.334 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBFD20496E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6360, FileId: 0x23000000022881, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.443 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE1FF389DC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6363, FileId: 0x4200000001db10, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.660 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE4EEBB93B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6382, FileId: 0x24000000022881, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:55.672 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7531549BC. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6384, FileId: 0x25000000022881, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:53:56.598 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj72C3E2968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6518, FileId: 0x26000000022881, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:54:09.284 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6732, FileId: 0x8100000000478c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:54:09.455 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6734, FileId: 0x2100000001aab8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:54:09.565 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6738, FileId: 0x3e000000013566, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:55:09.926 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6742, FileId: 0x25200000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:56:56.622 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #6847, FileId: 0xac0000000002fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T14:57:30.862 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-20T14:58:41.092 QuickScan:ScanID:0E7DE8A1-8BD7-4057-8554-80C314E392F8: Quick scan finished with error 0 2026-08-20T14:58:41.107 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb53f05e7ffffffe 2026-08-20T14:58:41.107 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x32d36a6c7ffffffe 2026-08-20T14:58:41.123 UnknownTelemetryScan triggered, type: 2 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 2 resources, RtpIoavOnly: FALSE 2026-08-20T14:58:41.123 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb53f05e7ffffffe 2026-08-20T14:58:41.123 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x32d36a6c7ffffffe 2026-08-20T14:58:41.139 [Engine] Engine 00007FF89FB255E0 no longer in use. Number of active engines: 1 2026-08-20T14:58:41.264 ProcessImageName: CCC.exe, Pid: 12388, TotalTime: 26668, Count: 389, MaxTime: 1218, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 39% 2026-08-20T14:58:41.264 ProcessImageName: explorer.exe, Pid: 7228, TotalTime: 5727, Count: 17, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-08-20T14:58:41.264 ProcessImageName: httpd.exe, Pid: 7268, TotalTime: 3674, Count: 78, MaxTime: 546, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 63% 2026-08-20T14:58:41.264 ProcessImageName: AsPowerBar.exe, Pid: 11932, TotalTime: 3115, Count: 18, MaxTime: 1171, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 40% 2026-08-20T14:58:41.264 ProcessImageName: DipAwayMode.exe, Pid: 6600, TotalTime: 2599, Count: 28, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 53% 2026-08-20T14:58:41.264 ProcessImageName: xampp-control.exe, Pid: 4904, TotalTime: 2089, Count: 9, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 40% 2026-08-20T14:58:41.264 ProcessImageName: MOM.exe, Pid: 10856, TotalTime: 1649, Count: 30, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 40% 2026-08-20T14:58:41.264 ProcessImageName: AISuite3.exe, Pid: 6584, TotalTime: 1443, Count: 25, MaxTime: 609, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 11% 2026-08-20T14:58:41.264 ProcessImageName: mysqld.exe, Pid: 12860, TotalTime: 1368, Count: 115, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 68% 2026-08-20T14:58:41.264 ProcessImageName: svchost.exe, Pid: 3488, TotalTime: 1281, Count: 2, MaxTime: 1281, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-08-20T14:58:41.264 ProcessImageName: websockify.exe, Pid: 11600, TotalTime: 850, Count: 18, MaxTime: 109, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 50% 2026-08-20T14:58:41.264 ProcessImageName: WmiPrvSE.exe, Pid: 13216, TotalTime: 648, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 84% 2026-08-20T14:58:41.264 ProcessImageName: WmiPrvSE.exe, Pid: 3852, TotalTime: 495, Count: 54, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\INF\prnms012.inf, EstimatedImpact: 25% 2026-08-20T14:58:41.264 ProcessImageName: firefox.exe, Pid: 5784, TotalTime: 406, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempb04192, EstimatedImpact: 14% 2026-08-20T14:58:41.264 ProcessImageName: svchost.exe, Pid: 3264, TotalTime: 375, Count: 2, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\AsRyzenMaster.exe, EstimatedImpact: 1% 2026-08-20T14:58:41.264 ProcessImageName: TeamViewer.exe, Pid: 7388, TotalTime: 327, Count: 2, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 10% 2026-08-20T14:58:41.326 [Engine] RSIG_UNLOADENGINE, 00007FF89FB255E0, err=0x0 2026-08-20T14:58:41.342 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C583D3C8-4766-4938-9CE0-D1E27854FA55} removed 2026-08-20T14:58:41.607 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-20T14:58:41.607 [RTP] Duplicating the current plugin configuration object... 2026-08-20T14:58:41.607 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T14:58:41.607 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-20T14:58:41.607 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-20T14:58:41.607 [RTP] No config change detected. Not updating plugin configuration. 2026-08-20T14:58:41.607 [RTP] No config changes found. No configuration switch. 2026-08-20T14:58:41.607 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-20T14:58:43.112 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-20T14:58:43.112 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-20T14:58:43.112 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) BEGIN BM telemetry GUID:{8C04B024-FC8B-F209-F3E7-37F5FCA518E6} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:872 ProcessCreationTime:134317106179377115 SessionID:1 CreationTime:08-20-2026 15:01:05 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-20T15:01:06.693 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-20T15:01:06.693 [Cloud] Start of cloud request. Passive mode: 0 2026-08-20T15:01:06.693 [Cloud] Queued cloud request. 2026-08-20T15:01:06.693 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-20T15:01:06.693 [Cloud] Dequeued cloud request. 2026-08-20T15:01:06.693 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-20T15:01:07.005 [Cloud] End of cloud request. 2026-08-20T15:01:07.521 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-20T15:02:10.983 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T15:04:09.822 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7611, FileId: 0x28000000010c12, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:04:09.838 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7613, FileId: 0x20000000010ced, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:08:52.820 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #7775, FileId: 0x2a000000010c12, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:17:15.983 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T15:32:20.995 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T15:41:19.436 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj459958922. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8649, FileId: 0x63000000011990, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.452 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj706DD5901. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8650, FileId: 0x64000000011990, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.452 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE536D59F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8651, FileId: 0x65000000011990, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.468 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj73A6199B5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8652, FileId: 0x66000000011990, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.483 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2B897390F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8653, FileId: 0x93000000013147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.483 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8D75A490C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8654, FileId: 0x94000000013147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.686 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj21F3D59B9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8655, FileId: 0xaf000000015676, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.686 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF020F49A3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8656, FileId: 0x5e0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.702 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBE976297E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8657, FileId: 0x5f0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.718 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj578F6C906. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8658, FileId: 0x600000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.733 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj107A289E9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8659, FileId: 0x610000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.749 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj40222791A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8660, FileId: 0x620000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.749 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE02FBB96E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8661, FileId: 0x630000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.765 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj065EDF995. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8662, FileId: 0x640000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.780 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8142939CF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8663, FileId: 0x650000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.796 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDB64239A4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8664, FileId: 0x660000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.796 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD41228924. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8665, FileId: 0x670000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.827 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAB9FB5947. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8666, FileId: 0x680000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:19.843 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj939B2E915. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8667, FileId: 0x690000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.160 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj3A32AE9A6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8668, FileId: 0x6a0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.175 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj53B7CA999. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8669, FileId: 0x6b0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.191 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC656D69A4. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8670, FileId: 0x6c0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.191 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8B9208977. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8671, FileId: 0x6d0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.207 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFBC39990E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8672, FileId: 0xac000000013147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.207 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj62004F968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8673, FileId: 0xad000000013147, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.316 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjED109398B. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8674, FileId: 0xb1000000015676, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.316 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjBA8E919C3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8675, FileId: 0x6f0000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.332 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE5C06A9EB. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8676, FileId: 0x700000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.347 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj014E539F2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8677, FileId: 0x710000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.363 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5599EB9B7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8678, FileId: 0x720000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.378 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj18D23997F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8679, FileId: 0x730000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.394 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE89F3B9E3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8680, FileId: 0x740000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:21.410 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1DF79398D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8681, FileId: 0x750000000134db, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:34.383 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8682, FileId: 0x169000000002cee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:34.477 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8684, FileId: 0xc7000000011958, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:49.471 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8687, FileId: 0x300000000110ad, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:41:49.471 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8689, FileId: 0xcc0000000118fd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T15:47:25.992 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T16:00:17.821 Bm signature throttled:0x000032b37183e45b 2026-08-20T16:02:30.997 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T16:17:23.129 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T16:30:17.590 [RTP] [Mini-filter] OpenWithoutRead notification (2322, 10001, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-08-20T16:32:28.138 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T16:47:32.006 Bm signature throttled:0x00002db31bed458f 2026-08-20T16:47:33.131 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T16:52:17.979 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 14463, Count: 986, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\ext\uppod\uppod.js->(UTF-8), EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: AcroCEF.exe, Pid: 11620, TotalTime: 4096, Count: 176, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-20T16:52:17.979 ProcessImageName: notepad++.exe, Pid: 10928, TotalTime: 1367, Count: 52, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 49% 2026-08-20T16:52:17.979 ProcessImageName: explorer.exe, Pid: 7228, TotalTime: 1341, Count: 6, MaxTime: 1046, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: WmiPrvSE.exe, Pid: 5976, TotalTime: 556, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-08-20T16:52:17.979 ProcessImageName: AdobeCollabSync.exe, Pid: 9944, TotalTime: 365, Count: 23, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: backgroundTaskHost.exe, Pid: 1472, TotalTime: 270, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 11% 2026-08-20T16:52:17.979 ProcessImageName: SDXHelper.exe, Pid: 5680, TotalTime: 195, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 5% 2026-08-20T16:52:17.979 ProcessImageName: SecurityHealthHost.exe, Pid: 4984, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 13% 2026-08-20T16:52:17.979 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 150, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: SDXHelper.exe, Pid: 10124, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 3% 2026-08-20T16:52:17.979 ProcessImageName: GUP.exe, Pid: 9592, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_AB1B00F707521C22B07C077113A83DC3, EstimatedImpact: 2% 2026-08-20T16:52:17.979 ProcessImageName: AcroCEF.exe, Pid: 11180, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: Acrobat.exe, Pid: 2592, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 35% 2026-08-20T16:52:17.979 ProcessImageName: OfficeC2RClient.exe, Pid: 6232, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\24CADE4E-F9D8-4FFA-A1FE-5CA9C850093D, EstimatedImpact: 3% 2026-08-20T16:52:17.979 ProcessImageName: AdobeARM.exe, Pid: 7672, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 8% 2026-08-20T16:52:17.979 ProcessImageName: SDXHelper.exe, Pid: 724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-08-20T16:52:17.979 ProcessImageName: svchost.exe, Pid: 3472, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: AcroCEF.exe, Pid: 13184, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0, EstimatedImpact: 3% 2026-08-20T16:52:17.979 ProcessImageName: Acrobat.exe, Pid: 6096, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 2% 2026-08-20T16:52:17.979 ProcessImageName: dllhost.exe, Pid: 5732, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: AggregatorHost.exe, Pid: 5128, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-20T16:52:17.979 ProcessImageName: dasHost.exe, Pid: 972, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 3% 2026-08-20T16:52:17.979 ProcessImageName: svchost.exe, Pid: 12876, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-20T17:02:38.127 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b 2026-08-20T17:17:43.127 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T17:30:33.878 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-20T17:30:33.878 [RTP] 7 newly mounted volumes accumulated, forcing a config update ... 2026-08-20T17:30:33.878 [RTP] Duplicating the current plugin configuration object... 2026-08-20T17:30:33.878 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-20T17:30:33.878 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-20T17:30:33.878 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-20T17:30:33.894 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-20T17:30:34.128 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-20T17:30:49.310 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-20T17:32:48.140 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T17:47:53.138 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T18:02:58.135 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T18:06:13.202 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:06:14.177 Engine:Process 700 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-08-20T18:06:15.548 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:17:23.784 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19996, FileId: 0x690000000072b2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:17:55.392 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner\31_E-S-MC 912.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20020, FileId: 0x560000000292a1, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:00.743 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner\G-P-PI 270 Anlage 1 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20022, FileId: 0x1200000002929a, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:03.133 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T18:18:06.102 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\e-s-mc_920_de_Bild_4.2.1.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20023, FileId: 0x400000000292a4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:11.436 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\e-p-pi_300_de.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20026, FileId: 0x9b0000000292f4, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:16.780 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28155 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20027, FileId: 0xbb0000000292cd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:22.139 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DE-P-PI 302 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20028, FileId: 0x630000000292e9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x401620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:27.472 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28132 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20029, FileId: 0x400000000292af, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:32.806 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28156 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20030, FileId: 0x260000000292ae, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:38.165 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28162-1 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20031, FileId: 0x9f0000000292ce, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:43.493 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28140-1 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20032, FileId: 0x4d0000000292bd, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:48.811 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\DIN\DIN 28006-1 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20033, FileId: 0x1d0000000292e3, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:54.144 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 3.3.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20034, FileId: 0x6a0000000292ff, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:18:59.988 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 1.2.1.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20036, FileId: 0x9a00000002930c, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:05.336 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 3.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20038, FileId: 0x32000000029302, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:10.685 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Gleitringdichtung\DIN 28138-1 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20040, FileId: 0x29000000029286, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:16.065 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 1.2.2.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20043, FileId: 0x51000000029309, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:21.424 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 3.2.1.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20044, FileId: 0x3a000000029304, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:26.763 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner (2)\Anlage 3.2.2.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20053, FileId: 0x2f0000000292fb, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:32.111 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Gleitringdichtung\DIN 28138-3 DE.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20054, FileId: 0x56000000029284, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:37.439 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner\DIN13345\0371d_DIN_EN_13445-1_20211201_de.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20055, FileId: 0x35000000029290, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:42.799 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner\W1711_Festigkeitsberechnung Rev.1.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20056, FileId: 0x8e00000002929f, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:19:48.127 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\OneDrive - SCIO Group\Vescon\BASF-WN\Neuer Ordner\WB8561_Festigkeitsberechnung Rev.0.pdf. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #20057, FileId: 0x52000000029299, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x501620, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x1, 0x10, 0x0:0\0x0:0 2026-08-20T18:23:52.218 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #20308, FileId: 0x27000000010d8e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:23:54.250 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:23:54.712 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:33:08.185 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T18:46:48.383 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:46:55.331 Bm signature throttled:0x00002db31bed458f 2026-08-20T18:48:13.139 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T18:52:17.993 ProcessImageName: httpd.exe, Pid: 2392, TotalTime: 53494, Count: 2972, MaxTime: 562, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\ext\uppod\uppod.js->(UTF-8), EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: explorer.exe, Pid: 7228, TotalTime: 13356, Count: 185, MaxTime: 4578, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: AcroCEF.exe, Pid: 11620, TotalTime: 4096, Count: 176, MaxTime: 359, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-20T18:52:17.993 ProcessImageName: notepad++.exe, Pid: 10928, TotalTime: 1428, Count: 79, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: WmiPrvSE.exe, Pid: 5976, TotalTime: 556, Count: 16, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\fvevol.sys, EstimatedImpact: 86% 2026-08-20T18:52:17.993 ProcessImageName: AdobeCollabSync.exe, Pid: 9944, TotalTime: 365, Count: 23, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: OpenWith.exe, Pid: 11896, TotalTime: 323, Count: 14, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7zG.exe, EstimatedImpact: 65% 2026-08-20T18:52:17.993 ProcessImageName: svchost.exe, Pid: 988, TotalTime: 311, Count: 2, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: backgroundTaskHost.exe, Pid: 1472, TotalTime: 270, Count: 34, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 11% 2026-08-20T18:52:17.993 ProcessImageName: svchost.exe, Pid: 1420, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 5680, TotalTime: 195, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 5% 2026-08-20T18:52:17.993 ProcessImageName: Notepad.exe, Pid: 12488, TotalTime: 166, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\changelog.txt, EstimatedImpact: 7% 2026-08-20T18:52:17.993 ProcessImageName: SecurityHealthHost.exe, Pid: 4984, TotalTime: 165, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres, EstimatedImpact: 13% 2026-08-20T18:52:17.993 ProcessImageName: TabTip.exe, Pid: 1196, TotalTime: 155, Count: 3, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tipskins.dll, EstimatedImpact: 100% 2026-08-20T18:52:17.993 ProcessImageName: Notepad.exe, Pid: 12952, TotalTime: 136, Count: 15, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\readme.txt, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: OfficeC2RClient.exe, Pid: 11776, TotalTime: 92, Count: 6, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 10124, TotalTime: 91, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: GUP.exe, Pid: 9592, TotalTime: 91, Count: 7, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A1D627669EFC8CD4F21BCF387D97F9B5_AB1B00F707521C22B07C077113A83DC3, EstimatedImpact: 2% 2026-08-20T18:52:17.993 ProcessImageName: notepad++.exe, Pid: 9932, TotalTime: 76, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: notepad++.exe, Pid: 9596, TotalTime: 76, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\config.xml, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: AcroCEF.exe, Pid: 11180, TotalTime: 76, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: ADNotificationManager.exe, Pid: 11684, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: Acrobat.exe, Pid: 2592, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro131072.dat, EstimatedImpact: 35% 2026-08-20T18:52:17.993 ProcessImageName: OfficeC2RClient.exe, Pid: 6232, TotalTime: 75, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\24CADE4E-F9D8-4FFA-A1FE-5CA9C850093D, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: OfficeC2RClient.exe, Pid: 9752, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260820-2023.log->(UTF-16LE), EstimatedImpact: 2% 2026-08-20T18:52:17.993 ProcessImageName: dllhost.exe, Pid: 5732, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01tmp.log, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: PhoneExperienceHost.exe, Pid: 10784, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\microsoft.system.package.metadata\S-1-5-21-3855297717-2871178096-3121473446-1002-MergedResources-55.pri, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: AdobeARM.exe, Pid: 7672, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Caches\cversions.1.db, EstimatedImpact: 8% 2026-08-20T18:52:17.993 ProcessImageName: TeamViewer.exe, Pid: 7388, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\BuddyListCache\15337305, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: AggregatorHost.exe, Pid: 5128, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 724, TotalTime: 60, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 7% 2026-08-20T18:52:17.993 ProcessImageName: svchost.exe, Pid: 3472, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\3e825a23979fa4d829bfc32ef453d5d4a6b73668\content.phf, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: AcroCEF.exe, Pid: 13184, TotalTime: 45, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: Acrobat.exe, Pid: 6096, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\desktop.ini, EstimatedImpact: 2% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 4100, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 7% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 5436, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3, EstimatedImpact: 15% 2026-08-20T18:52:17.993 ProcessImageName: dasHost.exe, Pid: 972, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_6.bmp, EstimatedImpact: 3% 2026-08-20T18:52:17.993 ProcessImageName: svchost.exe, Pid: 12876, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-20T18:52:17.993 ProcessImageName: SDXHelper.exe, Pid: 10788, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal, EstimatedImpact: 1% 2026-08-20T18:54:40.586 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23223, FileId: 0x16f00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.586 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23225, FileId: 0x1b00000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.586 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23227, FileId: 0x17300000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.586 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23222, FileId: 0x1a00000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.586 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23226, FileId: 0x1e00000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.618 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23228, FileId: 0x17400000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:40.633 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23224, FileId: 0x17100000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.133 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23266, FileId: 0x2700000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.133 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23267, FileId: 0x17c00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.133 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23270, FileId: 0x2900000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.149 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23269, FileId: 0x2800000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.149 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23268, FileId: 0x17d00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.149 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23264, FileId: 0x17a00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.149 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23265, FileId: 0x17b00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.196 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23276, FileId: 0x18200000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.211 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23281, FileId: 0x2f00000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.243 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23284, FileId: 0x3000000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.243 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23286, FileId: 0x3100000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.243 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23288, FileId: 0x3200000001a224, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T18:54:41.243 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #23290, FileId: 0x18700000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T19:03:18.133 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-20T19:07:37.993 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #24096, FileId: 0xf700000000ac8b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-20T19:14:26.067 Bm signature throttled:0x00002db31bed458f 2026-08-20T19:14:52.212 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\7E0C86AE-BCC0-4455-B6BF-1D469B1B09A12058.1dd30d82bc1d403 2026-08-20T19:14:52.321 Verifying engine and signature files (source: 0) ... 2026-08-20T19:14:52.321 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpengine.dll] due to PPL. 2026-08-20T19:14:52.321 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasbase.vdm] (file in cache) 2026-08-20T19:14:52.321 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-20T19:14:52.336 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasdlta.vdm] 2026-08-20T19:14:52.336 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpavbase.vdm] (file in cache) 2026-08-20T19:14:52.336 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-20T19:14:52.367 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpavdlta.vdm] 2026-08-20T19:14:52.539 [Engine] IsHybridMode: 0 2026-08-20T19:14:52.539 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-20T19:14:52.539 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DC4D328E2BF8D3BB4DBBDA30D52C1F35CD4DCD33.bin): 0x00000002 2026-08-20T19:14:52.555 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DC4D328E2BF8D3BB4DBBDA30D52C1F35CD4DCD33.bin) 2026-08-20T19:14:52.555 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-20T19:14:52.555 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-20T19:14:52.555 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-20T19:14:52.555 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-20T19:15:04.414 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-20T19:15:04.414 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-20T19:15:04.430 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FF83D3955E0, lRefCount: 6, hr=0 2026-08-20T19:15:04.430 [Engine] New active engine 00007FF8414C55E0 replacing engine 00007FF83D3955E0. Number of active engines: 2 2026-08-20T19:15:04.430 EngineInit:Global ASOC is enabled 2026-08-20T19:15:04.430 EngineInit:ASOO is enabled for developer volumes 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-20T19:15:04.508 MpWriteUupSignatureVersion 1.457.261.0, hr = 0 2026-08-20T19:15:04.508 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-20T19:15:04.539 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-20T19:15:04.539 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-20T19:15:04.539 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-20T19:15:04.539 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-20T19:15:04.539 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-20T19:15:04.571 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-20T19:15:04.571 [Plugin] Initializing RTP plugin state... 2026-08-20T19:15:04.571 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-20T19:15:04.571 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎20‎-‎2026 16:52:31 Last Perf:‎08‎-‎20‎-‎2026 16:52:30 First RTP Scan:‎08‎-‎20‎-‎2026 16:52:32 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1585 Misses:15678 BM Queue:0,212,0 Proc:0,206,0 File:0,94,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:24375 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:145311556 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:9922 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:50415 TotalHits:381082 InstanceCacheInserts:1575 InstanceCacheUpdates:0 InstanceCacheDeletes:295 InstanceCacheHits:399 InstanceCacheMisses:28846 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (1562/506) Success: 506, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* -------------------------------------------------------------------------------- Microsoft Defender Antivirus (77BDAF73-B396-481F-9042-AD358843EC24) Service Log Started On 08-21-2026 08:52:55 ************************************************************ OS install time: 12/12/2021 22:57:41.0 UTC Current time: 08/21/2026 08:52:55.118882100 UTC (13828 ms since boot) 2026-08-21T08:52:55.139 MpEnsureProcessMitigationPolicy(0x7) returns 0x1 2026-08-21T08:52:55.144 [HybridMode] isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-21T08:52:55.144 ProductId: 2, ProductFeature: 0, LaunchedProtected: 3, IsWcos: 0, IsContainerOs: 0, DirtyShutdownDetected: 0, PassiveRemediation: 0, IsHybridModePolicyEnabled: 0, IsVerifiedAndReputableTrustModeEnabled: 0 2026-08-21T08:52:55.219 [WPP] Starting WPP trace with buffersize 4MB, maxfilesize: 16MB, filename: MpWppTracing-20260821-085255-00000003-fffffffeffffffff.bin ... 2026-08-21T08:52:55.331 [WPP] Trace session started - MpWppTracing-20260821-085255-00000003-fffffffeffffffff.bin 2026-08-21T08:52:55.339 MpReinforceExclusionsAcls from LoadCapability: (hr = 0) 2026-08-21T08:52:55.345 [RbM] Rollback manager succesfully initialized. 2026-08-21T08:52:55.345 [RbM] Rollback manager EnableRollbackManager called. 2026-08-21T08:52:55.350 [RbM] Rollback manager EnableRollbackManager completed. 2026-08-21T08:52:55.350 [PlatUpd] Service launched successfully from: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 2026-08-21T08:52:55.350 MpWriteUupPlatformVersion 4.18.26070.9, hr = 0 2026-08-21T08:52:55.350 [PlatUpd] Failed to read Misc config regarding new coreservice lifecycle management, using legacy core service lifecycle management anyway. hr = 0x80070002 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdTimerInitalDelay) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdTimerMonitorInterval) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdDisableResController) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdEnableDailySensorChecks) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdAlertMonitorWindow) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdAlertMinInterval) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorEnableLeakDetector) hr = 0x80004004 2026-08-21T08:52:55.350 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x80004004 2026-08-21T08:52:55.355 MdCoreSvc is supported in this platform and OS 2026-08-21T08:52:55.355 MdCoreSvc is supported in this platform and OS 2026-08-21T08:52:55.355 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-21T08:52:55.355 [PlatUpd] Starting MdCoreSvc service 2026-08-21T08:52:55.414 [PlatUpd] Validating and fixing WMI MOF schema - Running command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe" -RegisterWmiSchema -Root "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0" 2026-08-21T08:53:01.310 [PlatUpd] MpAddMpUxRegistration succeeded 2026-08-21T08:53:01.310 [PlatUpd] MpManagementUpdateHandler: starting update for install path %ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0. 2026-08-21T08:53:01.310 [PlatUpd] MpManagementUpdateHandler: calling MpUpdateManagement() 2026-08-21T08:53:01.310 [PlatUpd] MpUpdateManagement: Management platform update started for components (3) 2026-08-21T08:53:01.310 [PlatUpd] CSP platform update started 2026-08-21T08:53:01.310 [PlatUpd] Defender MDM CSP platform update not required 2026-08-21T08:53:01.310 [PlatUpd] WMI/PS provider platform update started 2026-08-21T08:53:01.310 [PlatUpd] WMI/PS provider platform update not required 2026-08-21T08:53:01.310 [PlatUpd] MpUpdateManagement: Management platform update completed 2026-08-21T08:53:01.310 MdCoreSvc is supported in this platform and OS 2026-08-21T08:53:01.310 [PlatUpd] MDCoreSvc is supported by the version of the platform we are switching to. Making sure the service is registered with SCM 2026-08-21T08:53:01.310 [PlatUpd] Starting MdCoreSvc service 2026-08-21T08:53:01.310 [PlatUpd] MpCheckAndUpdateBinaryLocationTo(%ProgramData%\Microsoft\Windows Defender\Platform\4.18.26070.9-0): 11 items checked, 0 required update. hrMui: 0x1 hrEtw: 0 2026-08-21T08:53:01.310 [TS] Troubleshooting mode is not available! 2026-08-21T08:53:01.310 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-21T08:53:01.310 CheckProductDisabled(fWaitWSC: 1, fRemoveConfigs: 0) ... 2026-08-21T08:53:01.342 [Service] Enabling IOAV/IEV/ShellExt/EtwLogger registrations ... 2026-08-21T08:53:01.342 [Service] Enabling AutoLoggers ... 2026-08-21T08:53:01.357 DefenderApiLoggerLowPriv started successfully. 2026-08-21T08:53:01.357 [Service] Enabling AMSI registration ... 2026-08-21T08:53:01.357 [Service] Leaving EnableIOAVWorker(1, 0) with hr = 0 2026-08-21T08:53:01.373 Cache C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\8F48C739-1011-4DD8-9A27-E1F2076AD8B1-0.bin loaded.**********Cache stats************ No. Of buckets -> 76291 Each Bucket has max capacity of -> 1 entries number of Entries is 43622 Number of invalid entries is 0 Number of inserts issued is 1614470 Number of replaces issued is 0 Number of insert failures is 8 Number of inserts with duplicate entries is 6627 Number of lookups is 109227710 Number of lookup misses is 5261702 Number of fast lookup misses is 55688006 Number of false fast lookups is 5261697 Number of invalidations is 746674 Number of maintenance invalidations is 541193 Current File Size is 1871872 Journal ID = 1d68dc088d71441 Trusted image state = 2 USN = 2d6a5018f Setup boot count = 2 2026-08-21T08:53:01.373 Verifying license file... 2026-08-21T08:53:01.373 Verified [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\msmplics.dll] (file in cache) 2026-08-21T08:53:01.388 SharedSignatureRoot not configured. Disabling remote image load for msmpeng.exe. Once disabled, it can no longer be enabled without a service restart. hr=0x1 2026-08-21T08:53:01.388 Loaded module#0 MpComServer. 2026-08-21T08:53:01.388 Loaded module#1 StartupPolicies. 2026-08-21T08:53:01.388 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: False 2026-08-21T08:53:01.388 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-21T08:53:01.404 COM server initialized successfully. 2026-08-21T08:53:01.420 MpRefreshDefenderCoreConfigs: failed because engine is not ready, we cannot let the process continue because we might start core service while its configuration is not ready. 2026-08-21T08:53:01.420 [Plugin] Verifying C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll ... 2026-08-21T08:53:01.420 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mprtp.dll] due to PPL. 2026-08-21T08:53:01.435 [RTP] [RTP] FilterCommunicator object 0x000001ED25CC5750 initialized (\MicrosoftMalwareProtectionAsyncPortWD, , ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-21T08:53:01.451 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting RegLinkHardeningMode to 0 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 7 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting EfsHardeningFlags to 0 (hr=0). 2026-08-21T08:53:01.451 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-21T08:53:01.451 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-21T08:53:01.451 [RTP] Setting DisableDynamicFsHardening to 0 (hr=0). 2026-08-21T08:53:01.451 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-21T08:53:01.451 [RTP] [RTP] FilterCommunicator object 0x000001ED25CC5950 initialized (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD, \MicrosoftMalwareProtectionRemoteIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-21T08:53:01.451 [RTP] SyncDssAvailableThreads cap limit initialized by MiscConfig to: 18 2026-08-21T08:53:01.451 [RTP] [RtpCopyAccelerator] Windows19H1 1, WindowsCobalt 1, IsServerSKU 0, IsPassiveOrSideBySidePassiveMode 0, IsDevMode 0, fIsWindowsInhouseBuild 0, BuildLabEx 22000.1.amd64fre.co_release.210604-1628 2026-08-21T08:53:01.451 [RTP] [RtpCopyAccelerator] Initialized copy acceleration 2026-08-21T08:53:01.451 [RTP] [RTP] StartCommunication 0x000001ED25CC5750 (\MicrosoftMalwareProtectionAsyncPortWD, ), threads: 0 normal, 0 very low, 0 alt, thread pool threads: 4 normal, 0 very low, 0 alt 2026-08-21T08:53:01.451 [init][RTP] RTPPlugin initialization completed 2026-08-21T08:53:01.451 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\mpnirtp.dll] due to PPL. 2026-08-21T08:53:01.482 [RTP] [NiRTP] CNiRtpPlugin::Initialize completed successfully 2026-08-21T08:53:01.482 [init][NiRTP] NiRTPPlugin initialization completed 2026-08-21T08:53:01.482 OS boot count = 2 2026-08-21T08:53:01.482 OS Install = 0 2026-08-21T08:53:01.498 [ManagedAgent] HooksInitialize: starting 2026-08-21T08:53:01.498 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-21T08:53:01.498 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) 2026-08-21T08:53:01.498 [ManagedAgent] HooksInitialize: complete 2026-08-21T08:53:01.951 [init] MpAddMpUxRegistrationForToast succeeded 2026-08-21T08:53:01.951 [KSL] Entering CKSLEngine::Initialize. 2026-08-21T08:53:01.951 [KSL] Leaving CKSLEngine::Initialize(0). 2026-08-21T08:53:01.951 [KSL] Entering CKSLEngine::EnableKSL. State: [1] 2026-08-21T08:53:01.951 [KSL] MpInstallKslD: hr=0x1 2026-08-21T08:53:01.951 [KSL] MpRegisterKslD: hr=0 2026-08-21T08:53:01.967 [KSL] MpStartKslD: hr=0 2026-08-21T08:53:01.967 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-21T08:53:01.967 Loading engine... 2026-08-21T08:53:01.982 Verifying engine and signature files (source: 1) ... 2026-08-21T08:53:01.982 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpengine.dll] due to PPL. 2026-08-21T08:53:01.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasbase.vdm] (file in cache) 2026-08-21T08:53:01.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasdlta.vdm] (file in cache) 2026-08-21T08:53:01.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpavbase.vdm] (file in cache) 2026-08-21T08:53:01.982 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpavdlta.vdm] (file in cache) 2026-08-21T08:53:02.029 [Engine] IsHybridMode: 0 2026-08-21T08:53:02.029 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-21T08:53:02.076 Database:Using offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-DC4D328E2BF8D3BB4DBBDA30D52C1F35CD4DCD33.bin) IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-21T08:53:12.697 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-21T08:53:12.697 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-21T08:53:12.713 [Engine] New active engine 00007FFBD59D55E0 (no old engine). Number of active engines: 1 2026-08-21T08:53:12.728 EngineInit:Global ASOC is enabled 2026-08-21T08:53:12.728 EngineInit:ASOO is enabled for developer volumes 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.932 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:53:12.947 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\94f82da0c2af6be7f3fbcfcffec06b284ceb580a Dynamic Signature Compilation Timestamp:08-20-2026 14:43:28 Persistence Type:Duration Time remaining:288000000 2026-08-21T08:53:12.978 MpWriteUupSignatureVersion 1.457.261.0, hr = 0 2026-08-21T08:53:12.978 Dynamic signature dropped 2026-08-21T08:53:12.978 [SigStatUpd] CSignatureStatus: back to good 2026-08-21T08:53:12.978 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-21T08:53:13.057 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-21T08:53:13.057 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-21T08:53:13.057 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-21T08:53:13.057 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-21T08:53:13.119 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-21T08:53:13.119 [Plugin] Initializing RTP plugin state... 2026-08-21T08:53:13.119 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-21T08:53:13.119 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7} 2026-08-21T08:53:13.119 [SCC][CID=31843_5276] [1DS] SCCState hr=0x0 msg={"error":"","hr":"0x0","init":false,"source":"None","state":"None"} 2026-08-21T08:53:13.119 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:53:13.119 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:53:13.119 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:53:13.119 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-21T08:53:13.135 MdCoreSvc is supported in this platform and OS 2026-08-21T08:53:13.135 Engine loaded! 2026-08-21T08:53:13.135 [DLP] Create FeatureControlState instance 2026-08-21T08:53:13.150 RegisterSModeChangeListener: hr = 0x1 2026-08-21T08:53:13.150 RegisterHybridModeChangeListener: hr = 0 2026-08-21T08:53:13.166 [RTP] ****************************RTP Perf Log*************************** RTP Start:N/A Last Perf:N/A First RTP Scan:N/A Plugin States: AV:2 AS:2 RTP:2 OA:2 BM:2 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:0 System File Cache: Hits:0 Misses:0 BM Queue:0,0,0 Proc:0,0,0 File:0,0,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:2,2,0 SetEngine:1,1,0 SetState:1,1,0 SetUser:0,1,0 Config:0,0,0 ProcExcl:0,0,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:0 Pending:0 RegSize:2882 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:2102 AsyncQCurrent:0 BMFlags:8 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:3393 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:17426 TotalHits:0 InstanceCacheInserts:59 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:3782 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:-1ms (0/0) Success: 0, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-21T08:53:13.166 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 0 2026-08-21T08:53:13.166 Engine:Failure in process enumeration: Image:, Error:GetImageNameConfigurationEx, 0x80078020, PID: 4 2026-08-21T08:53:13.197 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-21T08:53:13.228 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-21T08:53:13.260 [AutoPurge] Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 2026-08-21T08:53:13.260 [SigReleaseHb] Initialized with Stage 0 2026-08-21T08:53:13.260 [EmergencySigManager] Emergency sig checks are currently disabled. Timer interval: 15 minutes. 2026-08-21T08:53:13.260 [SCC][CID=31843_5276] Initializing ... 2026-08-21T08:53:13.260 [SCC][CID=31843_5276] SCC Initialize! The feature is OFF on this machine (E5 = 0), hr: 0x80004001 2026-08-21T08:53:13.260 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-21T08:53:13.260 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-21T08:53:13.275 [NRI] Stopping NIS service ... 2026-08-21T08:53:13.275 [RTP] [RTP] Killbits updated: 0x200000000000000 -> 0x4000000 2026-08-21T08:53:13.275 [RTP] [RTP] LastAccessTimeSuppression is enabled (default behavior). Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.261.0 AV Signature Version: 1.457.261.0 ************************************************************ 2026-08-21T08:53:13.275 Ci Endpoint Security Policy Installation: Unsupported, hr = 0x00000001 2026-08-21T08:53:13.353 Trying to initialize resource usage monitoring... 2026-08-21T08:53:13.369 Resource usage Monitoring is enabled 2026-08-21T08:53:13.432 Job Notification: New process added to job (4412) 2026-08-21T08:53:13.557 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-21T08:53:13.557 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-21T08:53:13.572 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-21T08:53:13.572 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-21T08:53:13.572 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-21T08:53:13.572 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-21T08:53:13.572 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-21T08:53:13.572 [RTP] Generating the base plugin configuration ... 2026-08-21T08:53:13.572 [RTP] Path exclusion changed, new size in bytes: 2 2026-08-21T08:53:13.572 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T08:53:13.572 [RTP] Calling GenerateEngineConfigStruct (0x3e) ... 2026-08-21T08:53:13.572 [RTP] [RTP] RTPPlugin state has changed as follow: ASStatus:0->1, AVStatus:0->1, RTPStatus:0->1 2026-08-21T08:53:13.572 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T08:53:13.572 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-21T08:53:13.572 [RTP] [RTP] StartCommunication 0x000001ED25CC5950 (\MicrosoftMalwareProtectionPortWD, \MicrosoftMalwareProtectionVeryLowIoPortWD), threads: 8 normal, 2 very low, 0 alt, thread pool threads: 0 normal, 0 very low, 8 alt 2026-08-21T08:53:13.650 [RTP] [RTP] RTP worker threads ready [8 threads] 2026-08-21T08:53:13.682 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:10756] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:10792]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-21T08:53:13.682 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-21T08:53:13.697 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-21T08:53:13.697 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-21T08:53:13.697 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-21T08:53:13.697 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-21T08:53:13.697 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-21T08:53:13.697 [KSL] Leaving CKSLEngine::EnableKsl(0). IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b IDynamicConfig::ReportChange value=EnableSmsEmsOnArm64_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableWDClipHelper new=0 old1 IDynamicConfig::ReportChange value=EnableGetCmdComponentsV2_MpRamp new=False oldTrue IDynamicConfig::ReportChange value=MpFC_EnableNetPromptMemscan new=0 old1 IDynamicConfig::ReportChange value=MpFC_CoreSvcEnableUpdateLogging new=0 old1 IDynamicConfig::ReportChange value=MpFC_EnforceMpUxAgentHostParentCheck new=0 old1 IDynamicConfig::ReportChange value=MpDisableBmHealthOneDsEvent new=False oldTrue IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-21T08:53:13.713 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume3\Windows\System32\Windows.ApplicationModel.LockScreen.dll 2026-08-21T08:53:14.088 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:53:14.088 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:53:14.088 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:53:14.103 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:53:14.103 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:53:15.260 [PlatUpd] WMI MOF schema validation completed successfully 2026-08-21T08:53:16.697 [RTP] Duplicating the current plugin configuration object... 2026-08-21T08:53:16.697 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T08:53:16.697 [RTP] Updating plugin configuration due to recent config changes (0x600) ... 2026-08-21T08:53:16.697 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-21T08:53:16.697 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x600, Changed: 0x208 2026-08-21T08:53:57.913 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\32DDC1F3-6BB7-4074-A891-99DE9939AD56554.1dd314a98b00253 2026-08-21T08:53:58.038 Verifying engine and signature files (source: 0) ... 2026-08-21T08:53:58.038 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpengine.dll] due to PPL. 2026-08-21T08:53:58.038 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpasbase.vdm]. File not in cache (0x1) 2026-08-21T08:53:59.007 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpasbase.vdm] 2026-08-21T08:53:59.007 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-21T08:53:59.054 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpasdlta.vdm] 2026-08-21T08:53:59.054 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpavbase.vdm]. File not in cache (0x1) 2026-08-21T08:53:59.710 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpavbase.vdm] 2026-08-21T08:53:59.726 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-21T08:53:59.757 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpavdlta.vdm] 2026-08-21T08:54:00.069 [Engine] IsHybridMode: 0 2026-08-21T08:54:00.069 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-21T08:54:00.101 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F1967FED11B33E455E489ED02D909E834AD051B6.bin): 0x00000002 2026-08-21T08:54:00.132 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-F1967FED11B33E455E489ED02D909E834AD051B6.bin) 2026-08-21T08:54:00.132 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-21T08:54:00.132 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-21T08:54:00.132 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-21T08:54:00.132 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff 2026-08-21T08:54:01.397 Process scan (poststartupscan) started. 2026-08-21T08:54:01.397 Process scan (poststartupscan) completed. 2026-08-21T08:54:01.897 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-21T08:54:01.913 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-21T08:54:04.491 [RTP] Duplicating the current plugin configuration object... 2026-08-21T08:54:04.491 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T08:54:04.491 [RTP] Updating plugin configuration due to recent config changes (0x400) ... 2026-08-21T08:54:04.491 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-21T08:54:04.491 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x400, Changed: 0x208 IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-21T08:54:13.944 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-21T08:54:13.944 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-21T08:54:13.960 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFBD59D55E0, lRefCount: 6, hr=0 2026-08-21T08:54:13.960 [Engine] New active engine 00007FFB7F3055E0 replacing engine 00007FFBD59D55E0. Number of active engines: 2 2026-08-21T08:54:13.960 EngineInit:Global ASOC is enabled 2026-08-21T08:54:13.960 EngineInit:ASOO is enabled for developer volumes 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.022 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T08:54:14.038 MpWriteUupSignatureVersion 1.457.269.0, hr = 0 2026-08-21T08:54:14.038 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-21T08:54:14.054 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-21T08:54:14.054 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-21T08:54:14.054 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-21T08:54:14.054 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-21T08:54:14.054 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-21T08:54:14.085 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-21T08:54:14.085 [Plugin] Initializing RTP plugin state... 2026-08-21T08:54:14.085 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-21T08:54:14.085 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎21‎-‎2026 10:53:13 Last Perf:‎08‎-‎21‎-‎2026 10:53:13 First RTP Scan:‎08‎-‎21‎-‎2026 10:53:13 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:1 System File Cache: Hits:1366 Misses:1290 BM Queue:0,261,0 Proc:0,120,0 File:0,141,0 NamedPipe:0,0,0 Plugin Queue:0,0,0 Threat:0,0,0 Susp:0,0,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,0,0 SetUser:0,0,0 Config:0,1,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:2742 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:4088002 AsyncQCurrent:0 BMFlags:56575 ServiceMaj:0 ServiceMin:0 NumInstance:10 TotalStreamCon:5482 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:22471 TotalHits:8069 InstanceCacheInserts:165 InstanceCacheUpdates:0 InstanceCacheDeletes:163 InstanceCacheHits:0 InstanceCacheMisses:6219 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:7ms (464/66) Success: 66, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-21T08:54:14.085 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7} 2026-08-21T08:54:14.085 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7}\mpasbase.vdm in use, hr=0x80070020 2026-08-21T08:54:14.085 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-21T08:54:14.085 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FA437153-1BF9-424A-A0D9-5EF7E8928E89} removed 2026-08-21T08:54:14.085 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.085 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.085 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.085 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.085 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-21-2026 08:54:14 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-21-2026 08:54:14 2026-08-21T08:54:14.085 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-21T08:54:14.085 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-21T08:54:14.085 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T08:54:14.085 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-21T08:54:14.101 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T08:54:14.101 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.101 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.101 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.101 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-21T08:54:14.101 MdCoreSvc is supported in this platform and OS 2026-08-21T08:54:14.101 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-21T08:54:14.101 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-21-2026 08:54:14 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.269.0 AV Signature Version: 1.457.269.0 ************************************************************ 2026-08-21T08:54:14.101 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-21T08:54:14.101 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\32DDC1F3-6BB7-4074-A891-99DE9939AD56554.1dd314a98b00253 2026-08-21T08:54:14.179 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-21T08:54:14.179 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-21T08:54:14.491 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-21T08:54:14.491 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-21T08:54:14.491 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-21T08:54:14.491 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-21T08:54:14.491 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-21T08:54:14.507 [Engine] Engine 00007FFBD59D55E0 no longer in use. Number of active engines: 1 2026-08-21T08:54:14.507 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T08:54:14.507 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-21T08:54:14.554 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-21T08:54:14.554 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-21T08:54:14.554 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-21T08:54:14.601 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 19681, Count: 295, MaxTime: 1312, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.de_Localization.dll, EstimatedImpact: 73% 2026-08-21T08:54:14.601 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 4511, Count: 11, MaxTime: 1343, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\DesktopOK\DesktopOK.exe, EstimatedImpact: 8% 2026-08-21T08:54:14.601 ProcessImageName: DipAwayMode.exe, Pid: 6820, TotalTime: 2999, Count: 30, MaxTime: 437, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll, EstimatedImpact: 41% 2026-08-21T08:54:14.601 ProcessImageName: AsPowerBar.exe, Pid: 13240, TotalTime: 2832, Count: 18, MaxTime: 1109, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsPowerBar\Qt5Guid.dll, EstimatedImpact: 55% 2026-08-21T08:54:14.601 ProcessImageName: AISuite3.exe, Pid: 6784, TotalTime: 1694, Count: 23, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ASUS\AI Suite III\AsMultiLang.dll, EstimatedImpact: 6% 2026-08-21T08:54:14.601 ProcessImageName: MOM.exe, Pid: 12068, TotalTime: 1663, Count: 30, MaxTime: 531, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll, EstimatedImpact: 49% 2026-08-21T08:54:14.601 ProcessImageName: websockify.exe, Pid: 12088, TotalTime: 894, Count: 18, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\portDesktop\3_Portable\Portable\websockify\python27.dll, EstimatedImpact: 54% 2026-08-21T08:54:14.601 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 421, Count: 2, MaxTime: 265, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer.exe, EstimatedImpact: 7% 2026-08-21T08:54:14.601 ProcessImageName: WhatsApp.Root.exe, Pid: 12272, TotalTime: 331, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\5319275A.WhatsAppDesktop_2.2632.100.0_x64__cv1g1gvanyjgm\S-1-5-21-3855297717-2871178096-3121473446-1002.pckgdep, EstimatedImpact: 2% 2026-08-21T08:54:14.601 ProcessImageName: svchost.exe, Pid: 6584, TotalTime: 136, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\D24D0979AE9F1028535E3A9D94511EDA9589B5D2, EstimatedImpact: 17% 2026-08-21T08:54:14.601 ProcessImageName: backgroundTaskHost.exe, Pid: 10568, TotalTime: 92, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState\u_q62ml6qbrnu6d7984mn9vsh6\p_g7m2ag339emk5tr0k5uuafh1, EstimatedImpact: 23% 2026-08-21T08:54:14.601 ProcessImageName: runonce.exe, Pid: 3484, TotalTime: 75, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\desktop.ini, EstimatedImpact: 2% 2026-08-21T08:54:14.632 [Engine] RSIG_UNLOADENGINE, 00007FFBD59D55E0, err=0x0 2026-08-21T08:54:14.647 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{597E67E3-04E9-42BE-972B-815B1937FEB7} removed 2026-08-21T08:54:40.351 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3121, FileId: 0x19100000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.351 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3123, FileId: 0x19200000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.366 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3122, FileId: 0x2500000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.366 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3124, FileId: 0x2600000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.366 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3126, FileId: 0x2700000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.382 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3130, FileId: 0x19800000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.382 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3131, FileId: 0x2b00000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.397 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3125, FileId: 0x19300000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.397 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3127, FileId: 0x19400000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.397 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3132, FileId: 0x2c00000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.397 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3135, FileId: 0x2d00000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.413 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3133, FileId: 0x19900000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.413 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3139, FileId: 0x3000000003744c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.413 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3140, FileId: 0x19c00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.413 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3138, FileId: 0x19b00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.413 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3141, FileId: 0x19d00000000020e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.772 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #3166, FileId: 0x2700000000ac0b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:40.772 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\0ce3cb9e-be71-4d9c-867d-8b2abfefa196. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #3168, FileId: 0x3700000002b8a8, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:54:57.804 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T08:54:57.804 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T08:54:57.804 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x7894bd50 2026-08-21T08:57:58.479 Bm signature throttled:0x00002db31bed458f 2026-08-21T08:58:01.448 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #4338, FileId: 0x127000000008dc2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:13.261 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T08:58:42.480 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4477, FileId: 0x5400000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.480 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4480, FileId: 0x790000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.480 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4483, FileId: 0x7a0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.495 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4484, FileId: 0x5600000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.495 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4485, FileId: 0x7b0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.511 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4476, FileId: 0x770000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.511 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4487, FileId: 0x7c0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.527 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4478, FileId: 0x780000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.527 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4489, FileId: 0x7d0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.527 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4482, FileId: 0x5500000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.542 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4486, FileId: 0x5700000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.542 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4488, FileId: 0x5800000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.558 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4493, FileId: 0x7f0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.558 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4495, FileId: 0x5e00000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.573 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4494, FileId: 0x5c00000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.573 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4490, FileId: 0x7e0000000061fe, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.920 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4535, FileId: 0x6100000000b796, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.920 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #4534, FileId: 0x27000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:58:42.928 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\1c56f81c-61ce-4fa3-b4b3-2b14e218dfe6. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #4537, FileId: 0x162000000000dd9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T08:59:14.013 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-21T09:03:02.169 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #5699, FileId: 0x19c00000000e228, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:03:13.263 Timer callback: Initializating/verifying scheduled tasks ... 2026-08-21T09:03:13.263 [AutoPurge] AutoPurgeWorker triggered with dwWork=0x3 2026-08-21T09:03:13.279 Job Notification: New process added to job (6596) 2026-08-21T09:03:13.294 Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) launched 2026-08-21T09:03:13.310 Job Notification: New process added to job (3604) 2026-08-21T09:03:13.325 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:6596] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:3604]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-21T09:03:13.404 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 67132079(ms) from now at 05:42 (03:42 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-21T09:03:13.435 Job Notification: New process added to job (6892) 2026-08-21T09:03:13.450 Task(SignaturesUpdateService -ScheduleJob -UnmanagedUpdate) launched 2026-08-21T09:03:13.450 Job Notification: New process added to job (11828) 2026-08-21T09:03:13.466 [RTP] [Mini-filter] Denied OB operation OpenProcess[\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0\MpCmdRun.exe][Pid:6892] from process [\Device\HarddiskVolume3\Windows\System32\conhost.exe][Pid:11828]. OriginalDesiredAccess: [0x1fffff] ResultingAccess: [0x1ff7d4] 2026-08-21T09:03:13.763 Job Notification: New process added to job (2156) 2026-08-21T09:03:13.763 Task(GetDeviceTicket -AccessKey FB9D4690-076B-AE31-1B56-66A5E8EB219E ) launched as network service 2026-08-21T09:03:14.513 Job Notification: Process exited from job (2156) 2026-08-21T09:03:14.763 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext), ShouldSendEvenOnPaidNetworks: 0 2026-08-21T09:03:14.872 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T09:03:14.872 [Cloud] Queued cloud request. 2026-08-21T09:03:14.872 [Cloud] Dequeued cloud request. 2026-08-21T09:03:14.872 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T09:03:15.310 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T09:03:15.310 [Cloud] End of cloud request. 2026-08-21T09:03:15.810 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T09:03:19.763 Job Notification: Process exited from job (6892) 2026-08-21T09:03:19.779 Job Notification: Process exited from job (11828) 2026-08-21T09:03:19.841 Job Notification: Process exited from job (6596) 2026-08-21T09:03:19.841 Job Notification: Process exited from job (3604) 2026-08-21T09:04:01.404 Process scan (postsignatureupdatescan) started. 2026-08-21T09:04:04.810 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-21T09:04:20.622 Process scan (postsignatureupdatescan) completed. 2026-08-21T09:04:31.216 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\IDR_XML_DEFAULT_TRANSFORM[1]. Process: \Device\HarddiskVolume3\Windows\System32\taskhostw.exe, Status: 0xc0000001, State: 0, ScanRequest #6168, FileId: 0xef000000003a1b, Reason: OnClose, IoStatusBlockForNewFile: 0x3, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:00.923 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj62C0319D7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6917, FileId: 0x724000000001b13, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:00.939 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj14F0BA942. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6920, FileId: 0x34000000013502, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:00.939 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj7096F8921. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6922, FileId: 0x726000000001b13, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.001 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj19A6899F9. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6927, FileId: 0x240000000135d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.064 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjDB5BDC936. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6932, FileId: 0x38000000013502, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.095 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1CE1C790C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6935, FileId: 0x39000000013502, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.111 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD3B84D998. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6940, FileId: 0x3b000000013502, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.126 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6A130D93F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6947, FileId: 0x260000000135d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.158 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF2A4F991C. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6977, FileId: 0x3d000000013502, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:01.205 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj910F169EE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #6982, FileId: 0x270000000135d6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:02.145 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE9C8259D3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7035, FileId: 0x420000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:02.149 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj057C529A5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7036, FileId: 0x430000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:02.167 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9E7D16955. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7037, FileId: 0x440000000135e1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:15.451 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7166, FileId: 0x122000000004984, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:15.529 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7168, FileId: 0x29300000000589b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:05:15.685 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7174, FileId: 0x4700000000fc05, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:06:15.920 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #7176, FileId: 0xf6000000000e28, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:08:03.185 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\SDXHelper.exe, Status: 0xc0000001, State: 0, ScanRequest #7236, FileId: 0xb90000000002fe, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:12:24.114 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:12:25.905 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:12:27.198 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:12:30.060 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-08-21T09:12:30.060 [RTP] Duplicating the current plugin configuration object... 2026-08-21T09:12:30.060 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T09:12:30.060 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-21T09:12:30.060 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-21T09:12:30.061 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-21T09:12:30.152 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume8\xampp\xampp-control.exe 2026-08-21T09:12:30.582 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume10\xampp\xampp-control.exe 2026-08-21T09:12:31.422 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume5\xampp\xampp-control.exe 2026-08-21T09:12:36.712 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #7751, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:12:39.520 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5687 units Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-08-21T09:12:45.390 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T09:12:45.390 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T09:12:45.390 [Cloud] Queued cloud request. 2026-08-21T09:12:45.390 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T09:12:45.390 [Cloud] Dequeued cloud request. 2026-08-21T09:12:45.390 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T09:12:46.107 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\048573091599a2271128b5c8ca1582612463e035 Dynamic Signature Compilation Timestamp:08-21-2026 09:12:45 Persistence Type:Duration Time remaining:288000000 2026-08-21T09:12:46.108 [Cloud] End of cloud request. 2026-08-21T09:12:46.108 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T09:12:46.625 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T09:12:59.036 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php94C6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #8044, FileId: 0x3a00000001a103, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:13:18.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T09:15:15.894 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8151, FileId: 0x1500000001a6f8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:15:15.909 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #8153, FileId: 0x6a00000001ad34, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:16:52.753 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #8286, FileId: 0x3400000001acc7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:20:58.363 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:22:57.113 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb)` is 5437 units 2026-08-21T09:23:13.159 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\OneDrive\Apps\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb)` is 5140 units 2026-08-21T09:23:23.753 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume7\Users\desktop.ini 2026-08-21T09:23:59.034 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:25:41.987 [RTP] [Mini-filter] First scan on a volume: \Device\Mup\FB6911234\fb6911234\TOSHIBA-ExternalUSB3-0-02\100_!!!!\01_System\Netzwerk\WindowsFireware.bat 2026-08-21T09:27:50.394 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\INetCache\IE\BBZ0D8FM\update[1].txt. Process: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\geek64.exe, Status: 0xc0000001, State: 0, ScanRequest #10936, FileId: 0x3200000008f6d4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T09:28:23.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T09:29:19.441 [RTP] [Mini-filter] OpenWithoutRead notification (1682, 10018, \Device\HarddiskVolume3\Windows\System32\svchost.exe) sent successfully. 2026-08-21T09:37:15.605 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:43:28.262 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T09:49:39.760 Bm signature throttled:0x00002db31bed458f 2026-08-21T09:58:33.273 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T10:05:35.109 Bm signature throttled:0x00002db31bed458f 2026-08-21T10:13:38.271 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T10:28:43.272 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T10:42:45.882 Bm signature throttled:0x00002db31bed458f 2026-08-21T10:43:48.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T10:49:04.701 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14319, FileId: 0xba00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.702 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14321, FileId: 0xbb00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.702 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14318, FileId: 0x29000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.703 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14322, FileId: 0x2c000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.705 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14323, FileId: 0x2d000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.719 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14326, FileId: 0xbd00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.721 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14328, FileId: 0x30000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.740 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14331, FileId: 0xc200000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.742 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14327, FileId: 0xbf00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.744 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14333, FileId: 0xc300000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.746 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14335, FileId: 0xc400000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:04.754 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14332, FileId: 0x33000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:05.169 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #14364, FileId: 0x37000000012ad5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:49:05.185 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\36a922e7-221a-43ff-8ea8-bffbf0acaaea. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #14366, FileId: 0xe70000000014b9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T10:54:13.967 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 24889, Count: 366, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23876, Count: 35, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 1% 2026-08-21T10:54:13.967 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T10:54:13.967 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T10:54:13.967 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T10:54:13.967 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T10:54:13.967 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T10:54:13.967 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T10:54:13.967 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 2805, Count: 85, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T10:54:13.967 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T10:54:13.967 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T10:54:13.967 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T10:54:13.967 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T10:54:13.967 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T10:54:13.967 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T10:54:13.967 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T10:54:13.967 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T10:54:13.967 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T10:54:13.967 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T10:54:13.967 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 345, Count: 28, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 318, Count: 21, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 312, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T10:54:13.967 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T10:54:13.967 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 240, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 233, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOADF9.tmp, EstimatedImpact: 45% 2026-08-21T10:54:13.968 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T10:54:13.968 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 171, Count: 2, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T10:54:13.968 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T10:54:13.968 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 152, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T10:54:13.968 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T10:54:13.968 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T10:54:13.968 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T10:54:13.968 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T10:54:13.968 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T10:54:13.968 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T10:54:13.968 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 4% 2026-08-21T10:54:13.968 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T10:54:13.968 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T10:54:13.968 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T10:54:13.968 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T10:54:13.968 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T10:54:13.968 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 3% 2026-08-21T10:54:13.968 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T10:54:13.968 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T10:54:13.968 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 26% 2026-08-21T10:54:13.968 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T10:54:13.968 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T10:54:13.968 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T10:54:13.968 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T10:54:13.968 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T10:54:13.968 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T10:54:13.968 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T10:54:13.969 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{91E0771E-FE09-4F47-9C4D-D3E82FEED848}.json, EstimatedImpact: 0% 2026-08-21T10:54:13.969 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T10:54:13.969 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T10:54:13.969 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T10:54:13.969 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T10:58:53.265 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T11:13:58.265 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T11:22:56.571 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15507, FileId: 0x640000000b75a5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T11:29:03.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T11:32:45.983 Bm signature throttled:0x00002db31bed458f 2026-08-21T11:38:56.056 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Windows\Prefetch\XAMPP-CONTROL.EXE-CCCA688C.pf. Process: \Device\HarddiskVolume5\xampp\xampp-control.exe, Status: 0xc000004b, State: 0, ScanRequest #15873, FileId: 0x400000000509d, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8000, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T11:44:08.273 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T11:44:09.693 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #15946, FileId: 0x1d000000034f10, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=false, source=2, resourceid=0x4106df5f 2026-08-21T11:50:23.551 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T11:50:23.552 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T11:50:23.552 [Cloud] Queued cloud request. 2026-08-21T11:50:23.552 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T11:50:23.552 [Cloud] Dequeued cloud request. 2026-08-21T11:50:23.552 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T11:50:24.221 [Cloud] End of cloud request. 2026-08-21T11:50:24.221 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\mobile_reservation_application\Mobile Reservation Application\MobileReservation.apk. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x48e714e8bbc2 2026-08-21T11:50:24.735 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6bc6dbae 2026-08-21T11:52:18.045 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T11:52:18.045 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T11:52:18.045 [Cloud] Queued cloud request. 2026-08-21T11:52:18.045 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T11:52:18.046 [Cloud] Dequeued cloud request. 2026-08-21T11:52:18.046 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T11:52:18.357 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4368ca9106c7c81b8cad2a5530c26a3e086615ce Dynamic Signature Compilation Timestamp:08-21-2026 11:52:17 Persistence Type:Duration Time remaining:1728000000 2026-08-21T11:52:18.358 [Cloud] End of cloud request. 2026-08-21T11:52:18.358 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5fc27e33 2026-08-21T11:52:18.868 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T11:52:18.868 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T11:52:18.868 [Cloud] Queued cloud request. 2026-08-21T11:52:18.868 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T11:52:18.868 [Cloud] Dequeued cloud request. 2026-08-21T11:52:18.868 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T11:52:18.879 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T11:52:19.066 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7346a517989ac5eefc523c65244a73c877f89f9c Dynamic Signature Compilation Timestamp:08-21-2026 11:52:18 Persistence Type:Duration Time remaining:150196224 2026-08-21T11:52:19.067 [Cloud] End of cloud request. 2026-08-21T11:52:19.067 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T11:52:19.589 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1ba4dffc 2026-08-21T11:55:14.921 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T11:55:14.921 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T11:55:14.921 [Cloud] Queued cloud request. 2026-08-21T11:55:14.921 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T11:55:14.921 [Cloud] Dequeued cloud request. 2026-08-21T11:55:14.921 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\68deab3d672c929424a9d89462cc0a8d921a1c6c Dynamic Signature Compilation Timestamp:08-21-2026 11:55:14 Persistence Type:Duration Time remaining:150196224 2026-08-21T11:55:15.290 Dynamic signature received 2026-08-21T11:55:15.291 [Cloud] End of cloud request. 2026-08-21T11:55:15.291 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfcaa650d 2026-08-21T11:55:15.798 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T11:55:15.798 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T11:55:15.798 [Cloud] Queued cloud request. 2026-08-21T11:55:15.798 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T11:55:15.798 [Cloud] Dequeued cloud request. 2026-08-21T11:55:15.798 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T11:55:15.809 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T11:55:16.027 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5aea8bb2eeb8eb362b88bb6222d342c0517e3766 Dynamic Signature Compilation Timestamp:08-21-2026 11:55:15 Persistence Type:Duration Time remaining:150196224 2026-08-21T11:55:16.028 [Cloud] End of cloud request. 2026-08-21T11:55:16.028 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T11:55:16.549 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T11:55:57.795 Bm signature throttled:0x00002db31bed458f 2026-08-21T11:58:29.737 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17166, FileId: 0x1f00000003501b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T11:59:13.262 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=true, source=2, resourceid=0xa892ddd6 2026-08-21T12:04:01.472 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume9\wordpress\.htaccess Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24992611 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5579db6b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42357c3b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x50b6cf2f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x411338da 2026-08-21T12:04:44.763 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #17602, FileId: 0x36000000035520, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:13:33.390 Engine:Setting original file name "reg.exe" for "h:\windows\system32\reg.exe", hr=0x800710da 2026-08-21T12:14:18.262 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T12:29:23.272 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T12:30:34.547 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7B52.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19003, FileId: 0x2b000000034bf0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:06.401 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpF7B7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19057, FileId: 0x53000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:20.228 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2DBC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19085, FileId: 0x54000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:29.017 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4FEB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19100, FileId: 0x55000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:38.697 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php74F8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19118, FileId: 0x56000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:41.317 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7FE6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19128, FileId: 0x57000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:31:57.292 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpBDDA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19163, FileId: 0x58000000036715, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:33:02.792 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x0000157EB1025588, sigsha=9018bbb70a44f45fc8d654e776a41d5e4c19de15, cached=false, source=2, resourceid=0x94814b90 2026-08-21T12:40:15.946 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5A48.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #19821, FileId: 0x33000000033ce8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:42:39.913 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #19977, FileId: 0x310000000b6117, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T12:44:28.270 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T12:48:47.875 Engine:Setting original file name "pcalua.exe" for "h:\windows\system32\pcacli.dll", hr=0x800710da 2026-08-21T12:54:13.974 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 93090, Count: 5154, MaxTime: 515, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\webserver\quickphp\QuickPHP.exe, EstimatedImpact: 2% 2026-08-21T12:54:13.974 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 24980, Count: 377, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T12:54:13.974 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T12:54:13.974 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T12:54:13.974 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T12:54:13.974 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T12:54:13.974 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T12:54:13.974 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 2805, Count: 85, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T12:54:13.974 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T12:54:13.974 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T12:54:13.974 ProcessImageName: notepad++.exe, Pid: 7212, TotalTime: 1293, Count: 61, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T12:54:13.974 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T12:54:13.974 ProcessImageName: perl.exe, Pid: 4816, TotalTime: 779, Count: 4, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T12:54:13.974 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T12:54:13.974 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T12:54:13.974 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T12:54:13.974 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T12:54:13.974 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T12:54:13.974 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 405, Count: 32, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 366, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T12:54:13.974 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T12:54:13.974 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 318, Count: 21, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 312, Count: 2, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T12:54:13.975 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 240, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 233, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOADF9.tmp, EstimatedImpact: 45% 2026-08-21T12:54:13.975 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T12:54:13.975 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 171, Count: 2, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T12:54:13.975 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T12:54:13.975 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T12:54:13.975 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T12:54:13.975 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T12:54:13.975 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T12:54:13.975 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T12:54:13.975 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T12:54:13.975 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 4% 2026-08-21T12:54:13.975 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T12:54:13.975 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T12:54:13.975 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T12:54:13.975 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T12:54:13.975 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 3% 2026-08-21T12:54:13.975 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T12:54:13.975 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 26% 2026-08-21T12:54:13.975 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T12:54:13.975 ProcessImageName: dllhost.exe, Pid: 5860, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T12:54:13.975 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{91E0771E-FE09-4F47-9C4D-D3E82FEED848}.json, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T12:54:13.975 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T12:54:13.975 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 7584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1404.log, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 12636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1442.log, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 10748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1344.log, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T12:54:13.975 ProcessImageName: dasHost.exe, Pid: 5204, TotalTime: 15, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 1% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 2312, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1358.log, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1322.log, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T12:54:13.975 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T12:59:33.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T12:59:41.927 Engine:Setting original file name "rundll32.exe" for "h:\windows\system32\rundll32.exe", hr=0x800710da 2026-08-21T13:00:29.777 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x0000157EAFC2B838, sigsha=ef600f76a8e9dcce34454b1e4fda122185095fe4, cached=false, source=2, resourceid=0xb785cb3e Internal signature match:subtype=Lowfi, sigseq=0x0000157ED01FA601, sigsha=fdc6b8d4215e1e59a08ee3f4793e98a74459e01f, cached=false, source=2, resourceid=0xb785cb3e 2026-08-21T13:08:18.793 [AutoPurge] Verification Routine tasks have started. 2026-08-21T13:08:18.793 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-21T13:08:18.813 [AutoPurge] Cleanup Routine tasks have started. 2026-08-21T13:08:18.818 Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 2026-08-21T13:08:18.819 [AutoPurge] Routine task for Cache Maintenance has started. 2026-08-21T13:08:18.819 [AutoPurge] Routine task for Cache Maintenance ... 2026-08-21T13:08:18.819 [AutoPurge] Routine task for MpSFCBuild ... 2026-08-21T13:08:18.819 [AutoPurge] MpCmIsBuildCompleted() - S_OK 2026-08-21T13:08:18.819 [AutoPurge] MpSignalMaintenanceMode ... 2026-08-21T13:08:18.825 [AutoPurge] Purged 0 expired detection item(s) from a total of 7. 2026-08-21T13:08:18.825 [AutoPurge] 0 expired file(s) deleted under C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store (total: 1, expiration in 86400 seconds) Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:65538 Start time:08-21-2026 13:08:18 2026-08-21T13:08:18.829 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:9AB42B9E-924A-472B-AFEC-50A2A285DEDD, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-21T13:08:18.829 Scheduled scan with Id 9AB42B9E-924A-472B-AFEC-50A2A285DEDD configured CPU priority: normal (LowCpuPriority: 0) 2026-08-21T13:08:18.832 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-21T13:08:18.832 [SFC] System file cache build is not needed (already completed) Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-21-2026 13:08:18 2026-08-21T13:08:18.857 [PlatUpd] Purging orphaned platform update directories under C:\ProgramData\Microsoft\Windows Defender\Platform ... 2026-08-21T13:08:18.857 [PlatUpd] Not purging current location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26070.9-0 ... 2026-08-21T13:08:18.857 [PlatUpd] Not purging backup location C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0 ... 2026-08-21T13:08:18.857 [PlatUpd] Purging orphaned platform update directories under C:\Program Files\Windows Defender\Platform ... 2026-08-21T13:08:18.859 [AutoPurge] Cleanup Routine tasks have ended. 2026-08-21T13:08:18.935 Engine:Setting original file name "Accessibility-version.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2632.100.0_x64__cv1g1gvanyjgm\accessibility.dll", hr=0x800710da 2026-08-21T13:08:19.015 Engine:Setting original file name "USERCPL.DLL" for "c:\windows\systemresources\usercpl.dll.mun", hr=0x800710da 2026-08-21T13:08:19.091 EnsureProtectedFolderAcls(), hr = 0x0 2026-08-21T13:08:19.095 [AutoPurge] MpReinforceServiceAcls: 0 2026-08-21T13:08:19.108 Engine:Setting original file name "powershell.exe" for "c:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-08-21T13:08:19.136 Engine:Setting original file name "atiuxpag.dll" for "c:\windows\system32\atiuxp64.dll", hr=0x800710da 2026-08-21T13:08:19.140 [AutoPurge] Readded platform files to MOAC after ACL enforcement. hr=0 2026-08-21T13:08:19.152 [AutoPurge] UtilIsFileExists(C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\mpengine.dll): hr=0x80070002. Default sigs likely already removed. 2026-08-21T13:08:19.154 [AutoPurge] Verification Routine tasks have ended. 2026-08-21T13:08:19.352 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\microsoft office\root\office16\winappsdk\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-08-21T13:08:19.845 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\el-gr_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:08:20.005 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #21789, FileId: 0x3a0000000b6118, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T13:08:20.169 Engine:Setting original file name "VBoxRT.dll VBoxRT.dll VBoxRT.dll" for "c:\program files\oracle\virtualbox\vboxrt.dll", hr=0x800710da 2026-08-21T13:08:20.253 Engine:Setting original file name "VSSPROV.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\26fc8e2af1d5378cbc6341af2ee9f99d\vsswmi.dll.mui", hr=0x800710da 2026-08-21T13:08:20.296 Engine:Setting original file name "CertCa" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\16d33be66ba9efe8d34aad656aac84ec\certca.dll.mui", hr=0x800710da 2026-08-21T13:08:20.670 Engine:Setting original file name "vshost32-clr2.exe" for "c:\users\ithan\desktop\portdesktop\3_portable\portable\remote\novnc\websockify\websockify_2011-2015\melt command websocket.vshost.exe", hr=0x800710da 2026-08-21T13:08:20.741 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libwebvtt_plugin.dll", hr=0x800710da 2026-08-21T13:08:20.832 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-21T13:08:20.842 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-d..g-adminui.resources_31bf3856ad364e35_10.0.22000.1_de-de_65a8e6787acea599\dfrgui.exe.mui", hr=0x800710da 2026-08-21T13:08:20.853 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:08:20.863 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T13:08:20.865 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:08:21.022 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libgaussianblur_plugin.dll", hr=0x800710da 2026-08-21T13:08:21.060 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fa9e9f795919c397d45e924f4129acf1\kernel32.dll.mui", hr=0x800710da 2026-08-21T13:08:21.112 Engine:Setting original file name "dsprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4918ce064a6bb48b161043d0d36d3155\adprop.dll.mui", hr=0x800710da 2026-08-21T13:08:21.160 Engine:Setting original file name "accbdc.dll" for "c:\program files\microsoft office\root\vfs\windows\assembly\gac_64\microsoft.office.access.businessdatacatalog\16.0.0.0__71e9bce111e9429c\microsoft.office.access.businessdatacatalog.dll", hr=0x800710da 2026-08-21T13:08:21.254 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_nb-no_d24e45794c11ddf2\memtest.exe.mui", hr=0x800710da 2026-08-21T13:08:21.276 Engine:Setting original file name "CRYPT32.DLL" for "c:\windows\systemresources\crypt32.dll.mun", hr=0x800710da 2026-08-21T13:08:21.432 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_mosaic_bridge_plugin.dll", hr=0x800710da 2026-08-21T13:08:21.570 Engine:Setting original file name "msdxm.ocx" for "c:\windows\system32\dxmasf.dll", hr=0x800710da 2026-08-21T13:08:21.729 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-08-21T13:08:21.737 Engine:Setting original file name "Search_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\search\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:21.764 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libmotionblur_plugin.dll", hr=0x800710da 2026-08-21T13:08:21.830 Engine:Setting original file name "routemsg.DLL.MUI" for "c:\windows\system32\de-de\mprmsg.dll.mui", hr=0x800710da 2026-08-21T13:08:21.884 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi422_yuy2_plugin.dll", hr=0x800710da 2026-08-21T13:08:22.324 Engine:Setting original file name "bootstr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ddac26f793bd41f6f142593f827eb3e0\bootstr.dll.mui", hr=0x800710da 2026-08-21T13:08:22.518 Engine:Setting original file name "setup" for "c:\programdata\package cache\{d8bbe9f9-7c5b-42c6-b715-9ee898a2e515}\vc_redist.x64.exe", hr=0x800710da 2026-08-21T13:08:22.555 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_3bfd3d3d4d1b2925\memtest.efi.mui", hr=0x800710da 2026-08-21T13:08:22.838 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libvmem_plugin.dll", hr=0x800710da 2026-08-21T13:08:23.015 Engine:Setting original file name "bootmgr.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\boot\pcat\el-gr\57667689a714ca915f29a6ea84d1fd23\bootmgr.exe.mui", hr=0x800710da 2026-08-21T13:08:23.614 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-time-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:23.634 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-21T13:08:23.683 Engine:Setting original file name "WindowsUpdate_DiagPackage.dll.mui" for "c:\windows\diagnostics\system\windowsupdate\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:23.870 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-08-21T13:08:23.968 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-08-21T13:08:24.088 Engine:Setting original file name "graphics-hook" for "c:\programdata\obs-studio-hook\graphics-hook32.dll", hr=0x800710da 2026-08-21T13:08:24.274 Engine:Setting original file name "YourPhoneAppProxy.dll" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\yourphoneappproxy.exe", hr=0x800710da 2026-08-21T13:08:24.333 Engine:Setting original file name "npPDFViewerNPPlugin.dll" for "c:\program files\tracker software\pdf viewer\nppdfxcviewnpplugin.dll", hr=0x800710da 2026-08-21T13:08:24.345 Engine:Setting original file name "Taskmgr.exe" for "c:\windows\systemresources\taskmgr.exe.mun", hr=0x800710da 2026-08-21T13:08:24.381 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.3_3000.934.1904.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-21T13:08:24.536 Engine:Setting original file name "msfltr32.acm" for "c:\windows\system32\msacm32.dll", hr=0x800710da 2026-08-21T13:08:24.585 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-08-21T13:08:24.704 Engine:Setting original file name "CRYPTUIWIZARD.DLL" for "c:\windows\systemresources\cryptuiwizard.dll.mun", hr=0x800710da 2026-08-21T13:08:24.793 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libprefetch_plugin.dll", hr=0x800710da 2026-08-21T13:08:25.205 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d11_plugin.dll", hr=0x800710da 2026-08-21T13:08:25.219 Engine:Setting original file name "user32" for "c:\windows\winsxs\wow64_microsoft-windows-user32.resources_31bf3856ad364e35_10.0.22000.1_de-de_f5a569c9756903b3\user32.dll.mui", hr=0x800710da 2026-08-21T13:08:25.444 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-08-21T13:08:25.486 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\acbcfee0bb5fbaf9acca014a675b93a6\winresume.efi.mui", hr=0x800710da 2026-08-21T13:08:26.003 Engine:Setting original file name "mbnapi.dll" for "c:\windows\winsxs\wow64_microsoft-windows-wwanapi_31bf3856ad364e35_10.0.22000.1_none_049e8d74569a10be\wwanapi.dll", hr=0x800710da 2026-08-21T13:08:26.037 Engine:Setting original file name "PRINTUI.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\afa2b648877922a62ec6791b53687a54\ntprint.dll.mui", hr=0x800710da 2026-08-21T13:08:26.040 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ko-kr_e9bbc44473ecb236\memtest.exe.mui", hr=0x800710da 2026-08-21T13:08:26.044 Engine:Setting original file name "PROFNOTIFY.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\bb6bb7c616a73612ba439ceefa92fcf4\wsepno.dll.mui", hr=0x800710da 2026-08-21T13:08:26.102 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..docs-main.resources_31bf3856ad364e35_10.0.22000.1_de-de_111b86e074ff6f64\sdengin2.dll.mui", hr=0x800710da 2026-08-21T13:08:26.156 Engine:Setting original file name "glu32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\64c8f3f0d4bff000a24438effba55b87\glu32.dll.mui", hr=0x800710da 2026-08-21T13:08:26.307 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsdp_plugin.dll", hr=0x800710da 2026-08-21T13:08:26.564 Engine:Setting original file name "FIREWALLCONTROLPANEL.DLL" for "c:\windows\systemresources\firewallcontrolpanel.dll.mun", hr=0x800710da 2026-08-21T13:08:26.852 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_record_plugin.dll", hr=0x800710da 2026-08-21T13:08:26.872 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-timezone-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:26.909 Engine:Setting original file name ".NET Host Resolver - 8.0.15" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2632.100.0_x64__cv1g1gvanyjgm\hostfxr.dll", hr=0x800710da 2026-08-21T13:08:26.949 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblpcm_plugin.dll", hr=0x800710da 2026-08-21T13:08:27.032 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-08-21T13:08:27.291 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libvcd_plugin.dll", hr=0x800710da 2026-08-21T13:08:27.305 Engine:Setting original file name "adsldpc" for "c:\windows\system32\de-de\adsldpc.dll.mui", hr=0x800710da 2026-08-21T13:08:27.312 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libball_plugin.dll", hr=0x800710da 2026-08-21T13:08:27.576 Engine:Setting original file name "THEMECPL.DLL" for "c:\windows\systemresources\themecpl.dll.mun", hr=0x800710da 2026-08-21T13:08:27.750 Engine:Setting original file name "srpuxgp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a441bd464c852917231bf0d81ad795e9\srpuxnativesnapin.dll.mui", hr=0x800710da 2026-08-21T13:08:27.755 Engine:Setting original file name "netcfgx.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\ecef437036e0f3ba146480da1355f752\tcpipcfg.dll.mui", hr=0x800710da 2026-08-21T13:08:27.942 Engine:Setting original file name "WinUIEdit" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\winuiedit.dll", hr=0x800710da 2026-08-21T13:08:28.246 Engine:Setting original file name "Annot.api" for "c:\program files\adobe\acrobat dc\acrobat\plug_ins\annots.api", hr=0x800710da 2026-08-21T13:08:28.370 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libi420_rgb_mmx_plugin.dll", hr=0x800710da 2026-08-21T13:08:28.567 Engine:Setting original file name "metrocnv.dll" for "c:\program files\microsoft office\root\office16\wordcnv.dll", hr=0x800710da 2026-08-21T13:08:28.627 Engine:Setting original file name "SendTo9.Dll" for "c:\program files\microsoft office\root\office16\sendto.dll", hr=0x800710da 2026-08-21T13:08:28.663 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_ba04723bb72ef3c7\memtest.exe.mui", hr=0x800710da 2026-08-21T13:08:28.705 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.people_10.2202.100.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-08-21T13:08:28.910 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\windows\syswow64\de-de\ieadvpack.dll.mui", hr=0x800710da 2026-08-21T13:08:28.925 Engine:Setting original file name "imm32" for "c:\windows\syswow64\imm32.dll", hr=0x800710da 2026-08-21T13:08:29.199 Engine:Setting original file name "embeddedmodesvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\9a2bea5802991e6a6762bc3df43f3ddd\embeddedmodesvc.dll.mui", hr=0x800710da 2026-08-21T13:08:29.281 Engine:Setting original file name "WLRMNDR.EXE" for "c:\windows\system32\wlrmdr.exe", hr=0x800710da 2026-08-21T13:08:29.286 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libvobsub_plugin.dll", hr=0x800710da 2026-08-21T13:08:29.352 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\system32\de-de\aeevts.dll.mui", hr=0x800710da 2026-08-21T13:08:29.358 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-08-21T13:08:29.392 Engine:Setting original file name "ADVPACK.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\85cd4a7fa645bafca3ada52cccdb32d8\ieadvpack.dll.mui", hr=0x800710da 2026-08-21T13:08:29.730 Engine:Setting original file name "imageres.DLL" for "c:\windows\systemresources\imageres.dll.mun", hr=0x800710da 2026-08-21T13:08:29.774 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-21T13:08:29.842 Engine:Setting original file name "devinfoset.DLL" for "c:\windows\syswow64\devobj.dll", hr=0x800710da 2026-08-21T13:08:29.873 Engine:Setting original file name "uwfwaitui.scr.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\314e26d7f5d68950b663ddadbf78ceba\uwfservicingscr.scr.mui", hr=0x800710da 2026-08-21T13:08:30.029 Engine:Setting original file name "dual_engine_adapter.dll" for "c:\program files (x86)\microsoft\edge\application\151.0.4129.86\dual_engine_adapter_x64.dll", hr=0x800710da 2026-08-21T13:08:30.064 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\syswow64\ddores.dll", hr=0x800710da 2026-08-21T13:08:30.348 Engine:Setting original file name "secinit" for "c:\windows\syswow64\de-de\secinit.exe.mui", hr=0x800710da 2026-08-21T13:08:30.398 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\spu\liblogo_plugin.dll", hr=0x800710da 2026-08-21T13:08:30.425 Engine:Setting original file name "SECLOGON.EXE.MUI" for "c:\windows\winsxs\amd64_microsoft-windows-s..onservice.resources_31bf3856ad364e35_10.0.22000.1_de-de_622a5800b246af2a\seclogon.dll.mui", hr=0x800710da 2026-08-21T13:08:30.548 Engine:Setting original file name "OARTIMM.DLL" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\oartim.dll", hr=0x800710da 2026-08-21T13:08:30.771 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-multibyte-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:30.940 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdvbsub_plugin.dll", hr=0x800710da 2026-08-21T13:08:30.971 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirect3d9_plugin.dll", hr=0x800710da 2026-08-21T13:08:30.980 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-filesystem-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:31.035 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\devicecenter\el-gr\be5fa21b029be0db65906cbaf6601792\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:31.390 Engine:Setting original file name "Printer_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_b2d9aa5f2cb030af\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:31.474 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\windows\diagnostics\system\networking\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:31.639 Engine:Setting original file name "SaveAsWebXAML.vsl" for "c:\program files\microsoft office\root\office16\savwbxaml.dll", hr=0x800710da 2026-08-21T13:08:31.741 Engine:Setting original file name "WSecEdit.dll" for "c:\windows\systemresources\wsecedit.dll.mun", hr=0x800710da 2026-08-21T13:08:31.771 Engine:Setting original file name "HvsiEvaluator.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\8b0f7117a80f77034f86767c189c177d\hvsigpext.dll.mui", hr=0x800710da 2026-08-21T13:08:31.878 Engine:Setting original file name "hiberrsm.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\acbcfee0bb5fbaf9acca014a675b93a6\winresume.exe.mui", hr=0x800710da 2026-08-21T13:08:31.950 Engine:Setting original file name ".NET Host Resolver -" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\hostfxr.dll", hr=0x800710da 2026-08-21T13:08:31.988 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_pt-br_191dd5dd30e9e95f\memtest.exe.mui", hr=0x800710da 2026-08-21T13:08:31.999 Engine:Setting original file name "dnscmmc" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef5f6b46a93b53c08743a44cd1e27e8c\dnscmmc.dll.mui", hr=0x800710da 2026-08-21T13:08:32.281 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libavi_plugin.dll", hr=0x800710da 2026-08-21T13:08:32.350 Engine:Setting original file name "rundll32.exe" for "c:\windows\system32\rundll32.exe", hr=0x800710da 2026-08-21T13:08:32.419 Engine:Setting original file name "debugregsvc.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f6a2b3e9d13ee7fe756e07e917336377\debugregsvc.dll.mui", hr=0x800710da 2026-08-21T13:08:32.490 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libps_plugin.dll", hr=0x800710da 2026-08-21T13:08:32.509 Engine:Setting original file name "Apphelp" for "c:\windows\system32\de-de\apphelp.dll.mui", hr=0x800710da 2026-08-21T13:08:32.604 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libdemuxdump_plugin.dll", hr=0x800710da 2026-08-21T13:08:32.732 Engine:Setting original file name "VBoxGuestControl.dll" for "c:\program files\oracle\virtualbox\vboxguestcontrolsvc.dll", hr=0x800710da 2026-08-21T13:08:32.842 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libhqdn3d_plugin.dll", hr=0x800710da 2026-08-21T13:08:32.904 Engine:Setting original file name "WMDM.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2578798b7dfdcfa509d12c0b4cffb7ef\mswmdm.dll.mui", hr=0x800710da 2026-08-21T13:08:32.926 Engine:Setting original file name "mstscax.dll" for "c:\windows\winsxs\amd64_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_10.0.22000.2538_none_a905b6e8fd617528\mstscax.dll.mun", hr=0x800710da 2026-08-21T13:08:33.134 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.744.1258.0_x64__8wekyb3d8bbwe\npudetect\npudetect.dll", hr=0x800710da 2026-08-21T13:08:33.137 Engine:Setting original file name ""pnpclean.dll".mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1585848482bb5e03046c7b9ff726801\pnpclean.dll.mui", hr=0x800710da 2026-08-21T13:08:33.260 Engine:Setting original file name "SDENGINE.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\d085764e859a5745bd3663905ed28e35\sdengin2.dll.mui", hr=0x800710da 2026-08-21T13:08:33.605 Engine:Setting original file name "AdobeScCore.dll" for "c:\program files\adobe\acrobat dc\acrobat\sccore.dll", hr=0x800710da 2026-08-21T13:08:33.696 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_fr-fr_60249f05f0b2ffc7\msprivs.dll.mui", hr=0x800710da 2026-08-21T13:08:33.899 Engine:Setting original file name "dwmcore" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5e38cb0b77e870c5753b854deead7dd7\dwmcore.dll.mui", hr=0x800710da 2026-08-21T13:08:33.946 Engine:Setting original file name "stobject.dll" for "c:\windows\systemresources\stobject.dll.mun", hr=0x800710da 2026-08-21T13:08:34.261 Engine:Setting original file name "Text3D" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\5b655806d283a50089b53a18ef82998e\sstext3d.scr.mui", hr=0x800710da 2026-08-21T13:08:34.433 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_en-us_bda1cc22fdb9f7c0\msprivs.dll.mui", hr=0x800710da 2026-08-21T13:08:34.490 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\53058c376a6ad852c81665140391a604\pegi-pt.rs.mui", hr=0x800710da 2026-08-21T13:08:34.767 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\liblibbluray_plugin.dll", hr=0x800710da 2026-08-21T13:08:34.865 Engine:Setting original file name "Microsoft.Windows.Workloads.Resources.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.770.750.0_x64__8wekyb3d8bbwe\microsoft.windows.workloads.resources_ec.dll", hr=0x800710da 2026-08-21T13:08:34.872 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\winsxs\amd64_microsoft-windows-s..y-credential-picker_31bf3856ad364e35_10.0.22000.653_none_abcfd2bec0e94946\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-08-21T13:08:34.998 Engine:Setting original file name "schtasks.exe" for "c:\windows\system32\schtasks.exe", hr=0x800710da 2026-08-21T13:08:35.119 Engine:Setting original file name "DirectWriteForwarder" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2632.100.0_x64__cv1g1gvanyjgm\directwriteforwarder.dll", hr=0x800710da 2026-08-21T13:08:35.126 Engine:Setting original file name "mavinject64.exe" for "c:\windows\system32\mavinject.exe", hr=0x800710da 2026-08-21T13:08:35.291 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libantiflicker_plugin.dll", hr=0x800710da 2026-08-21T13:08:35.392 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access_output\libaccess_output_file_plugin.dll", hr=0x800710da 2026-08-21T13:08:35.667 Engine:Setting original file name "OLBNAME" for "c:\program files\microsoft office\root\office16\msprj.olb", hr=0x800710da 2026-08-21T13:08:35.782 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x64__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-08-21T13:08:35.889 Engine:Setting original file name "mmocl64.dll" for "c:\windows\system32\amdmmcl6.dll", hr=0x800710da 2026-08-21T13:08:36.147 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai\sdk\npudetect.dll", hr=0x800710da 2026-08-21T13:08:36.175 Engine:Setting original file name "NPUDetect" for "c:\program files\windowsapps\microsoft.windows.photos_2026.11060.2004.0_x64__8wekyb3d8bbwe\perceptiveshell\npudetect.dll", hr=0x800710da 2026-08-21T13:08:36.230 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_datetime_l1_1_0.dll", hr=0x800710da 2026-08-21T13:08:36.258 Engine:Setting original file name "MMFUtil.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\de-de\41801dc1862b908d41e2564f6cb4f28c\mmfutil.dll.mui", hr=0x800710da 2026-08-21T13:08:36.364 Engine:Setting original file name "IPSECSNP.DLL" for "c:\windows\systemresources\ipsecsnp.dll.mun", hr=0x800710da 2026-08-21T13:08:36.379 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-08-21T13:08:36.483 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-synch-l1-2-0.dll", hr=0x800710da 2026-08-21T13:08:36.750 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdxva2_plugin.dll", hr=0x800710da 2026-08-21T13:08:36.894 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.data.winmd", hr=0x800710da 2026-08-21T13:08:36.992 Engine:Setting original file name "MicrosoftEdgeDevTools.exe" for "c:\windows\system32\microsoftedgebchost.exe", hr=0x800710da 2026-08-21T13:08:36.995 Engine:Setting original file name "Betriebssystem Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\de-de\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:37.231 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdvdread_plugin.dll", hr=0x800710da 2026-08-21T13:08:37.466 Engine:Setting original file name "imapi.exe.mui" for "c:\windows\syswow64\de-de\imapi.dll.mui", hr=0x800710da 2026-08-21T13:08:37.515 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libtcp_plugin.dll", hr=0x800710da 2026-08-21T13:08:37.553 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-21T13:08:37.645 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.applicationmodel.winmd", hr=0x800710da 2026-08-21T13:08:37.882 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.security.winmd", hr=0x800710da 2026-08-21T13:08:37.987 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:38.004 Engine:Setting original file name ""TextInputFramework.DYNLINK"" for "c:\windows\syswow64\textinputframework.dll", hr=0x800710da 2026-08-21T13:08:38.091 Engine:Setting original file name "Maintenance_DiagPackage.dll.mui" for "c:\windows\diagnostics\scheduled\maintenance\de-de\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:38.549 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librist_plugin.dll", hr=0x800710da 2026-08-21T13:08:38.649 Engine:Setting original file name "bootres" for "c:\windows\winsxs\amd64_microsoft-windows-bootres.resources_31bf3856ad364e35_10.0.22000.1_de-de_8f18303c6c8c7d94\bootres.dll.mui", hr=0x800710da 2026-08-21T13:08:38.733 Engine:Setting original file name "msacm32.acm.mui" for "c:\windows\syswow64\de-de\msacm32.drv.mui", hr=0x800710da 2026-08-21T13:08:39.065 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libsftp_plugin.dll", hr=0x800710da 2026-08-21T13:08:39.086 Engine:Setting original file name "TSSignTool.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\75632512cece20e30d812381852074c9\rdpsign.exe.mui", hr=0x800710da 2026-08-21T13:08:39.103 Engine:Setting original file name "Windows SDK" for "c:\windows\system32\winmetadata\windows.system.winmd", hr=0x800710da 2026-08-21T13:08:39.344 Engine:Setting original file name "msvcr100_clr0400.dll" for "c:\windows\syswow64\msvcr100.dll", hr=0x800710da 2026-08-21T13:08:39.472 Engine:Setting original file name "appidsvc.dll.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-appid.resources_31bf3856ad364e35_10.0.22000.1_de-de_e37d50b0c2c5cc74_appidsvc.dll.mui_6717e231", hr=0x800710da 2026-08-21T13:08:39.512 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-core-file-l1-2-0.dll", hr=0x800710da 2026-08-21T13:08:39.632 Engine:Setting original file name "ndisimplatwmi.DLL.MUI" for "c:\windows\winsxs\wow64_microsoft-windows-n..mplatform.resources_31bf3856ad364e35_10.0.22000.1_de-de_545b08052b95c023\ndisimplatcim.dll.mui", hr=0x800710da 2026-08-21T13:08:39.783 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libcaf_plugin.dll", hr=0x800710da 2026-08-21T13:08:39.793 Engine:Setting original file name "uhssvc" for "c:\program files\microsoft update health tools\uhssvc.exe", hr=0x800710da 2026-08-21T13:08:40.038 Engine:Setting original file name "libcrypto" for "c:\program files\microsoft onedrive\26.139.0720.0007\libcrypto-3-x64.dll", hr=0x800710da 2026-08-21T13:08:40.052 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libvorbis_plugin.dll", hr=0x800710da 2026-08-21T13:08:40.152 Engine:Setting original file name "setup" for "c:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe", hr=0x800710da 2026-08-21T13:08:40.167 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\framework\v2.0.50727\system.windows.forms.tlb", hr=0x800710da 2026-08-21T13:08:40.251 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-21T13:08:40.582 Engine:Setting original file name "ISOLMIG.DLL" for "c:\windows\winsxs\wow64_microsoft-windows-m..tion-isolationlayer_31bf3856ad364e35_10.0.22000.1_none_be884a074186c4ab\migisol.dll", hr=0x800710da 2026-08-21T13:08:40.630 Engine:Setting original file name "LODCTR.DLL.MUI" for "c:\windows\system32\de-de\loadperf.dll.mui", hr=0x800710da 2026-08-21T13:08:40.635 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_gather_plugin.dll", hr=0x800710da 2026-08-21T13:08:40.699 Engine:Setting original file name "secinit" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\31196c1b6e70d8895ea664e5dacecfcf\secinit.exe.mui", hr=0x800710da 2026-08-21T13:08:40.743 Engine:Setting original file name "dwmscenei" for "c:\program files\microsoft office\root\office16\winappsdk\dwmscenei.dll", hr=0x800710da 2026-08-21T13:08:41.146 Engine:Setting original file name "sqlite3" for "c:\windows\system32\winsqlite3.dll", hr=0x800710da 2026-08-21T13:08:41.465 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libcompressor_plugin.dll", hr=0x800710da 2026-08-21T13:08:41.523 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\mux\libmux_avi_plugin.dll", hr=0x800710da 2026-08-21T13:08:41.548 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\services_discovery\libmediadirs_plugin.dll", hr=0x800710da 2026-08-21T13:08:41.693 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libdcp_plugin.dll", hr=0x800710da 2026-08-21T13:08:41.760 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_stats_plugin.dll", hr=0x800710da 2026-08-21T13:08:41.795 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-08-21T13:08:41.898 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\3c213aafced6b715dc1708977d20ac67\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:42.024 Engine:Setting original file name "pegi-pt.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\pegi-pt.rs.mui", hr=0x800710da 2026-08-21T13:08:42.175 Engine:Setting original file name "filterLib.dll" for "c:\windows\syswow64\fltlib.dll", hr=0x800710da 2026-08-21T13:08:42.260 Engine:Setting original file name "Microsoft® .NET Framework" for "c:\program files\windowsapps\microsoft.xbox.tcui_1.24.10001.0_x64__8wekyb3d8bbwe\clrcompression.dll", hr=0x800710da 2026-08-21T13:08:42.319 Engine:Setting original file name "ShADprop.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ef967ec0af326ba66d8258744c103909\dsprop.dll.mui", hr=0x800710da 2026-08-21T13:08:42.384 Engine:Setting original file name "AppVEntSubsystems.dll" for "c:\windows\syswow64\appventsubsystems32.dll", hr=0x800710da 2026-08-21T13:08:42.403 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_block_plugin.dll", hr=0x800710da 2026-08-21T13:08:42.474 Engine:Setting original file name "WindowsCodecs" for "c:\windows\system32\windowscodecs.dll", hr=0x800710da 2026-08-21T13:08:43.111 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\boot\de-de\87bc9d043511a9098a7aa6d43b9356f4\winload.exe.mui", hr=0x800710da 2026-08-21T13:08:43.496 Engine:Setting original file name "MicrosoftRawCodec" for "c:\windows\winsxs\wow64_microsoft-windows-windowscodecraw_31bf3856ad364e35_10.0.22000.1219_none_188021b123c01a8a\windowscodecsraw.dll", hr=0x800710da 2026-08-21T13:08:43.525 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-21T13:08:43.597 Engine:Setting original file name "davsvc.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\56230aefe1a5f7ef32b3b4b9372ce0da\webclnt.dll.mui", hr=0x800710da 2026-08-21T13:08:44.112 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubsusf_plugin.dll", hr=0x800710da 2026-08-21T13:08:44.498 Engine:Setting original file name "gdi32" for "c:\windows\syswow64\gdi32full.dll", hr=0x800710da 2026-08-21T13:08:44.555 Engine:Setting original file name "ddputils.lib.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\eccf9541753be0b74164bcaea547d45d\ddputils.dll.mui", hr=0x800710da 2026-08-21T13:08:44.688 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_filter\libcache_read_plugin.dll", hr=0x800710da 2026-08-21T13:08:44.910 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libfreeze_plugin.dll", hr=0x800710da 2026-08-21T13:08:44.942 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspudec_plugin.dll", hr=0x800710da 2026-08-21T13:08:45.194 Engine:Setting original file name "msinfo.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\common files\microsoft shared\msinfo\de-de\b8febddb53a0bffcf3cff4ac6892b632\msinfo32.exe.mui", hr=0x800710da 2026-08-21T13:08:45.254 Engine:Setting original file name "mmcbase.dll" for "c:\windows\systemresources\mmcbase.dll.mun", hr=0x800710da 2026-08-21T13:08:45.313 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libwingdi_plugin.dll", hr=0x800710da 2026-08-21T13:08:45.345 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_core_localization_l1_2_0.dll", hr=0x800710da 2026-08-21T13:08:45.449 Engine:Setting original file name "bcastdvrusersvc.dll.mui" for "c:\windows\system32\de-de\bcastdvruserservice.dll.mui", hr=0x800710da 2026-08-21T13:08:45.833 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\en-us_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:08:46.068 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\gui\libqt_plugin.dll", hr=0x800710da 2026-08-21T13:08:46.116 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_av1_plugin.dll", hr=0x800710da 2026-08-21T13:08:46.619 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-21T13:08:46.869 Engine:Setting original file name "DWriteCore" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\dwritecore.dll", hr=0x800710da 2026-08-21T13:08:46.979 Engine:Setting original file name "ERC" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\d04ef706fd80591e6537eec21dc8a805\wercplsupport.dll.mui", hr=0x800710da 2026-08-21T13:08:47.284 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\el-gr\memtest.efi.mui", hr=0x800710da 2026-08-21T13:08:47.357 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-runtime-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:47.409 Engine:Setting original file name "LicensingWinRuntime.dll" for "c:\windows\syswow64\licensingwinrt.dll", hr=0x800710da 2026-08-21T13:08:47.413 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-stdio-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:47.458 Engine:Setting original file name "NetAdapter.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-n..daptercim.resources_31bf3856ad364e35_10.0.22000.1_de-de_ad586773a2c5f1f9\netadaptercim.dll.mui", hr=0x800710da 2026-08-21T13:08:47.553 Engine:Setting original file name "desktop-launcher.exe" for "c:\users\ithan\desktop\firefox.exe", hr=0x800710da 2026-08-21T13:08:47.603 Engine:Setting original file name "utilman2.exe.mui" for "c:\windows\system32\de-de\utilman.exe.mui", hr=0x800710da 2026-08-21T13:08:47.660 Engine:Setting original file name "iscsicpl.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\0ead269312ac4b0d059f3326cad715e2\iscsicpl.dll.mui", hr=0x800710da 2026-08-21T13:08:47.750 Engine:Setting original file name "WUDFPf.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-d..-usermode.resources_31bf3856ad364e35_10.0.22000.1_de-de_74374e426d967c20_wudfpf.sys.mui_f61e9e86", hr=0x800710da 2026-08-21T13:08:47.767 Engine:Setting original file name "ADL" for "c:\windows\syswow64\atiadlxy.dll", hr=0x800710da 2026-08-21T13:08:47.777 Engine:Setting original file name "NearByShareExperience.dll.mui" for "c:\windows\system32\de-de\microsoft-windows-internal-shell-nearshareexperience.dll.mui", hr=0x800710da 2026-08-21T13:08:47.814 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libfaad_plugin.dll", hr=0x800710da 2026-08-21T13:08:47.822 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libaribsub_plugin.dll", hr=0x800710da 2026-08-21T13:08:48.060 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.2_2000.802.31.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-21T13:08:48.065 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\boot\el-gr\87bc9d043511a9098a7aa6d43b9356f4\winload.efi.mui", hr=0x800710da 2026-08-21T13:08:48.097 Engine:Setting original file name "System.IO.Compression.Native" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\system.io.compression.native.dll", hr=0x800710da 2026-08-21T13:08:48.167 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libty_plugin.dll", hr=0x800710da 2026-08-21T13:08:48.270 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libaiff_plugin.dll", hr=0x800710da 2026-08-21T13:08:48.443 Engine:Setting original file name "Atiamaxx.dll" for "c:\program files (x86)\ati technologies\ati.ace\core-static\atiama64.dll", hr=0x800710da 2026-08-21T13:08:48.667 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sl-si_369db5b8fade7cb8\sl-si_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:08:48.903 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libgain_plugin.dll", hr=0x800710da 2026-08-21T13:08:49.035 Engine:Setting original file name "mf.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\c44b46f32714a135f6326395455c7097\mfpmp.exe.mui", hr=0x800710da 2026-08-21T13:08:49.105 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-math-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:49.278 Engine:Setting original file name "MORICONS.DLL" for "c:\windows\systemresources\moricons.dll.mun", hr=0x800710da 2026-08-21T13:08:49.497 Engine:Setting original file name "OSFMount " for "c:\users\ithan\desktop\portdesktop\3_portable\portable\osfm1015\osfmount.exe", hr=0x800710da 2026-08-21T13:08:49.554 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_string_l1_1_0.dll", hr=0x800710da 2026-08-21T13:08:49.675 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-core-xstate-l2-1-0.dll", hr=0x800710da 2026-08-21T13:08:49.722 Engine:Setting original file name "MORPH10.DLL" for "c:\program files\microsoft office\root\office16\morph9.dll", hr=0x800710da 2026-08-21T13:08:49.809 Engine:Setting original file name "scfilter.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-s..em-extras.resources_31bf3856ad364e35_10.0.22000.1_de-de_101a65ba50658f02_scfilter.sys.mui_cebab716", hr=0x800710da 2026-08-21T13:08:50.093 Engine:Setting original file name "CertEnroll" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\fedb03f818780ac8bd5bb7c6b5523a01\certenroll.dll.mui", hr=0x800710da 2026-08-21T13:08:50.141 Engine:Setting original file name "vlc.exe" for "c:\program files\videolan\vlc\vlc-cache-gen.exe", hr=0x800710da 2026-08-21T13:08:50.185 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_delay_plugin.dll", hr=0x800710da 2026-08-21T13:08:50.202 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_hevc_plugin.dll", hr=0x800710da 2026-08-21T13:08:50.218 Engine:Setting original file name "osloader.exe" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\576e09eb4af48a97810786c42c5cc8c7\winload.exe.mui", hr=0x800710da 2026-08-21T13:08:50.272 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_hu-hu_0174f2839b8ec2e3\memtest.exe.mui", hr=0x800710da 2026-08-21T13:08:50.496 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libdirectdraw_plugin.dll", hr=0x800710da 2026-08-21T13:08:50.503 Engine:Setting original file name "DeviceCategories.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\ea8b43ef4d346283540d80cf108935da\ddores.dll.mui", hr=0x800710da 2026-08-21T13:08:50.562 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-process-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:50.938 Engine:Setting original file name "Microsoft.Graphics.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x86__8wekyb3d8bbwe\microsoft.graphics.display.dll", hr=0x800710da 2026-08-21T13:08:51.029 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_filter\libcroppadd_plugin.dll", hr=0x800710da 2026-08-21T13:08:51.372 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\5319275a.whatsappdesktop_2.2632.100.0_x64__cv1g1gvanyjgm\coremessagingxp.dll", hr=0x800710da 2026-08-21T13:08:51.525 Engine:Setting original file name "spwizres.dll" for "c:\windows\system32\spwizimg.dll", hr=0x800710da 2026-08-21T13:08:51.805 Engine:Setting original file name "audioepb.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\cbfe5d55efef45f02bc86a1f34aab086\audioendpointbuilder.dll.mui", hr=0x800710da 2026-08-21T13:08:51.854 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_zh-tw_212473e6e24cae42\msprivs.dll.mui", hr=0x800710da 2026-08-21T13:08:51.904 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\visualization\libgoom_plugin.dll", hr=0x800710da 2026-08-21T13:08:52.274 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.519.329.0_x64__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-21T13:08:52.442 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsvcdsub_plugin.dll", hr=0x800710da 2026-08-21T13:08:52.777 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\libaccess_realrtsp_plugin.dll", hr=0x800710da 2026-08-21T13:08:52.825 Engine:Setting original file name "mmcndmgr.dll" for "c:\windows\systemresources\mmcndmgr.dll.mun", hr=0x800710da 2026-08-21T13:08:53.048 Engine:Setting original file name "apisetstub" for "c:\program files (x86)\hisuite\api_ms_win_crt_heap_l1_1_0.dll", hr=0x800710da 2026-08-21T13:08:53.284 Engine:Setting original file name ""IME_TextInputHelpers.DYNLINK".MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\b9f393ae851b06d4a035ca5d63f57c66\ime_textinputhelpers.dll.mui", hr=0x800710da 2026-08-21T13:08:53.347 Engine:Setting original file name "MsoIntl.dll" for "c:\program files\windowsapps\microsoft.windowscommunicationsapps_16005.14326.22342.0_x64__8wekyb3d8bbwe\en-gb\msointlimm.dll", hr=0x800710da 2026-08-21T13:08:53.383 Engine:Setting original file name "WinUIEdit" for "c:\program files\microsoft office\root\office16\winappsdk\winuiedit.dll", hr=0x800710da 2026-08-21T13:08:53.453 Engine:Setting original file name "kernel32" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\63f568702d686717211e91531e7807ec\kernel32.dll.mui", hr=0x800710da 2026-08-21T13:08:53.531 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_da-dk_671089d19f20c966\memtest.efi.mui", hr=0x800710da 2026-08-21T13:08:53.555 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liba52_plugin.dll", hr=0x800710da 2026-08-21T13:08:53.643 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\microsoft.net\assembly\gac_msil\accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\accessibility.dll", hr=0x800710da 2026-08-21T13:08:53.720 Engine:Setting original file name "MSACC9.OLB" for "c:\program files\microsoft office\root\office16\msacc.olb", hr=0x800710da 2026-08-21T13:08:53.906 Engine:Setting original file name "gpprefcl" for "c:\windows\system32\de-de\gpprefcl.dll.mui", hr=0x800710da 2026-08-21T13:08:53.936 Engine:Setting original file name "RRASUPG.DLL" for "c:\windows\syswow64\setup\rasmigplugin.dll", hr=0x800710da 2026-08-21T13:08:54.425 Engine:Setting original file name "amdhcp32.dll" for "c:\windows\system32\amdhcp64.dll", hr=0x800710da 2026-08-21T13:08:54.927 Engine:Setting original file name "esrb.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\esrb.rs.mui", hr=0x800710da 2026-08-21T13:08:55.024 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\bluetooth\el-gr\b330cc0822e6f7e65fcf5402452fcab1\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:55.151 Engine:Setting original file name "WMDM.dll.mui" for "c:\windows\system32\de-de\mswmdm.dll.mui", hr=0x800710da 2026-08-21T13:08:55.491 Engine:Setting original file name "QEdWipes.dll" for "c:\windows\systemresources\qedwipes.dll.mun", hr=0x800710da 2026-08-21T13:08:55.576 Engine:Setting original file name "ETWCoreUIComponentsResources.dll" for "c:\windows\winsxs\amd64_microsoft-windows-c..uicomponents-events_31bf3856ad364e35_10.0.22000.1_none_060420b87367bb9d\etwcoreuicomponentsresources.dll.mun", hr=0x800710da 2026-08-21T13:08:55.613 Engine:Setting original file name "MFC42.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a0954090cb9e3a6dba3e4178a3aeb73b\mfc42u.dll.mui", hr=0x800710da 2026-08-21T13:08:55.652 Engine:Setting original file name "bfsvc.exe" for "c:\windows\system32\ucsvc.exe", hr=0x800710da 2026-08-21T13:08:55.711 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_mixer\libinteger_mixer_plugin.dll", hr=0x800710da 2026-08-21T13:08:55.727 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\iebrowseweb\el-gr\43307d8a0be2826e20c260103251d4c4\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:55.827 Engine:Setting original file name "FontCacheService" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a801eaa64f7106bd10000bdf6b8f006f\fntcache.dll.mui", hr=0x800710da 2026-08-21T13:08:55.871 Engine:Setting original file name "VCAMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcamp140_app.dll", hr=0x800710da 2026-08-21T13:08:55.952 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\logger\libconsole_logger_plugin.dll", hr=0x800710da 2026-08-21T13:08:56.005 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\system32\de-de\wlrmdr.exe.mui", hr=0x800710da 2026-08-21T13:08:56.084 Engine:Setting original file name "IEBrowseWeb_DiagPackage.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-i..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_9fcefeb7dd7451b1\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:08:56.199 Engine:Setting original file name "PenImc" for "c:\program files\windowsapps\microsoft.yourphone_1.25072.79.0_x64__8wekyb3d8bbwe\penimc_cor3.dll", hr=0x800710da 2026-08-21T13:08:56.499 Engine:Setting original file name "pcbp.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\8c26245c42cbd227a892c2fdba4af983\pcbp.rs.mui", hr=0x800710da 2026-08-21T13:08:56.726 Engine:Setting original file name " " for "c:\program files (x86)\microsoft\edgewebview\application\151.0.4129.93\dxcompiler.dll", hr=0x800710da 2026-08-21T13:08:56.744 Engine:Setting original file name "lhdfrgui.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\a0aea013558eb6aadc415a385f5fbe06\dfrgui.exe.mui", hr=0x800710da 2026-08-21T13:08:56.889 Engine:Setting original file name "wrs.dll.mui" for "c:\windows\system32\en-us\web.rs.mui", hr=0x800710da 2026-08-21T13:08:57.105 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\meta_engine\libtaglib_plugin.dll", hr=0x800710da 2026-08-21T13:08:57.360 Engine:Setting original file name "Ribbons" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\b808f4af8b21f3215e2a294f4ed50441\ribbons.scr.mui", hr=0x800710da 2026-08-21T13:08:57.431 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\en-us\memtest.efi.mui", hr=0x800710da 2026-08-21T13:08:57.622 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libsubstx3g_plugin.dll", hr=0x800710da 2026-08-21T13:08:57.974 Engine:Setting original file name "TARGET_NAME.dll" for "c:\program files\microsoft office\root\office16\cpprestsdk.dll", hr=0x800710da 2026-08-21T13:08:58.174 Engine:Setting original file name "dmdskres.dll" for "c:\windows\systemresources\dmdskres.dll.mun", hr=0x800710da 2026-08-21T13:08:58.489 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\librawvideo_plugin.dll", hr=0x800710da 2026-08-21T13:08:58.502 Engine:Setting original file name "SOA1000.DLL" for "c:\program files\microsoft office\root\office16\soa.dll", hr=0x800710da 2026-08-21T13:08:58.811 Engine:Setting original file name "mapi32.dll" for "c:\windows\syswow64\mapistub.dll", hr=0x800710da 2026-08-21T13:08:58.925 Engine:Setting original file name "SR.exe.mui" for "c:\windows\winsxs\amd64_microsoft-windows-narrator.resources_31bf3856ad364e35_10.0.22000.1_de-de_73a872336658cea5\narrator.exe.mui", hr=0x800710da 2026-08-21T13:08:59.021 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libxa_plugin.dll", hr=0x800710da 2026-08-21T13:08:59.644 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_chroma\libyuy2_i422_plugin.dll", hr=0x800710da 2026-08-21T13:08:59.845 Engine:Setting original file name "SCardSvr.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5c9de808650befd07338b97093d13884\scardsvr.dll.mui", hr=0x800710da 2026-08-21T13:08:59.866 Engine:Setting original file name "ServDeps.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\wbem\el-gr\e15a2ee2d783965c719679ae3f2882af\servdeps.dll.mui", hr=0x800710da 2026-08-21T13:08:59.939 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-string-l1-1-0.dll", hr=0x800710da 2026-08-21T13:08:59.949 Engine:Setting original file name "cob-au.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e1046ccdcbee2bdc23f555528616f847\cob-au.rs.mui", hr=0x800710da 2026-08-21T13:08:59.957 Engine:Setting original file name "CONHOST.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f73cf41700fa48d35b91a8125061a9f7\conhostv1.dll.mui", hr=0x800710da 2026-08-21T13:09:00.534 Engine:Setting original file name " " for "c:\program files\uvnc bvba\ultravnc\unins000.exe", hr=0x800710da 2026-08-21T13:09:00.567 Engine:Setting original file name "SR.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\4054450b151f58398287c806a6b29b0b\narrator.exe.mui", hr=0x800710da 2026-08-21T13:09:00.642 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-lsa-msprivs.resources_31bf3856ad364e35_10.0.22000.1_da-dk_178560ee0d059761\msprivs.dll.mui", hr=0x800710da 2026-08-21T13:09:00.898 Engine:Setting original file name "CRProcessMonitor .exe" for "c:\program files\adobe\acrobat dc\acrobat\adobe crash processor.exe", hr=0x800710da 2026-08-21T13:09:00.921 Engine:Setting original file name "NPUDetect" for "c:\program files\microsoft office\root\office16\winappsdk\npudetect.dll", hr=0x800710da 2026-08-21T13:09:01.133 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libspeex_plugin.dll", hr=0x800710da 2026-08-21T13:09:01.184 Engine:Setting original file name "updater.exe" for "c:\program files\mozilla firefox\tobedeleted\moz58aac614-6550-4884-84c5-51adac2f1e79", hr=0x800710da 2026-08-21T13:09:01.230 Engine:Setting original file name "oflc-nz.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\09a3572337f4c2b28ed1ffda13fd7fbe\oflc-nz.rs.mui", hr=0x800710da 2026-08-21T13:09:01.273 Engine:Setting original file name "clusapi" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\40ee7e569f062bf19b200f51536c9e05\clusapi.dll.mui", hr=0x800710da 2026-08-21T13:09:01.285 Engine:Setting original file name "aero.msstyles.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\resources\themes\aero\de-de\0654f51b71166cbb924d16f03cc94f87\aerolite.msstyles.mui", hr=0x800710da 2026-08-21T13:09:01.536 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\system32\mp4sdecd.dll", hr=0x800710da 2026-08-21T13:09:01.733 Engine:Setting original file name "rastls.dll" for "c:\windows\systemresources\rastls.dll.mun", hr=0x800710da 2026-08-21T13:09:02.385 Engine:Setting original file name "mspriv.dll.mui" for "c:\windows\system32\nl-nl\msprivs.dll.mui", hr=0x87af000b 2026-08-21T13:09:02.604 Engine:Setting original file name "unpnhost.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\243d7219c5bb9c7bb80f1bb2effe6745\upnphost.dll.mui", hr=0x800710da 2026-08-21T13:09:02.609 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\office16\api-ms-win-crt-conio-l1-1-0.dll", hr=0x800710da 2026-08-21T13:09:02.680 Engine:Setting original file name "nbtinfo.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\5f57053eda213d0b999f218c0f3ba1d1\nbtstat.exe.mui", hr=0x800710da 2026-08-21T13:09:02.855 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\amd64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_de-de_643c1f0da0f71e00\memtest.efi.mui", hr=0x800710da 2026-08-21T13:09:03.247 Engine:Setting original file name "ShADprop.dll.mui" for "c:\windows\winsxs\amd64_dsprop.resources_31bf3856ad364e35_10.0.22000.1_de-de_07bf09b0a52dc82f\dsprop.dll.mui", hr=0x800710da 2026-08-21T13:09:03.251 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\pcat\en-us\memtest.exe.mui", hr=0x800710da 2026-08-21T13:09:03.255 Engine:Setting original file name "pegi.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a9ac302171ad085daaa94da794af3532\pegi.rs.mui", hr=0x800710da 2026-08-21T13:09:03.372 Engine:Setting original file name "MAPI32.DLL" for "c:\program files\microsoft office\root\office16\olmapi32.dll", hr=0x800710da 2026-08-21T13:09:03.398 Engine:Setting original file name "1E.Client.DataBridge" for "c:\program files\teamviewer\1e.client.databridge.dll", hr=0x800710da 2026-08-21T13:09:03.504 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\stream_out\libstream_out_rtp_plugin.dll", hr=0x800710da 2026-08-21T13:09:03.616 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\access\librtp_plugin.dll", hr=0x800710da 2026-08-21T13:09:03.881 Engine:Setting original file name "memdiag.exe" for "c:\windows\boot\efi\pt-pt\memtest.efi.mui", hr=0x800710da 2026-08-21T13:09:03.967 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\libtta_plugin.dll", hr=0x800710da 2026-08-21T13:09:03.982 Engine:Triggered AR EMS scan 2026-08-21T13:09:03.987 Engine:EMS scan for process: lsass pid: 776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.012 Engine:EMS scan for process: svchost pid: 984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.026 Engine:EMS scan for process: svchost pid: 576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.029 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.035 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.046 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.051 Engine:EMS scan for process: svchost pid: 1332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.054 Engine:Setting original file name "Bubbles" for "c:\windows\winsxs\amd64_microsoft-windows-bubbles.resources_31bf3856ad364e35_10.0.22000.1_de-de_79ab474eb3128fbb\bubbles.scr.mui", hr=0x87af000b 2026-08-21T13:09:04.061 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.064 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.066 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.072 Engine:EMS scan for process: svchost pid: 1532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.080 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.083 Engine:EMS scan for process: svchost pid: 1604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.084 Engine:Setting original file name "TWINUI.dll" for "c:\windows\systemresources\twinui.dll.mun", hr=0x800710da 2026-08-21T13:09:04.088 Engine:EMS scan for process: svchost pid: 1612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.091 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.095 Engine:EMS scan for process: svchost pid: 1740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.100 Engine:EMS scan for process: svchost pid: 1812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.107 Engine:EMS scan for process: svchost pid: 1940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.113 Engine:EMS scan for process: svchost pid: 2052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.117 Engine:EMS scan for process: svchost pid: 2128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.120 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.127 Engine:EMS scan for process: svchost pid: 2384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.130 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.139 Engine:EMS scan for process: svchost pid: 2512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.142 Engine:EMS scan for process: svchost pid: 2524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.145 Engine:EMS scan for process: svchost pid: 2540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.149 Engine:EMS scan for process: svchost pid: 2668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.152 Engine:EMS scan for process: svchost pid: 2700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.155 Engine:EMS scan for process: svchost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.162 Engine:EMS scan for process: svchost pid: 2756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.165 Engine:EMS scan for process: svchost pid: 2988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.171 Engine:EMS scan for process: svchost pid: 1096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.177 Engine:EMS scan for process: svchost pid: 2812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.181 Engine:EMS scan for process: svchost pid: 3416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.184 Engine:EMS scan for process: svchost pid: 3424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.187 Engine:EMS scan for process: svchost pid: 3472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.192 Engine:EMS scan for process: svchost pid: 3500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.197 Engine:EMS scan for process: svchost pid: 3944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.201 Engine:EMS scan for process: svchost pid: 4048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.206 Engine:EMS scan for process: svchost pid: 4064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.210 Engine:EMS scan for process: svchost pid: 3064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.218 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.225 Engine:EMS scan for process: svchost pid: 4220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.230 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.239 Engine:EMS scan for process: svchost pid: 4340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.242 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.247 Engine:EMS scan for process: svchost pid: 5100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.253 Engine:EMS scan for process: dllhost pid: 5860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.256 Engine:EMS scan for process: svchost pid: 5896, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.259 Engine:EMS scan for process: svchost pid: 5876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.262 Engine:EMS scan for process: svchost pid: 6244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.269 Engine:EMS scan for process: svchost pid: 6252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.277 Engine:EMS scan for process: svchost pid: 6388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.285 Engine:EMS scan for process: svchost pid: 6584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.291 Engine:EMS scan for process: svchost pid: 6652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.298 Engine:EMS scan for process: svchost pid: 6860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.301 Bm signature throttled:0x00002db31bed458f 2026-08-21T13:09:04.303 Engine:EMS scan for process: svchost pid: 6908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.312 Engine:EMS scan for process: svchost pid: 5456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.318 Engine:EMS scan for process: explorer pid: 7428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.376 Engine:EMS scan for process: svchost pid: 7704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.383 Engine:EMS scan for process: svchost pid: 7828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.387 Engine:EMS scan for process: svchost pid: 7892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.397 Engine:EMS scan for process: svchost pid: 6928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.402 Engine:EMS scan for process: svchost pid: 8496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.406 Engine:EMS scan for process: svchost pid: 9672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.413 Engine:EMS scan for process: dllhost pid: 9972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.415 Bm signature throttled:0x00002db31bed458f 2026-08-21T13:09:04.416 Engine:EMS scan for process: svchost pid: 11160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.420 Engine:EMS scan for process: svchost pid: 11252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.426 Engine:EMS scan for process: svchost pid: 10788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.431 Engine:EMS scan for process: svchost pid: 13144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.435 Engine:EMS scan for process: svchost pid: 13048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.439 Engine:EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.441 Engine:Setting original file name "geek.exe" for "c:\users\ithan\appdata\local\temp\geek64.exe", hr=0x800710da 2026-08-21T13:09:04.442 Engine:EMS scan for process: svchost pid: 10760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.463 Engine:EMS scan for process: svchost pid: 7500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.468 Engine:EMS scan for process: svchost pid: 5180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.475 Engine:EMS scan for process: svchost pid: 4452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.481 Engine:EMS scan for process: svchost pid: 3440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.489 Engine:EMS scan for process: dllhost pid: 7576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.491 Engine:EMS scan for process: svchost pid: 3120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.494 Engine:EMS scan for process: dllhost pid: 12604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.497 Engine:EMS scan for process: explorer pid: 12268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.508 Engine:EMS scan for process: svchost pid: 11172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.516 Engine:EMS scan for process: dllhost pid: 2064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.520 Engine:EMS scan for process: svchost pid: 2452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.522 Engine:EMS scan for process: dllhost pid: 11976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.525 Engine:EMS scan for process: dllhost pid: 13152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.528 Engine:EMS scan for process: dllhost pid: 9348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.533 Engine:EMS scan for process: svchost pid: 10752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:09:04.636 Engine:Setting original file name "SaveAsWebVML.vsl" for "c:\program files\microsoft office\root\office16\savwbras.dll", hr=0x800710da 2026-08-21T13:09:05.070 Engine:Setting original file name ""ApplyTrustOffline.PROGRAM"" for "c:\windows\system32\applytrustoffline.exe", hr=0x800710da 2026-08-21T13:09:05.249 Engine:Setting original file name "iccvid.drv.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\a664d3bfb84a6d6f09cb25b13627b3c7\iccvid.dll.mui", hr=0x800710da 2026-08-21T13:09:05.285 Engine:Setting original file name "PDFViewerIEPlugin.dll" for "c:\program files\tracker software\pdf viewer\win32\pdfxcviewieplugin.dll", hr=0x800710da 2026-08-21T13:09:05.496 Engine:Setting original file name "SHELL32.DLL" for "c:\windows\systemresources\shell32.dll.mun", hr=0x800710da 2026-08-21T13:09:05.532 Engine:Setting original file name "Vulkan Runtime" for "c:\program files (x86)\microsoft\skype for desktop\vulkan-1.dll", hr=0x800710da 2026-08-21T13:09:05.611 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\audio_filter\libtospdif_plugin.dll", hr=0x800710da 2026-08-21T13:09:05.671 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_sr-..-rs_dcce1dfd6ff023e9\sr-latn-rs_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:09:05.825 Engine:Setting original file name "CoreMessaging.dll" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.7_7000.785.2325.0_x86__8wekyb3d8bbwe\coremessagingxp.dll", hr=0x800710da 2026-08-21T13:09:05.842 Engine:Setting original file name "powershell.exe" for "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe", hr=0x87af000b 2026-08-21T13:09:05.866 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..gon-tools.resources_31bf3856ad364e35_10.0.22000.1_de-de_c2ff583ea79f308d_wlrmdr.exe.mui_ee563c83", hr=0x800710da 2026-08-21T13:09:06.012 Engine:Setting original file name "ImagingDevices.cpl.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\program files\windows photo viewer\de-de\982914dc7eceadd06e84b21adc384339\imagingdevices.exe.mui", hr=0x800710da 2026-08-21T13:09:06.052 Engine:Setting original file name "dwmcorei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe\dwmcorei.dll", hr=0x800710da 2026-08-21T13:09:06.121 Engine:Setting original file name "winrnr" for "c:\windows\syswow64\winrnr.dll", hr=0x800710da 2026-08-21T13:09:06.156 Engine:Setting original file name "MrmCore.dll" for "c:\windows\system32\mrmcorer.dll", hr=0x87af000b 2026-08-21T13:09:06.161 Engine:Setting original file name "ContextH.exe.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\e9a9976924f9b0d35abab49f15e2d327\bwcontexthandler.dll.mui", hr=0x800710da 2026-08-21T13:09:06.418 Engine:Setting original file name "CRLogTransport .exe" for "c:\program files\adobe\acrobat dc\acrobat\crlogtransport.exe", hr=0x800710da 2026-08-21T13:09:06.521 Engine:Setting original file name "dwmscenei" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.6_6000.457.2140.0_x64__8wekyb3d8bbwe\dwmscenei.dll", hr=0x800710da 2026-08-21T13:09:06.578 Engine:Setting original file name "VCOMP140.DLL" for "c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.33519.0_x86__8wekyb3d8bbwe\vcomp140_app.dll", hr=0x800710da 2026-08-21T13:09:06.605 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\packetizer\libpacketizer_dts_plugin.dll", hr=0x800710da 2026-08-21T13:09:06.806 Engine:Setting original file name "sqlite3" for "c:\windows\syswow64\winsqlite3.dll", hr=0x800710da 2026-08-21T13:09:06.901 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\winsxs\x86_microsoft-windows-s..-binaries.resources_31bf3856ad364e35_10.0.22000.1_ro-ro_960843c806afb4db\ro-ro_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:09:06.919 Engine:Setting original file name "Λειτουργικό σύστημα Microsoft® Windows®" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\networking\el-gr\36ccdff4202f00249567458e14bbd267\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:09:06.932 Engine:Setting original file name "scrnsave" for "c:\windows\syswow64\de-de\scrnsave.scr.mui", hr=0x800710da 2026-08-21T13:09:06.961 Engine:Setting original file name "apisetstub" for "c:\program files\microsoft office\root\vfs\programfilesx86\microsoft office\office16\api-ms-win-crt-locale-l1-1-0.dll", hr=0x800710da 2026-08-21T13:09:07.193 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libzvbi_plugin.dll", hr=0x800710da 2026-08-21T13:09:07.535 Engine:Setting original file name "Windows.Security.Credentials.UI.CredentialPicker.exe" for "c:\windows\syswow64\windows.security.credentials.ui.credentialpicker.dll", hr=0x800710da 2026-08-21T13:09:07.612 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_it-it_a42c68828e60d945\memtest.exe.mui", hr=0x800710da 2026-08-21T13:09:07.758 Engine:Setting original file name "djctq.dll.mui" for "c:\windows\winsxs\amd64_microsoft-windows-p..gssystems.resources_31bf3856ad364e35_10.0.22000.1_de-de_0954536deee5b242\djctq.rs.mui", hr=0x87af000b 2026-08-21T13:09:07.859 Engine:Setting original file name "wuceffects" for "c:\program files\windowsapps\microsoft.windowsappruntime.1.4_4000.1309.2056.0_x86__8wekyb3d8bbwe\wuceffectsi.dll", hr=0x800710da 2026-08-21T13:09:08.000 Engine:Setting original file name "UNKNOWN_FILE" for "c:\windows\winsxs\amd64_netfx-system_tlb_b03f5f7f11d50a3a_10.0.22000.1_none_27a97a473fb6b8b6\system.tlb", hr=0x87af000b 2026-08-21T13:09:08.119 Engine:Setting original file name "memdiag.exe" for "c:\windows\winsxs\wow64_microsoft-windows-b..iagnostic.resources_31bf3856ad364e35_10.0.22000.1_ja-jp_4651e78f817beb20\memtest.exe.mui", hr=0x800710da 2026-08-21T13:09:08.185 Engine:Setting original file name "DeviceCategories.dll" for "c:\windows\system32\ddores.dll", hr=0x800710da 2026-08-21T13:09:08.284 Engine:Setting original file name "CLEANMGR.DLL.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\f036e07836fb4812b87c1c93c3729441\cleanmgr.exe.mui", hr=0x800710da 2026-08-21T13:09:08.387 Engine:Setting original file name "System.dll" for "c:\windows\microsoft.net\framework\v4.0.30319\nativeimages\system.ni.dll", hr=0x800710da 2026-08-21T13:09:08.438 Engine:Setting original file name "PtpProv" for "c:\windows\system32\de-de\ptpprov.dll.mui", hr=0x800710da 2026-08-21T13:09:08.465 Engine:Setting original file name "partmgr.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-p..onmanager.resources_31bf3856ad364e35_10.0.22000.1_de-de_ab7e8d50609158fd_partmgr.sys.mui_b800c491", hr=0x800710da 2026-08-21T13:09:08.688 Engine:Setting original file name "gdi32" for "c:\windows\system32\gdi32full.dll", hr=0x800710da 2026-08-21T13:09:08.756 Engine:Setting original file name "ir50_32.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\2c0ac7543e8aa135b73a0b1f673d99d7\ir50_32original.dll.mui", hr=0x800710da 2026-08-21T13:09:08.768 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\libdca_plugin.dll", hr=0x800710da 2026-08-21T13:09:08.777 Engine:Setting original file name "CertCli" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\system32\el-gr\77e2ae79f345787fba84fcee92b20c02\certcli.dll.mui", hr=0x800710da 2026-08-21T13:09:09.208 Engine:Setting original file name "sysinfo.exe.mui" for "c:\windows\syswow64\en-us\systeminfo.exe.mui", hr=0x800710da 2026-08-21T13:09:09.553 Engine:Setting original file name "chakra.dll" for "c:\windows\systemresources\chakra.dll.mun", hr=0x800710da 2026-08-21T13:09:09.679 Engine:Setting original file name "AddinLoader.dll" for "c:\users\ithan\appdata\local\microsoft\teamsmeetingaddin\1.0.22349.4\x64\microsoft.teams.addinloader.dll", hr=0x800710da 2026-08-21T13:09:09.755 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\demux\librawdv_plugin.dll", hr=0x800710da 2026-08-21T13:09:09.906 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\video_output\libgl_plugin.dll", hr=0x800710da 2026-08-21T13:09:10.163 Engine:Setting original file name "ws2ifsl.sys.mui" for "c:\windows\winsxs\backup\amd64_microsoft-windows-w..e-ws2ifsl.resources_31bf3856ad364e35_10.0.22000.1_de-de_d7081c23e4aa6981_ws2ifsl.sys.mui_b672c7b4", hr=0x800710da 2026-08-21T13:09:10.181 Engine:Setting original file name "Audio_DiagPackage.dll.mui" for "c:\program files\windowsapps\microsoft.languageexperiencepackel-gr_22000.51.239.0_neutral__8wekyb3d8bbwe\windows\diagnostics\system\audio\el-gr\f3e16cbdcce80eca08b6d4370e246d83\diagpackage.dll.mui", hr=0x800710da 2026-08-21T13:09:10.561 Engine:Setting original file name "WLRMNDR.EXE.MUI" for "c:\program files\windowsapps\microsoft.languageexperiencepackde-de_22000.46.238.0_neutral__8wekyb3d8bbwe\windows\system32\de-de\7ef7344f314d2504b55f4a2ab40ff254\wlrmdr.exe.mui", hr=0x800710da 2026-08-21T13:09:10.656 Engine:Setting original file name "msdxm.ocx" for "c:\windows\syswow64\dxmasf.dll", hr=0x800710da 2026-08-21T13:09:11.091 Engine:Setting original file name "winrnr" for "c:\windows\system32\winrnr.dll", hr=0x800710da 2026-08-21T13:09:11.134 Engine:Setting original file name "VLC media player" for "c:\program files\videolan\vlc\plugins\codec\liblibmpeg2_plugin.dll", hr=0x800710da 2026-08-21T13:09:11.223 Engine:Setting original file name "BITLOCKERTOGO.EXE.MUI" for "c:\windows\bitlockerdiscoveryvolumecontents\ja-jp_bitlockertogo.exe.mui", hr=0x800710da 2026-08-21T13:09:11.228 Engine:Setting original file name "mp4sdmod.dll" for "c:\windows\syswow64\mp4sdecd.dll", hr=0x800710da 2026-08-21T13:09:11.267 OriginalFileName Maintenance::9900 files in Moac, 188 skipped (cached), 0 filename set 2026-08-21T13:09:11.267 [AutoPurge] Routine task for Cache Maintenance has ended. 2026-08-21T13:09:41.309 RPC Rundown called on ScanID: 9AB42B9E-924A-472B-AFEC-50A2A285DEDD 2026-08-21T13:09:41.309 On demand scan closed without completion. Current scan state: 1. ScanSource: 1, Scan flags:0x10001. NumberOfResources:0. ScanId:9AB42B9E-924A-472B-AFEC-50A2A285DEDD. bRemoveFromList(ClientKilled):1 2026-08-21T13:09:41.463 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9AB42B9E-924A-472B-AFEC-50A2A285DEDD 2026-08-21T13:09:41.463 QuickScan:ScanID:9AB42B9E-924A-472B-AFEC-50A2A285DEDD: Scan was stopped 2026-08-21T13:09:41.465 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9AB42B9E-924A-472B-AFEC-50A2A285DEDD 2026-08-21T13:09:41.465 QuickScan:ScanID:9AB42B9E-924A-472B-AFEC-50A2A285DEDD: Quick scan aborted by callback after end stage 2026-08-21T13:09:41.465 HandleOnDemandStatusChange: Scan Cancelled, pContext->Lock.hCancelEvent signaled for ScanID:9AB42B9E-924A-472B-AFEC-50A2A285DEDD 2026-08-21T13:09:41.467 OnDemandScanWorker: Scan Cancelled! scanId:9AB42B9E-924A-472B-AFEC-50A2A285DEDD, hr = 0x80508018 2026-08-21T13:09:43.492 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:09:43.499 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T13:09:43.501 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:14:38.265 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T13:16:30.797 Created on demand scan context for ScanType:1. ScanTrigger:55, ScanId:D7510CDF-788C-4A9A-9089-6EB2A02435FD, Source: MPSOURCE_SYSTEM(2), EngineSource: MP_SCANSOURCE_SCHEDULED(1) 2026-08-21T13:16:30.797 Scheduled scan with Id D7510CDF-788C-4A9A-9089-6EB2A02435FD configured CPU priority: normal (LowCpuPriority: 0) 2026-08-21T13:16:30.798 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-21T13:16:30.798 [SFC] System file cache build is not needed (already completed) 2026-08-21T13:16:32.042 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #22298, FileId: 0x27000000036403, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T13:16:32.818 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:16:32.826 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T13:16:32.827 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:16:33.923 Engine:Triggered AR EMS scan 2026-08-21T13:16:33.927 Engine:EMS scan for process: lsass pid: 776, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.951 Engine:EMS scan for process: svchost pid: 984, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.965 Engine:EMS scan for process: svchost pid: 576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.969 Engine:EMS scan for process: svchost pid: 1040, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.973 Engine:EMS scan for process: svchost pid: 1204, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.984 Engine:EMS scan for process: svchost pid: 1240, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.988 Engine:EMS scan for process: svchost pid: 1332, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:33.998 Engine:EMS scan for process: svchost pid: 1352, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.005 Engine:EMS scan for process: svchost pid: 1392, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.006 Engine:EMS scan for process: svchost pid: 1412, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.012 Engine:EMS scan for process: svchost pid: 1532, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.020 Engine:EMS scan for process: svchost pid: 1552, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.023 Engine:EMS scan for process: svchost pid: 1604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.027 Engine:EMS scan for process: svchost pid: 1612, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.029 Engine:EMS scan for process: svchost pid: 1676, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.032 Engine:EMS scan for process: svchost pid: 1740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.037 Engine:EMS scan for process: svchost pid: 1812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.044 Engine:EMS scan for process: svchost pid: 1940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.050 Engine:EMS scan for process: svchost pid: 2052, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.053 Engine:EMS scan for process: svchost pid: 2128, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.056 Engine:EMS scan for process: svchost pid: 2140, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.063 Engine:EMS scan for process: svchost pid: 2384, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.066 Engine:EMS scan for process: svchost pid: 2416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.073 Engine:EMS scan for process: svchost pid: 2512, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.075 Engine:EMS scan for process: svchost pid: 2524, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.077 Engine:EMS scan for process: svchost pid: 2540, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.082 Engine:EMS scan for process: svchost pid: 2668, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.084 Engine:EMS scan for process: svchost pid: 2700, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.087 Engine:EMS scan for process: svchost pid: 2740, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.094 Engine:EMS scan for process: svchost pid: 2756, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.097 Engine:EMS scan for process: svchost pid: 2988, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.101 Engine:EMS scan for process: svchost pid: 1096, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.107 Engine:EMS scan for process: svchost pid: 2812, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.110 Engine:EMS scan for process: svchost pid: 3416, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.116 Engine:EMS scan for process: svchost pid: 3424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.123 Engine:EMS scan for process: svchost pid: 3472, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.127 Engine:EMS scan for process: svchost pid: 3500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.132 Engine:EMS scan for process: svchost pid: 3944, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.135 Engine:EMS scan for process: svchost pid: 4048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.139 Engine:EMS scan for process: svchost pid: 4064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.150 Engine:EMS scan for process: svchost pid: 3064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.157 Engine:EMS scan for process: svchost pid: 2940, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.164 Engine:EMS scan for process: svchost pid: 4220, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.173 Engine:EMS scan for process: svchost pid: 4272, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.183 Engine:EMS scan for process: svchost pid: 4340, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.185 Engine:EMS scan for process: svchost pid: 4456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.189 Engine:EMS scan for process: svchost pid: 5100, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.195 Engine:EMS scan for process: dllhost pid: 5860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.198 Engine:EMS scan for process: svchost pid: 5896, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.200 Engine:EMS scan for process: svchost pid: 5876, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.202 Engine:EMS scan for process: svchost pid: 6244, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.209 Engine:EMS scan for process: svchost pid: 6252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.217 Engine:EMS scan for process: svchost pid: 6388, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.225 Engine:EMS scan for process: svchost pid: 6584, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.231 Engine:EMS scan for process: svchost pid: 6652, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.237 Engine:EMS scan for process: svchost pid: 6860, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.240 Engine:EMS scan for process: svchost pid: 6908, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.250 Engine:EMS scan for process: svchost pid: 5456, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.256 Engine:EMS scan for process: explorer pid: 7428, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.310 Engine:EMS scan for process: svchost pid: 7704, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.318 Engine:EMS scan for process: svchost pid: 7828, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.322 Engine:EMS scan for process: svchost pid: 7892, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.332 Engine:EMS scan for process: svchost pid: 6928, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.335 Engine:EMS scan for process: svchost pid: 8496, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.338 Engine:EMS scan for process: svchost pid: 9672, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.341 Engine:EMS scan for process: dllhost pid: 9972, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.343 Engine:EMS scan for process: svchost pid: 11160, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.351 Engine:EMS scan for process: svchost pid: 11252, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.357 Engine:EMS scan for process: svchost pid: 10788, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.360 Engine:EMS scan for process: svchost pid: 13144, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.371 Engine:EMS scan for process: svchost pid: 13048, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.380 Engine:EMS scan for process: svchost pid: 1424, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.383 Engine:EMS scan for process: svchost pid: 10760, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.404 Engine:EMS scan for process: svchost pid: 7500, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.408 Engine:EMS scan for process: svchost pid: 5180, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.416 Engine:EMS scan for process: svchost pid: 4452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.422 Engine:EMS scan for process: svchost pid: 3440, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.430 Engine:EMS scan for process: dllhost pid: 7576, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.432 Engine:EMS scan for process: svchost pid: 3120, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.434 Engine:EMS scan for process: dllhost pid: 12604, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.437 Engine:EMS scan for process: explorer pid: 12268, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.448 Engine:EMS scan for process: svchost pid: 11172, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.453 Engine:EMS scan for process: dllhost pid: 2064, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.456 Engine:EMS scan for process: svchost pid: 2452, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.462 Engine:EMS scan for process: dllhost pid: 11976, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.465 Engine:EMS scan for process: dllhost pid: 13152, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.468 Engine:EMS scan for process: dllhost pid: 9348, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:16:34.471 Engine:EMS scan for process: svchost pid: 10752, sigseq: 0x0, sendMemoryScanReport: 0, source: 1 2026-08-21T13:20:29.482 QuickScan:ScanID:D7510CDF-788C-4A9A-9089-6EB2A02435FD: Quick scan finished with error 0 2026-08-21T13:20:30.024 CheckProductDisabled(fWaitWSC: 0, fRemoveConfigs: 1) ... 2026-08-21T13:20:30.042 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T13:20:30.045 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T13:20:30.045 [RTP] [RtpConfig] Config change detected, type: 32 2026-08-21T13:20:30.045 [RTP] Duplicating the current plugin configuration object... 2026-08-21T13:20:30.045 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T13:20:30.046 [RTP] Updating plugin configuration due to recent config changes (0x20) ... 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 2 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 4096 2026-08-21T13:20:30.046 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T13:20:30.046 [RTP] No config change detected. Not updating plugin configuration. 2026-08-21T13:20:30.046 [RTP] No config changes found. No configuration switch. 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 4 2026-08-21T13:20:30.046 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x20, Changed: 0 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 8 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 16 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 1024 2026-08-21T13:20:30.046 [RTP] [RtpConfig] Config change detected, type: 2048 2026-08-21T13:20:30.046 [RTP] Setting DisableAsyncScanOnClose to 0 (hr=0). 2026-08-21T13:20:30.046 [RTP] Setting DisableAsyncScanOnOpen to 0 in wdfilter (hr=0). 2026-08-21T13:20:30.046 [RTP] Setting FilterExperimentMode to 0 (hr=0). 2026-08-21T13:20:30.048 [RTP] Setting DisableDriverUnload to 1 (hr=0). 2026-08-21T13:20:30.048 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-21T13:20:30.048 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-21T13:20:30.048 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-21T13:20:30.048 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-21T13:20:30.048 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-21T13:20:30.048 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T13:20:30.048 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-21T13:20:30.048 [RTP] [RTP] LastAccessTimeSuppression for network files is enabled by configuration. 2026-08-21T13:20:30.049 [RTP] [RtpConfig] Config change detected, type: 64 2026-08-21T13:20:30.052 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T13:20:30.055 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T13:20:30.071 Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2 -ScanTrigger 52) is scheduled to run in 40738504(ms) from now at 02:39 (00:39 UTC) with period 86400000(ms). Daily task start time is randomized to reduce spikes. 2026-08-21T13:20:31.513 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:20:31.520 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T13:20:31.522 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T13:20:32.585 [RTP] Duplicating the current plugin configuration object... 2026-08-21T13:20:32.585 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T13:20:32.585 [RTP] Updating plugin configuration due to recent config changes (0x41e) ... 2026-08-21T13:20:32.585 [RTP] Calling GenerateEngineConfigStruct (0x8) ... 2026-08-21T13:20:32.586 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x41e, Changed: 0x208 2026-08-21T13:29:43.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T13:36:26.883 Bm signature throttled:0x00002db31bed458f 2026-08-21T13:41:11.047 Engine:Setting original file name "pcalua.exe" for "h:\windows\system32\pcadm.dll", hr=0x800710da 2026-08-21T13:44:48.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000157EAFC2B838, sigsha=ef600f76a8e9dcce34454b1e4fda122185095fe4, cached=false, source=2, resourceid=0x8dcbd7e8 Internal signature match:subtype=Lowfi, sigseq=0x0000157ED01FA601, sigsha=fdc6b8d4215e1e59a08ee3f4793e98a74459e01f, cached=false, source=2, resourceid=0x8dcbd7e8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24992611 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5579db6b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42357c3b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x50b6cf2f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x411338da 2026-08-21T13:59:53.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T14:14:58.265 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T14:17:34.990 Bm signature throttled:0x00002db31bed458f BEGIN BM telemetry GUID:{EC0D7405-3E6B-EBCB-483D-99E70A162DA3} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:11832 ProcessCreationTime:134317859371097392 SessionID:1 CreationTime:08-21-2026 14:20:14 ImagePath:D:\xampp\FileZillaFTP\FileZillaServer.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-21T14:20:16.003 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T14:20:16.003 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T14:20:16.003 [Cloud] Queued cloud request. 2026-08-21T14:20:16.003 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T14:20:16.003 [Cloud] Dequeued cloud request. 2026-08-21T14:20:16.004 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T14:20:16.309 [Cloud] End of cloud request. 2026-08-21T14:20:16.829 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T14:30:03.265 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T14:35:26.493 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b 2026-08-21T14:45:08.269 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T14:48:31.194 Bm signature throttled:0x00002db31bed458f 2026-08-21T14:54:13.986 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 222234, Count: 11794, MaxTime: 781, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp_7.4.1_mit_Programme\xampp\uninstall.exe, EstimatedImpact: 1% 2026-08-21T14:54:13.986 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 24995, Count: 379, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T14:54:13.986 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T14:54:13.986 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T14:54:13.986 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T14:54:13.986 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T14:54:13.986 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T14:54:13.986 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T14:54:13.986 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T14:54:13.986 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 2805, Count: 85, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T14:54:13.986 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T14:54:13.986 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T14:54:13.986 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T14:54:13.986 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T14:54:13.986 ProcessImageName: notepad++.exe, Pid: 7212, TotalTime: 1293, Count: 61, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T14:54:13.986 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: taskhostw.exe, Pid: 8332, TotalTime: 1093, Count: 2, MaxTime: 1062, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-08-21T14:54:13.987 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T14:54:13.987 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T14:54:13.987 ProcessImageName: perl.exe, Pid: 4816, TotalTime: 779, Count: 4, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T14:54:13.987 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T14:54:13.987 ProcessImageName: perl.exe, Pid: 10940, TotalTime: 560, Count: 5, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\libstdc++-6.dll, EstimatedImpact: 100% 2026-08-21T14:54:13.987 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 515, Count: 3, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 450, Count: 39, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T14:54:13.987 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T14:54:13.987 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T14:54:13.987 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 366, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T14:54:13.987 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 318, Count: 24, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T14:54:13.987 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 240, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 233, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOADF9.tmp, EstimatedImpact: 45% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 2524, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T14:54:13.987 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 186, Count: 3, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T14:54:13.987 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T14:54:13.987 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T14:54:13.987 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 2940, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer_Service.exe, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: dllhost.exe, Pid: 5860, TotalTime: 135, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T14:54:13.987 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T14:54:13.987 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T14:54:13.987 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 4% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 76, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\SystemResources\twinui.appcore.dll.mun, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: dasHost.exe, Pid: 5204, TotalTime: 75, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T14:54:13.987 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T14:54:13.987 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T14:54:13.987 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T14:54:13.987 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 60, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T14:54:13.987 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 26% 2026-08-21T14:54:13.987 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T14:54:13.987 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{91E0771E-FE09-4F47-9C4D-D3E82FEED848}.json, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T14:54:13.987 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T14:54:13.987 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T14:54:13.987 ProcessImageName: backgroundTaskHost.exe, Pid: 12536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1787317000, EstimatedImpact: 29% 2026-08-21T14:54:13.987 ProcessImageName: backgroundTaskHost.exe, Pid: 4016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1787302503->(UTF-16LE), EstimatedImpact: 28% 2026-08-21T14:54:13.987 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1344.log, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 12636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1442.log, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 7584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1404.log, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T14:54:13.987 ProcessImageName: backgroundTaskHost.exe, Pid: 4920, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787320631, EstimatedImpact: 1% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 6564, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1516.log, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: sihost.exe, Pid: 6532, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1322.log, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 2848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1508.log->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: OfficeC2RClient.exe, Pid: 2312, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1358.log, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: StoreDesktopExtension.exe, Pid: 11960, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 9% 2026-08-21T14:54:13.987 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T14:54:13.987 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T15:00:13.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T15:04:25.064 Bm signature throttled:0x00002db31bed458f BEGIN BM telemetry GUID:{81A02AB2-C12E-504D-9985-DF5152A324B7} SignatureID:340520518878414 SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0 ThreatLevel:0 ProcessID:2004 ProcessCreationTime:134317859382025316 SessionID:1 CreationTime:08-21-2026 15:09:01 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-21T15:09:02.004 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T15:09:02.004 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:09:02.004 [Cloud] Queued cloud request. 2026-08-21T15:09:02.004 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T15:09:02.004 [Cloud] Dequeued cloud request. 2026-08-21T15:09:02.004 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:09:02.265 [Cloud] End of cloud request. 2026-08-21T15:09:02.777 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:15:18.261 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T15:19:37.752 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) Internal signature match:subtype=Lowfi, sigseq=0x000063E78EA4A718, sigsha=a690228b9916a65ec33ca9267d5d8e67bb239426, cached=false, source=5, resourceid=0x1fa698c8 2026-08-21T15:19:37.816 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T15:19:37.817 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:19:37.817 [Cloud] Queued cloud request. 2026-08-21T15:19:37.817 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T15:19:37.817 [Cloud] Dequeued cloud request. 2026-08-21T15:19:37.817 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:19:38.365 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f3b5f89e4170338ea6e97d3ad59c6975ffb1b7e7 Dynamic Signature Compilation Timestamp:08-21-2026 15:19:37 Persistence Type:Duration Time remaining:864000000 2026-08-21T15:19:38.368 [Cloud] End of cloud request. 2026-08-21T15:19:38.368 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T15:19:38.382 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:19:38.398 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:19:38.403 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. status=0x8070022, statusex=0x2, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T15:19:38.409 [RTP] [Mini-filter] Blocked file(#1): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #35468, FileId: 0x80000000068dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 BEGIN BM telemetry GUID:{13B736FC-8D9C-1F5D-EE49-1D70EFCF39E6} SignatureID:120615708262628 SigSha:e885968f9a24daa58050ac5509c0821faae78591 ThreatLevel:0 ProcessID:7428 ProcessCreationTime:134317759795377200 SessionID:1 CreationTime:08-21-2026 15:19:38 ImagePath:C:\Windows\explorer.exe Taint Info:Friendly: Y; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-21T15:19:38.432 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:19:38.451 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:19:38.451 SDN:Issuing SDN query for \\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) (sha1=822713aa20db9cf9577a00d7e5387f43d28377d2, sha2=091c335c3b64d9ec35619e67c14ce9370bae28f9b46b0836d5ced112ee3d2e06) 2026-08-21T15:19:38.456 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T15:19:38.456 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:19:38.456 [Cloud] Queued cloud request. 2026-08-21T15:19:38.456 [Cloud] Dequeued cloud request. 2026-08-21T15:19:38.456 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T15:19:38.457 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:19:38.626 [Cloud] End of cloud request. 2026-08-21T15:19:38.643 SDN:SDN query completed: 00000000 2026-08-21T15:19:39.136 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:19:39.307 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T15:19:39.308 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:19:39.308 [Cloud] Queued cloud request. 2026-08-21T15:19:39.308 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T15:19:39.308 [Cloud] Dequeued cloud request. 2026-08-21T15:19:39.308 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:19:39.335 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T15:19:39.335 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:19:39.335 [Cloud] Queued cloud request. 2026-08-21T15:19:39.335 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T15:19:39.335 [Cloud] Dequeued cloud request. 2026-08-21T15:19:39.336 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:19:39.436 [Cloud] End of cloud request. Begin Resource Scan Scan ID:{2A6E77F6-3FED-4AF0-AC55-AACCAA82D780} Scan Source:3 Start Time:08-21-2026 15:19:38 End Time:08-21-2026 15:19:39 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:19:39.438 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:19:39.439 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:19:39.449 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:19:39.454 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php PropBag [length: 0, data: (null)] 2026-08-21T15:19:39.454 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 3950 milliseconds. 1 detections to be cleaned. 2026-08-21T15:19:39.539 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-08-21T15:19:39.539 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:19:39.539 [Cloud] Queued cloud request. 2026-08-21T15:19:39.539 [Cloud] Dequeued cloud request. 2026-08-21T15:19:39.541 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:19:39.765 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:19:39.766 [Cloud] End of cloud request. 2026-08-21T15:19:39.884 [Cloud] End of cloud request. 2026-08-21T15:19:39.963 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:19:43.413 [RoutineClean] Cleaning 1 detections 2026-08-21T15:19:43.433 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:19:43.450 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:19:43.455 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{D55F1081-A6F6-4C1A-9279-5C1775A3C44E} Scan Source:6 Start Time:08-21-2026 15:19:43 End Time:08-21-2026 15:19:43 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:19:43.460 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:19:43.461 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:19:43.462 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:19:43.482 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:19:43.498 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:19:45.482 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:19:45.492 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:19:45.494 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:20:00.926 QuickScan:ScanID:54A5DF1F-1AD1-43B7-A1CE-F2E74EE54897: Quick scan finished with error 0 2026-08-21T15:20:00.932 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{54A5DF1F-1AD1-43B7-A1CE-F2E74EE54897} Scan Source:6 Start Time:08-21-2026 15:19:43 End Time:08-21-2026 15:20:00 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T15:20:01.043 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:20:01.059 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:20:01.064 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:20:01.072 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T15:20:01.072 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:20:01.072 [Cloud] Queued cloud request. 2026-08-21T15:20:01.072 [Cloud] Dequeued cloud request. 2026-08-21T15:20:01.074 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 15:20:01 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 15:20:01 Result:0 2026-08-21T15:20:01.077 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T15:20:01.077 [RoutineClean] Routine cleaning timer rescheduled to fire in 4927 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T15:20:01.149 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:20:03.085 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:20:03.095 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:20:03.097 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:20:06.018 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T15:20:11.201 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:20:11.201 [Cloud] End of cloud request. 2026-08-21T15:20:11.718 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:20:16.667 Bm signature throttled:0x00002db31bed458f 2026-08-21T15:20:31.084 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8f51cb9d7ffffffe 2026-08-21T15:20:31.094 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T15:20:31.098 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8f51cb9d7ffffffe 2026-08-21T15:20:31.100 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x8f51cb9d7ffffffe 2026-08-21T15:20:31.112 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T15:20:31.112 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:20:31.112 [Cloud] Queued cloud request. 2026-08-21T15:20:31.112 [Cloud] Dequeued cloud request. 2026-08-21T15:20:31.136 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:20:31.178 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:20:31.178 [Cloud] End of cloud request. 2026-08-21T15:20:31.691 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:23:56.660 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #36429, FileId: 0x44000000008384, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:28:42.198 Bm signature throttled:0x00002db31bed458f 2026-08-21T15:28:42.595 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\Prefetch\RDPINPUT.EXE-D83DCC53.pf. Process: \Device\HarddiskVolume3\Windows\System32\rdpinput.exe, Status: 0xc000004b, State: 0, ScanRequest #36874, FileId: 0x6b000000010dc9, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:28:42.611 Engine:Process 704 will be fully monitored because of injection from C:\Windows\System32\dwm.exe 2026-08-21T15:29:35.378 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:29:35.394 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:29:35.396 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T15:29:35.399 [RTP] [Mini-filter] Blocked file(#4): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #37246, FileId: 0x90000000068dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:29:35.417 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:29:35.436 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{9A487F20-EB1E-4E3C-BF30-E7A71C374635} Scan Source:3 Start Time:08-21-2026 15:29:35 End Time:08-21-2026 15:29:35 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:29:35.440 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:29:35.441 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:29:35.446 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:29:35.448 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php PropBag [length: 0, data: (null)] 2026-08-21T15:29:35.448 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4948 milliseconds. 1 detections to be cleaned. 2026-08-21T15:29:40.411 [RoutineClean] Cleaning 1 detections 2026-08-21T15:29:40.435 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:29:40.457 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:29:40.464 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{6B0D1B81-11DF-4282-B4BE-F063D37C664F} Scan Source:6 Start Time:08-21-2026 15:29:40 End Time:08-21-2026 15:29:40 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:29:40.471 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:29:40.472 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:29:40.474 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:29:40.669 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:29:40.733 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:29:42.501 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:29:42.512 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:29:42.519 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:29:57.144 QuickScan:ScanID:A042B27E-ACFA-4631-8A65-E18B66B4AE58: Quick scan finished with error 0 2026-08-21T15:29:57.150 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{A042B27E-ACFA-4631-8A65-E18B66B4AE58} Scan Source:6 Start Time:08-21-2026 15:29:40 End Time:08-21-2026 15:29:57 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T15:29:57.254 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:29:57.271 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:29:57.275 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:29:57.281 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T15:29:57.281 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:29:57.281 [Cloud] Queued cloud request. 2026-08-21T15:29:57.282 [Cloud] Dequeued cloud request. 2026-08-21T15:29:57.283 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 15:29:57 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 15:29:57 Result:0 2026-08-21T15:29:57.294 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T15:29:57.294 [RoutineClean] Routine cleaning timer rescheduled to fire in 4931 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T15:29:57.316 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:29:57.562 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:29:57.562 [Cloud] End of cloud request. 2026-08-21T15:29:58.080 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:29:59.295 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:29:59.305 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:29:59.307 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:30:02.238 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T15:30:23.273 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T15:30:27.296 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x1f9128a57ffffffe 2026-08-21T15:30:27.304 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T15:30:27.309 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x1f9128a57ffffffe 2026-08-21T15:30:27.313 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x1f9128a57ffffffe 2026-08-21T15:30:27.328 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T15:30:27.328 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:30:27.328 [Cloud] Queued cloud request. 2026-08-21T15:30:27.328 [Cloud] Dequeued cloud request. 2026-08-21T15:30:27.357 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:30:27.385 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:30:27.385 [Cloud] End of cloud request. 2026-08-21T15:30:27.899 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:31:26.000 Engine:Setting original file name "wmic.exe" for "h:\windows\system32\wbem\wmic.exe", hr=0x800710da 2026-08-21T15:31:48.592 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:31:48.611 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:31:48.614 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T15:31:48.619 [RTP] [Mini-filter] Blocked file(#5): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #37365, FileId: 0xa0000000068dd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:31:48.647 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:31:48.681 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{C6059C77-BB9E-477B-9010-EDA10BAFE7DD} Scan Source:3 Start Time:08-21-2026 15:31:48 End Time:08-21-2026 15:31:48 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:31:48.687 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:31:48.688 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:31:48.694 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:31:48.698 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php PropBag [length: 0, data: (null)] 2026-08-21T15:31:48.698 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4916 milliseconds. 1 detections to be cleaned. 2026-08-21T15:31:53.623 [RoutineClean] Cleaning 1 detections 2026-08-21T15:31:53.645 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:31:53.664 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:31:53.671 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{4CF4C698-78CC-40A5-8F6C-F94BFFEC2F41} Scan Source:6 Start Time:08-21-2026 15:31:53 End Time:08-21-2026 15:31:53 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T15:31:53.678 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:31:53.680 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:31:53.681 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T15:31:53.704 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:31:53.725 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:31:55.721 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:31:55.731 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:31:55.735 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:32:13.831 QuickScan:ScanID:50AB6BA4-E7DE-4733-B368-7B1A505E51E8: Quick scan finished with error 0 2026-08-21T15:32:13.838 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{50AB6BA4-E7DE-4733-B368-7B1A505E51E8} Scan Source:6 Start Time:08-21-2026 15:31:53 End Time:08-21-2026 15:32:13 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T15:32:13.945 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php) 2026-08-21T15:32:13.962 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T15:32:13.967 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php; 2026-08-21T15:32:14.015 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T15:32:14.015 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:32:14.015 [Cloud] Queued cloud request. 2026-08-21T15:32:14.015 [Cloud] Dequeued cloud request. 2026-08-21T15:32:14.023 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 15:32:13 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 15:32:14 Result:0 2026-08-21T15:32:14.026 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T15:32:14.026 [RoutineClean] Routine cleaning timer rescheduled to fire in 4886 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T15:32:14.048 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:32:14.234 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:32:14.235 [Cloud] End of cloud request. 2026-08-21T15:32:14.765 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:32:16.067 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:32:16.087 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T15:32:16.088 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T15:32:18.921 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T15:32:44.027 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb21f7b77ffffffe 2026-08-21T15:32:44.037 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T15:32:44.042 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb21f7b77ffffffe 2026-08-21T15:32:44.045 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0xb21f7b77ffffffe 2026-08-21T15:32:44.058 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T15:32:44.058 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T15:32:44.058 [Cloud] Queued cloud request. 2026-08-21T15:32:44.058 [Cloud] Dequeued cloud request. 2026-08-21T15:32:44.084 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T15:32:44.111 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T15:32:44.112 [Cloud] End of cloud request. 2026-08-21T15:32:44.631 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T15:39:33.233 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #37703, FileId: 0x3f0000000b769a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.825 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2800579FF. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37822, FileId: 0x100000000bc8b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.841 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj1CF75E9DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37823, FileId: 0x110000000bc8b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.849 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4BC108925. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37824, FileId: 0x120000000bc8b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.859 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAADE519F0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37825, FileId: 0x130000000bc8b0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.875 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj87B49797A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37827, FileId: 0x1c0000000bc8af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:19.881 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj6253E49F0. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37828, FileId: 0x1d0000000bc8af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.107 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj70C9CF9C2. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37829, FileId: 0x100000000bc8b8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.119 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB188F596A. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37830, FileId: 0x130000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.174 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj8983E69B6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37831, FileId: 0x140000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.187 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj9ABBBE90F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37832, FileId: 0x150000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.201 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj25D5FA917. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37833, FileId: 0x160000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.215 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj64FDC3968. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37834, FileId: 0x170000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.228 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj5431229A3. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37835, FileId: 0x180000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.240 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj2B10F9965. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37836, FileId: 0x190000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.254 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj86E621938. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37837, FileId: 0x1a0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.267 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj4CB22D920. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37838, FileId: 0x1b0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.279 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE0C3599DA. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37839, FileId: 0x1c0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.307 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj459ADE916. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37840, FileId: 0x1d0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:20.322 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj12055C9D5. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37841, FileId: 0x1e0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.343 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj477EBC93D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37843, FileId: 0x1f0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.355 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB6259392E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37844, FileId: 0x200000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.364 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjB675A096E. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37845, FileId: 0x210000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.372 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj86A87C91D. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37846, FileId: 0x220000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.388 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjE0E89F93F. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37847, FileId: 0x2a0000000bc8b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.394 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjA523E49A1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37848, FileId: 0x2b0000000bc8b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.495 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjAD85149F8. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37849, FileId: 0x300000000bc8b1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.506 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF0D34E9F7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37850, FileId: 0x240000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.521 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjD4FFC7912. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37851, FileId: 0x250000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.534 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj05837F9E6. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37852, FileId: 0x260000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.547 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjC788549AE. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37853, FileId: 0x270000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.567 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjFB892E9E1. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37854, FileId: 0x280000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.582 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mjF8E50C9C7. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37855, FileId: 0x290000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:21.610 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-mj0EB0F2925. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37856, FileId: 0x2a0000000bc8b5, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:34.697 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37871, FileId: 0x1d0000000397a4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:34.882 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37873, FileId: 0x1e0000000bc8af, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:49.662 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\metadata.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37885, FileId: 0x170000000bbf59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:41:49.666 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\apps\SingleClientMini\content\assets.db-wal. Process: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe, Status: 0xc0000001, State: 0, ScanRequest #37887, FileId: 0x120000000bc6f0, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:43:42.273 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #38012, FileId: 0x190000000bbf59, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:45:27.315 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #38249, FileId: 0x42000000039ae8, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:45:28.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T15:54:40.197 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39178, FileId: 0xc800000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.206 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39182, FileId: 0xca00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.206 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39184, FileId: 0x130000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.206 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39181, FileId: 0xc900000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.206 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39183, FileId: 0x120000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.213 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39186, FileId: 0x140000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.229 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39187, FileId: 0xcc00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39192, FileId: 0xd000000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39194, FileId: 0x190000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39197, FileId: 0x1b0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39196, FileId: 0x1a0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39193, FileId: 0xd100000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39199, FileId: 0x1c0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39191, FileId: 0xcf00000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39198, FileId: 0xd300000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.244 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #39195, FileId: 0xd200000000aca4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T15:54:40.625 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\117eaabc-5324-4073-b77e-d59d1d6aa5f2. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #39226, FileId: 0x4d000000032f23, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T16:00:33.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa55a4353 2026-08-21T16:00:53.582 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T16:00:53.582 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T16:00:53.582 [Cloud] Queued cloud request. 2026-08-21T16:00:53.582 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T16:00:53.582 [Cloud] Dequeued cloud request. 2026-08-21T16:00:53.582 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T16:00:54.304 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\aa520e97399d474f792ff9217a81008a12b82331 Dynamic Signature Compilation Timestamp:08-21-2026 16:00:53 Persistence Type:Duration Time remaining:288000000 2026-08-21T16:00:54.304 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T16:00:54.304 [Cloud] End of cloud request. 2026-08-21T16:00:54.807 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x64fe6f6f 2026-08-21T16:06:05.164 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T16:06:05.164 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T16:06:05.164 [Cloud] Queued cloud request. 2026-08-21T16:06:05.164 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T16:06:05.164 [Cloud] Dequeued cloud request. 2026-08-21T16:06:05.164 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T16:06:05.777 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d6467f546b9e37f67a6efc1140077d1e4ad17200 Dynamic Signature Compilation Timestamp:08-21-2026 16:06:05 Persistence Type:Duration Time remaining:288000000 2026-08-21T16:06:05.777 [Cloud] End of cloud request. 2026-08-21T16:06:05.777 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T16:06:06.280 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T16:10:13.515 Bm signature throttled:0x000135b39c9104ce 2026-08-21T16:15:38.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T16:30:43.268 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T16:45:48.271 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T16:54:13.999 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 364169, Count: 19967, MaxTime: 1671, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\04_IPTV_AUDIO\Web-IPTV-Player-master\dist\clappr.js, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 32290, Count: 833, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T16:54:13.999 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T16:54:13.999 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T16:54:13.999 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T16:54:13.999 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T16:54:13.999 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 2805, Count: 85, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T16:54:13.999 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T16:54:13.999 ProcessImageName: notepad++.exe, Pid: 7212, TotalTime: 1293, Count: 61, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: notepad++.exe, Pid: 10968, TotalTime: 1207, Count: 62, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: taskhostw.exe, Pid: 8332, TotalTime: 1093, Count: 2, MaxTime: 1062, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-08-21T16:54:13.999 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T16:54:13.999 ProcessImageName: PDFXCview.exe, Pid: 9408, TotalTime: 886, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\SearchProviders\Ask.xml, EstimatedImpact: 53% 2026-08-21T16:54:13.999 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 780, Count: 4, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: perl.exe, Pid: 4816, TotalTime: 779, Count: 4, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T16:54:13.999 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T16:54:13.999 ProcessImageName: firefox.exe, Pid: 7256, TotalTime: 631, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13488, EstimatedImpact: 46% 2026-08-21T16:54:13.999 ProcessImageName: perl.exe, Pid: 10940, TotalTime: 560, Count: 5, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\libstdc++-6.dll, EstimatedImpact: 100% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 541, Count: 45, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T16:54:13.999 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 439, Count: 34, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T16:54:13.999 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T16:54:13.999 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T16:54:13.999 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 366, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 14184, TotalTime: 330, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787324264, EstimatedImpact: 7% 2026-08-21T16:54:13.999 ProcessImageName: webalizer.exe, Pid: 10172, TotalTime: 287, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\logs\access.log, EstimatedImpact: 17% 2026-08-21T16:54:13.999 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 286, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T16:54:13.999 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 240, Count: 26, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 233, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOADF9.tmp, EstimatedImpact: 45% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 2524, TotalTime: 216, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: TabTip.exe, Pid: 764, TotalTime: 202, Count: 5, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 98% 2026-08-21T16:54:13.999 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 201, Count: 4, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 196, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T16:54:13.999 ProcessImageName: SDXHelper.exe, Pid: 8808, TotalTime: 181, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 19% 2026-08-21T16:54:13.999 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T16:54:13.999 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T16:54:13.999 ProcessImageName: dllhost.exe, Pid: 5860, TotalTime: 165, Count: 15, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: dasHost.exe, Pid: 5204, TotalTime: 151, Count: 24, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: SDXHelper.exe, Pid: 7792, TotalTime: 151, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 15% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T16:54:13.999 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 2940, TotalTime: 139, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer_Service.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 13892, TotalTime: 137, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 576, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 122, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T16:54:13.999 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T16:54:13.999 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T16:54:13.999 ProcessImageName: dllhost.exe, Pid: 13152, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\contextMenu\NppShell.dll, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T16:54:13.999 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: mysqld.exe, Pid: 240, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\data\mysql_error.log, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T16:54:13.999 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 75, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T16:54:13.999 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T16:54:13.999 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T16:54:13.999 ProcessImageName: cmd.exe, Pid: 7796, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp_7.4.1_mit_Programme\xampp\webalizer\webalizer.exe, EstimatedImpact: 55% 2026-08-21T16:54:13.999 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T16:54:13.999 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T16:54:13.999 ProcessImageName: sihost.exe, Pid: 6532, TotalTime: 46, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T16:54:13.999 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T16:54:13.999 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{91E0771E-FE09-4F47-9C4D-D3E82FEED848}.json, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T16:54:13.999 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 5760, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1745.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 11096, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1743.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T16:54:13.999 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 4016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1787302503->(UTF-16LE), EstimatedImpact: 28% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 12536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1787317000, EstimatedImpact: 29% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 12636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1442.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 5068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1739.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1344.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 7584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1404.log, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T16:54:13.999 ProcessImageName: backgroundTaskHost.exe, Pid: 4920, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787320631, EstimatedImpact: 1% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 2848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1508.log->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 2312, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1358.log, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 6564, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1516.log, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1322.log, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 1204, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: StoreDesktopExtension.exe, Pid: 11960, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 9% 2026-08-21T16:54:13.999 ProcessImageName: SecHealthUI.exe, Pid: 7200, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SecHealthUI_1000.29628.1000.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T16:54:13.999 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T17:00:53.275 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T17:02:09.179 Engine:Setting original file name "register-cimprovider2.exe" for "h:\windows\system32\register-cimprovider.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa13aa866 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x885da585 2026-08-21T17:03:48.608 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:48.608 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:48.608 [Cloud] Queued cloud request. 2026-08-21T17:03:48.608 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:48.608 [Cloud] Dequeued cloud request. 2026-08-21T17:03:48.608 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6ac6b6ade9bf2bc68172dab48add23b7d2a8405a Dynamic Signature Compilation Timestamp:08-21-2026 17:03:49 Persistence Type:Duration Time remaining:150196224 2026-08-21T17:03:49.646 Dynamic signature received 2026-08-21T17:03:49.646 [Cloud] End of cloud request. 2026-08-21T17:03:49.646 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8bf22364 2026-08-21T17:03:49.849 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:49.849 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:49.849 [Cloud] Queued cloud request. 2026-08-21T17:03:49.849 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:49.849 [Cloud] Dequeued cloud request. 2026-08-21T17:03:49.849 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\89079af5f95e1a3f2cab181639c54f0794070880 Dynamic Signature Compilation Timestamp:08-21-2026 17:03:49 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:50.054 Dynamic signature received 2026-08-21T17:03:50.054 [Cloud] End of cloud request. 2026-08-21T17:03:50.054 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8cab3f56 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc0cf9e01 2026-08-21T17:03:50.211 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7d003aaf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe00fdbd9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8bffa7a2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6f1df760 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x74668183 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3940a1fc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7a5ce120 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa633dbf9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xee055ce6 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x27d7e6e8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdd4f0136 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x90da6837 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5d3e5d3d 2026-08-21T17:03:54.639 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:54.639 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:54.639 [Cloud] Queued cloud request. 2026-08-21T17:03:54.639 [Cloud] Dequeued cloud request. 2026-08-21T17:03:54.639 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:54.639 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\962f9be53d36534fd9eb7eeb0cf195900c054509 Dynamic Signature Compilation Timestamp:08-21-2026 17:03:54 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:54.811 Dynamic signature received 2026-08-21T17:03:54.811 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:03:54.811 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29cd262d 2026-08-21T17:03:54.874 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:54.874 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:54.874 [Cloud] Queued cloud request. 2026-08-21T17:03:54.874 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:54.874 [Cloud] Dequeued cloud request. 2026-08-21T17:03:54.889 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ddf6d2e2e3ab7d2a3d1dbef4f19792f4ff5b4d4 Dynamic Signature Compilation Timestamp:08-21-2026 17:03:54 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:55.094 Dynamic signature received 2026-08-21T17:03:55.094 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:03:55.094 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7fbe700b 2026-08-21T17:03:55.172 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:55.172 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:55.172 [Cloud] Queued cloud request. 2026-08-21T17:03:55.172 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:55.172 [Cloud] Dequeued cloud request. 2026-08-21T17:03:55.172 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:03:55.329 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:03:55.376 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\91cb3ae1b85515c0b67f53fc0c585085f6c6746e Dynamic Signature Compilation Timestamp:08-21-2026 17:03:54 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:55.376 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:03:55.376 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x025c0359 2026-08-21T17:03:55.533 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:55.533 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:55.533 [Cloud] Queued cloud request. 2026-08-21T17:03:55.533 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:55.533 [Cloud] Dequeued cloud request. 2026-08-21T17:03:55.533 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1776ff95b9512f5b39680f7e9ba2dea885e19d47 Dynamic Signature Compilation Timestamp:08-21-2026 17:03:55 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:55.847 Dynamic signature received 2026-08-21T17:03:55.847 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:03:55.847 [Cloud] End of cloud request. 2026-08-21T17:03:55.879 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a694f8b 2026-08-21T17:03:55.973 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:03:55.973 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:03:55.989 [Cloud] Queued cloud request. 2026-08-21T17:03:55.989 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:03:55.989 [Cloud] Dequeued cloud request. 2026-08-21T17:03:55.989 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:03:56.178 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52c23c0519518bc752da7644d5291dbe3a51cfe5 Dynamic Signature Compilation Timestamp:08-21-2026 17:03:55 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:03:56.178 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:03:56.178 [Cloud] End of cloud request. 2026-08-21T17:03:56.742 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x843ef6f3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfd8c762d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfec961f3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x46eeec7f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2507f149 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x708f699e 2026-08-21T17:04:28.824 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:04:28.824 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:04:28.824 [Cloud] Queued cloud request. 2026-08-21T17:04:28.824 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:04:28.824 [Cloud] Dequeued cloud request. 2026-08-21T17:04:28.824 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\eb9d324fc0f2550f0d9908fa10789fd813933554 Dynamic Signature Compilation Timestamp:08-21-2026 17:04:28 Persistence Type:Duration Time remaining:150196224 2026-08-21T17:04:29.279 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:04:29.279 [Cloud] End of cloud request. 2026-08-21T17:04:29.279 Dynamic signature received 2026-08-21T17:04:29.813 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x02283253 2026-08-21T17:04:53.002 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:04:53.002 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:04:53.002 [Cloud] Queued cloud request. 2026-08-21T17:04:53.002 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:04:53.002 [Cloud] Dequeued cloud request. 2026-08-21T17:04:53.002 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:04:53.049 [Cloud] End of cloud request. 2026-08-21T17:04:53.049 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3\webinterface\inhalt.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xb4475597 2026-08-21T17:04:53.072 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:04:53.072 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:04:53.072 [Cloud] Queued cloud request. 2026-08-21T17:04:53.072 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:04:53.072 [Cloud] Dequeued cloud request. 2026-08-21T17:04:53.072 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:04:53.096 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3\webinterface\inhalt.php. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-08-21T17:04:53.096 [Cloud] End of cloud request. 2026-08-21T17:04:53.614 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62fe08e3 2026-08-21T17:05:06.286 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:06.286 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:06.286 [Cloud] Queued cloud request. 2026-08-21T17:05:06.286 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:06.286 [Cloud] Dequeued cloud request. 2026-08-21T17:05:06.286 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:06.460 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87c2823b7b16276bb13c0316b944953c9db81277 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:05 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:06.460 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:06.460 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6ed4d79 2026-08-21T17:05:06.554 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:06.554 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:06.554 [Cloud] Queued cloud request. 2026-08-21T17:05:06.554 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:06.554 [Cloud] Dequeued cloud request. 2026-08-21T17:05:06.554 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:06.773 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e6c43f0a9a91730657f602293070f57cc8ebede6 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:06 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:06.773 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:06.773 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdc88fec3 2026-08-21T17:05:06.836 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:06.836 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:06.836 [Cloud] Queued cloud request. 2026-08-21T17:05:06.836 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:06.836 [Cloud] Dequeued cloud request. 2026-08-21T17:05:06.836 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:06.963 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:07.041 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\af3b0903f296c87759fa4241b4a43e3dcd1a7444 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:06 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:07.041 [Cloud] End of cloud request. 2026-08-21T17:05:07.041 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0752f25f 2026-08-21T17:05:07.120 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:07.120 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:07.120 [Cloud] Queued cloud request. 2026-08-21T17:05:07.120 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:07.120 [Cloud] Dequeued cloud request. 2026-08-21T17:05:07.120 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:07.356 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75223f03c34e56fcdc7b1c5dc5f4462a8721cb74 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:06 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:07.356 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:07.356 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30741d05 2026-08-21T17:05:07.544 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:07.560 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:07.560 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:07.560 [Cloud] Queued cloud request. 2026-08-21T17:05:07.560 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:07.560 [Cloud] Dequeued cloud request. 2026-08-21T17:05:07.560 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7724b0cc3167566654f9d37e626e64080b43d31c Dynamic Signature Compilation Timestamp:08-21-2026 17:05:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:07.748 Dynamic signature received 2026-08-21T17:05:07.748 [Cloud] End of cloud request. 2026-08-21T17:05:07.748 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x93d531c8 2026-08-21T17:05:07.874 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:07.874 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:07.874 [Cloud] Queued cloud request. 2026-08-21T17:05:07.874 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:07.874 [Cloud] Dequeued cloud request. 2026-08-21T17:05:07.874 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:08.047 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\26ceb8b374d7b41422628f4d617e2323c2391194 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:08.047 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:08.047 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x469def99 2026-08-21T17:05:08.125 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:08.125 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:08.125 [Cloud] Queued cloud request. 2026-08-21T17:05:08.125 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:08.125 [Cloud] Dequeued cloud request. 2026-08-21T17:05:08.125 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:08.266 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:08.376 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\421f10fe4fefe989a5df81cb917cc9d72964c549 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:08.376 [Cloud] End of cloud request. 2026-08-21T17:05:08.376 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x47da139e 2026-08-21T17:05:08.455 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:08.455 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:08.455 [Cloud] Queued cloud request. 2026-08-21T17:05:08.455 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:08.455 [Cloud] Dequeued cloud request. 2026-08-21T17:05:08.455 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:08.659 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6d03f2f2e3c9c2c1d2c19f466d05e25e6003467a Dynamic Signature Compilation Timestamp:08-21-2026 17:05:08 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:08.659 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:08.659 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62f0425c 2026-08-21T17:05:08.738 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:08.738 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:08.738 [Cloud] Queued cloud request. 2026-08-21T17:05:08.738 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:08.738 [Cloud] Dequeued cloud request. 2026-08-21T17:05:08.738 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:08.879 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cbaa9c5a78f746212146c85362a8ca200ecab825 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:08 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:09.036 Dynamic signature received 2026-08-21T17:05:09.051 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:09.051 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd5154f77 2026-08-21T17:05:09.114 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:09.114 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:09.114 [Cloud] Queued cloud request. 2026-08-21T17:05:09.114 [Cloud] Dequeued cloud request. 2026-08-21T17:05:09.114 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:09.114 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a614abdda001cc317fbd3a8a1868ebbdfb30a835 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:08 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:09.412 Dynamic signature received 2026-08-21T17:05:09.412 [Cloud] End of cloud request. 2026-08-21T17:05:09.412 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa9e17444 2026-08-21T17:05:09.538 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:09.538 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:09.538 [Cloud] Queued cloud request. 2026-08-21T17:05:09.538 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:09.538 [Cloud] Dequeued cloud request. 2026-08-21T17:05:09.538 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:09.553 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x370e191a 2026-08-21T17:05:10.230 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:10.230 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:10.230 [Cloud] Queued cloud request. 2026-08-21T17:05:10.230 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:10.230 [Cloud] Dequeued cloud request. 2026-08-21T17:05:10.230 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:10.355 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.45157~. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x1ed97486 2026-08-21T17:05:10.371 [Cloud] End of cloud request. 2026-08-21T17:05:10.371 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:10.371 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:10.371 [Cloud] Queued cloud request. 2026-08-21T17:05:10.371 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:10.371 [Cloud] Dequeued cloud request. 2026-08-21T17:05:10.387 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:10.434 [Cloud] End of cloud request. 2026-08-21T17:05:10.434 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.45157~. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-08-21T17:05:10.908 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x0339abd3 2026-08-21T17:05:11.047 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:11.047 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:11.047 [Cloud] Queued cloud request. 2026-08-21T17:05:11.047 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:11.047 [Cloud] Dequeued cloud request. 2026-08-21T17:05:11.047 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:11.126 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.59969~. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xea318003 2026-08-21T17:05:11.157 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:11.157 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:11.157 [Cloud] Queued cloud request. 2026-08-21T17:05:11.157 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:11.157 [Cloud] Dequeued cloud request. 2026-08-21T17:05:11.157 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:11.173 [Cloud] End of cloud request. 2026-08-21T17:05:11.251 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\.tmp_inhalt.php.59969~. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-08-21T17:05:11.251 [Cloud] End of cloud request. 2026-08-21T17:05:11.722 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xe6f98cec 2026-08-21T17:05:12.067 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:12.067 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:12.067 [Cloud] Queued cloud request. 2026-08-21T17:05:12.067 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:12.067 [Cloud] Dequeued cloud request. 2026-08-21T17:05:12.067 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:12.118 [Cloud] End of cloud request. 2026-08-21T17:05:12.118 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\inhalt.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xce4b68a3 2026-08-21T17:05:12.146 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:12.146 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:12.146 [Cloud] Queued cloud request. 2026-08-21T17:05:12.146 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:12.146 [Cloud] Dequeued cloud request. 2026-08-21T17:05:12.146 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:12.177 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3_4_0\webinterface\inhalt.php. status=0x40030000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-08-21T17:05:12.193 [Cloud] End of cloud request. 2026-08-21T17:05:12.680 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3ed3161124cc2cdf218a2066401e528c6c394069 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:18.824 [Cloud] End of cloud request. 2026-08-21T17:05:18.824 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:18.824 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb00d244a 2026-08-21T17:05:18.899 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:18.899 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:18.899 [Cloud] Queued cloud request. 2026-08-21T17:05:18.899 [Cloud] Dequeued cloud request. 2026-08-21T17:05:18.899 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:18.899 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9da98acdccfce2a382b631f374cd9774494d55a7 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:19.125 Dynamic signature received 2026-08-21T17:05:19.134 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:19.134 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfe9f79d6 2026-08-21T17:05:19.244 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:19.244 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:19.244 [Cloud] Queued cloud request. 2026-08-21T17:05:19.244 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:19.244 [Cloud] Dequeued cloud request. 2026-08-21T17:05:19.244 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:19.354 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\abd2a5a1ee1ca84559f426bac1092e9cbdd14fe3 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:19.526 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:19.526 [Cloud] End of cloud request. 2026-08-21T17:05:19.526 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1ce6afa3 2026-08-21T17:05:19.605 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:19.605 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:19.605 [Cloud] Queued cloud request. 2026-08-21T17:05:19.605 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:19.605 [Cloud] Dequeued cloud request. 2026-08-21T17:05:19.626 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\49954ec54ab2fa510af864eb462b90ff3a7b2ec6 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:19.903 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:19.903 [Cloud] End of cloud request. 2026-08-21T17:05:19.903 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2ec00030 2026-08-21T17:05:19.966 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:19.966 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:19.966 [Cloud] Queued cloud request. 2026-08-21T17:05:19.966 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:19.966 [Cloud] Dequeued cloud request. 2026-08-21T17:05:19.982 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:20.076 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\793c3173d46e2eb5829a497bd5e839c0cb278a18 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:20.217 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:20.227 Dynamic signature received 2026-08-21T17:05:20.233 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6b9e2ba0 2026-08-21T17:05:20.359 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:20.359 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:20.359 [Cloud] Queued cloud request. 2026-08-21T17:05:20.359 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:20.359 [Cloud] Dequeued cloud request. 2026-08-21T17:05:20.359 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4a5f2f35ae0351eaae4fd503768e6a5c68387677 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:20.688 Dynamic signature received 2026-08-21T17:05:20.688 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:20.688 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7a60a790 2026-08-21T17:05:20.787 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:20.804 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:20.804 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:20.804 [Cloud] Queued cloud request. 2026-08-21T17:05:20.804 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:20.804 [Cloud] Dequeued cloud request. 2026-08-21T17:05:20.804 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ca9580c20b33c8b90b7b2d526b128a9c488e0222 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:21.112 Dynamic signature received 2026-08-21T17:05:21.112 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:21.160 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf82add20 2026-08-21T17:05:21.316 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:21.316 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:21.316 [Cloud] Queued cloud request. 2026-08-21T17:05:21.316 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:21.316 [Cloud] Dequeued cloud request. 2026-08-21T17:05:21.329 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:21.730 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7ed6084f92704f0447d90341c1288eb3c0821640 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:21.830 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:21.830 Dynamic signature received 2026-08-21T17:05:21.834 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x602f71d7 2026-08-21T17:05:21.931 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:21.931 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:21.931 [Cloud] Queued cloud request. 2026-08-21T17:05:21.931 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:21.931 [Cloud] Dequeued cloud request. 2026-08-21T17:05:21.931 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:22.399 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52ff51f9f982ed5174747ab913861e99923b6df3 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:22.508 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:22.508 [Cloud] End of cloud request. 2026-08-21T17:05:22.508 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x567ef049 2026-08-21T17:05:22.603 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:22.603 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:22.603 [Cloud] Queued cloud request. 2026-08-21T17:05:22.603 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:22.603 [Cloud] Dequeued cloud request. 2026-08-21T17:05:22.618 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:22.979 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume5\xampp\tmp\sess_8knaljhe5vttb72lf6thsmmca0. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #47012, FileId: 0x800000000692b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:05:22.979 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume5\xampp\tmp\sess_8knaljhe5vttb72lf6thsmmca0. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #47013, FileId: 0x800000000692b, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52fd88e13c4576f086cae8dd6a19df1b52ea02b0 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:23.011 Dynamic signature received 2026-08-21T17:05:23.011 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:23.011 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8d0c3a6d 2026-08-21T17:05:23.058 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:23.074 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:23.074 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:23.074 [Cloud] Queued cloud request. 2026-08-21T17:05:23.074 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:23.074 [Cloud] Dequeued cloud request. 2026-08-21T17:05:23.074 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\37fa2bd5a81ec84412827956fddee7a59d964afa Dynamic Signature Compilation Timestamp:08-21-2026 17:05:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:23.293 [Cloud] End of cloud request. 2026-08-21T17:05:23.293 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:23.309 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2c25ea29 2026-08-21T17:05:23.419 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:23.419 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:23.419 [Cloud] Queued cloud request. 2026-08-21T17:05:23.419 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:23.419 [Cloud] Dequeued cloud request. 2026-08-21T17:05:23.419 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:23.842 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\889c1a751dabd9111bbce11d2e74146d5bdcead2 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:23.967 Dynamic signature received 2026-08-21T17:05:23.967 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:23.967 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5d50809a 2026-08-21T17:05:24.046 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:24.046 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:24.046 [Cloud] Queued cloud request. 2026-08-21T17:05:24.046 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:24.046 [Cloud] Dequeued cloud request. 2026-08-21T17:05:24.046 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e90f500b785b13a35cdc0ad5da78f91e3bdf0f1e Dynamic Signature Compilation Timestamp:08-21-2026 17:05:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:24.250 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:24.250 [Cloud] End of cloud request. 2026-08-21T17:05:24.266 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x01a29ece 2026-08-21T17:05:24.517 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:05:24.517 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:24.517 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:24.517 [Cloud] Queued cloud request. 2026-08-21T17:05:24.517 [Cloud] Dequeued cloud request. 2026-08-21T17:05:24.517 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:24.517 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\58957911efbe6d66c3e33e1df3d29a62e8d65168 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:24.816 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:24.816 Dynamic signature received 2026-08-21T17:05:24.816 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8e9ca1b 2026-08-21T17:05:24.894 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:24.894 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:24.894 [Cloud] Queued cloud request. 2026-08-21T17:05:24.894 [Cloud] Dequeued cloud request. 2026-08-21T17:05:24.894 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:05:24.894 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:25.333 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9c4434fd61582aaa012202e6e92899e2324de679 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:33 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:34.362 Dynamic signature received 2026-08-21T17:05:34.362 [Cloud] End of cloud request. 2026-08-21T17:05:34.362 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1202b93f 2026-08-21T17:05:34.425 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:05:34.425 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:05:34.425 [Cloud] Queued cloud request. 2026-08-21T17:05:34.425 [Cloud] Dequeued cloud request. 2026-08-21T17:05:34.425 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:05:34.425 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\690f27176064e69ab3bb1be1f50f4d7b844ae562 Dynamic Signature Compilation Timestamp:08-21-2026 17:05:34 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:05:34.676 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:05:34.692 Dynamic signature received 2026-08-21T17:05:34.692 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=false, source=2, resourceid=0x4106df5f 2026-08-21T17:05:34.817 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\mobile_reservation_application\Mobile Reservation Application\MobileReservation.apk. status=0x40050000, statusex=0x0, threatid=0x80000000, sigseq=0x48e714e8bbc2 2026-08-21T17:05:34.865 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdf792b90 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa317ad10 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1ed809be Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x83d7e8c8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe82794b3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7147c4cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7d039c26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x46ea3cc1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1984d231 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf5e1cf3f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x697fab81 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x440fd5f9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0fc7eee6 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf3025b26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6b295342 Internal signature match:subtype=Lowfi, sigseq=0x0000157E33D9FFCA, sigsha=0459df302375d2dac3bdcc77f8de0ef87bf64a82, cached=false, source=2, resourceid=0x10f64fa9 Internal signature match:subtype=Lowfi, sigseq=0x0000157E16747B83, sigsha=3081b5e0a400ec3d535c92f38bdfd44916ec8a0a, cached=false, source=2, resourceid=0x10f64fa9 Internal signature match:subtype=Lowfi, sigseq=0x0000157E312703E4, sigsha=941d024a9558542696ff04b1f87af9ef99a0e896, cached=false, source=2, resourceid=0x10f64fa9 Internal signature match:subtype=Lowfi, sigseq=0x0000157E6535524D, sigsha=2775e3d2a670dd0502745a58bd64bee3b61f9ff3, cached=false, source=2, resourceid=0x10f64fa9 2026-08-21T17:15:58.274 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T17:31:03.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3487ddf8 2026-08-21T17:40:48.792 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:40:48.792 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:40:48.792 [Cloud] Queued cloud request. 2026-08-21T17:40:48.792 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:40:48.799 [Cloud] Dequeued cloud request. 2026-08-21T17:40:48.799 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:40:49.114 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9732dd1481eb0fa4cfd0d9d2183ec2efad3d9d65 Dynamic Signature Compilation Timestamp:08-21-2026 17:40:48 Persistence Type:Duration Time remaining:150196224 2026-08-21T17:40:49.114 [Cloud] End of cloud request. 2026-08-21T17:40:49.114 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:40:49.616 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x53c3a613 2026-08-21T17:41:19.689 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:41:19.689 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:41:19.689 [Cloud] Queued cloud request. 2026-08-21T17:41:19.689 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:41:19.689 [Cloud] Dequeued cloud request. 2026-08-21T17:41:19.689 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:41:19.925 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4ef4af46db8c29cf60c49df24f4851d9eb92ca22 Dynamic Signature Compilation Timestamp:08-21-2026 17:41:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:41:19.925 [Cloud] End of cloud request. 2026-08-21T17:41:19.925 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:41:20.427 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4d70c0d5 2026-08-21T17:41:55.567 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:41:55.567 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:41:55.567 [Cloud] Queued cloud request. 2026-08-21T17:41:55.567 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:41:55.567 [Cloud] Dequeued cloud request. 2026-08-21T17:41:55.567 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:41:55.767 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9bef75029cda1c6101ace24ce91bf3b3259944b2 Dynamic Signature Compilation Timestamp:08-21-2026 17:41:55 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:41:55.776 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:41:55.776 [Cloud] End of cloud request. 2026-08-21T17:41:56.279 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000057E76737F662, sigsha=6bc244b7f38da81f8c3ff4702633edb637f10987, cached=false, source=2, resourceid=0x7c0d4618 2026-08-21T17:42:21.168 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:42:21.168 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:42:21.168 [Cloud] Queued cloud request. 2026-08-21T17:42:21.168 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:42:21.168 [Cloud] Dequeued cloud request. 2026-08-21T17:42:21.168 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:42:21.403 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\216fd86b7e42c5ebeeee20b0981f65a0fbd3b7d9 Dynamic Signature Compilation Timestamp:08-21-2026 17:42:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:42:21.403 [Cloud] End of cloud request. 2026-08-21T17:42:21.403 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:42:21.907 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x47931bc8 2026-08-21T17:42:28.099 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:42:28.099 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:42:28.099 [Cloud] Queued cloud request. 2026-08-21T17:42:28.099 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:42:28.099 [Cloud] Dequeued cloud request. 2026-08-21T17:42:28.099 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:42:28.931 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a8ebf7226699b1611a6a73f25d2ef1943a16d829 Dynamic Signature Compilation Timestamp:08-21-2026 17:42:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:42:28.931 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:42:28.931 [Cloud] End of cloud request. 2026-08-21T17:42:29.434 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5c4e0622 2026-08-21T17:42:45.465 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:42:45.465 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:42:45.465 [Cloud] Queued cloud request. 2026-08-21T17:42:45.465 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:42:45.465 [Cloud] Dequeued cloud request. 2026-08-21T17:42:45.465 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:42:45.919 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e91d465aad82025343c793c4f8846f91eff50da5 Dynamic Signature Compilation Timestamp:08-21-2026 17:42:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:42:45.919 [Cloud] End of cloud request. 2026-08-21T17:42:45.919 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:42:46.422 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x53550db7 2026-08-21T17:42:54.985 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:42:54.985 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:42:54.985 [Cloud] Queued cloud request. 2026-08-21T17:42:54.985 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:42:54.985 [Cloud] Dequeued cloud request. 2026-08-21T17:42:54.985 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:42:55.236 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2a92949315c44984d574627703d3a4ede876c31f Dynamic Signature Compilation Timestamp:08-21-2026 17:42:54 Persistence Type:Duration Time remaining:150196224 2026-08-21T17:42:55.236 [Cloud] End of cloud request. 2026-08-21T17:42:55.236 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:42:55.739 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9e63f576 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd95d93b3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe24bfc85 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x446b5321 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x25e39bcf 2026-08-21T17:44:08.003 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:44:08.003 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:44:08.003 [Cloud] Queued cloud request. 2026-08-21T17:44:08.003 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:44:08.003 [Cloud] Dequeued cloud request. 2026-08-21T17:44:08.003 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:44:08.255 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\62e6cbc994b1babd977b1723e99eb872ae4befcf Dynamic Signature Compilation Timestamp:08-21-2026 17:44:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:44:08.255 [Cloud] End of cloud request. 2026-08-21T17:44:08.255 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:44:08.757 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9e81019d 2026-08-21T17:44:50.001 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:44:50.001 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:44:50.001 [Cloud] Queued cloud request. 2026-08-21T17:44:50.001 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:44:50.001 [Cloud] Dequeued cloud request. 2026-08-21T17:44:50.001 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:44:50.190 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\79cd681cf41c9432fdbcf679a4163d9b8b41d0a4 Dynamic Signature Compilation Timestamp:08-21-2026 17:44:49 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:44:50.190 [Cloud] End of cloud request. 2026-08-21T17:44:50.190 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:44:50.693 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0d22b62e 2026-08-21T17:45:35.112 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:45:35.112 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:45:35.112 [Cloud] Queued cloud request. 2026-08-21T17:45:35.112 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:45:35.128 [Cloud] Dequeued cloud request. 2026-08-21T17:45:35.128 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:45:35.285 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c59978cbd9743902bcd81104ed75c66c1885a900 Dynamic Signature Compilation Timestamp:08-21-2026 17:45:34 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:45:35.285 [Cloud] End of cloud request. 2026-08-21T17:45:35.285 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:45:35.788 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa0e9e9ac Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0730e3f5 2026-08-21T17:45:46.503 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:45:46.503 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:45:46.503 [Cloud] Queued cloud request. 2026-08-21T17:45:46.503 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:45:46.503 [Cloud] Dequeued cloud request. 2026-08-21T17:45:46.503 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:45:46.802 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\add99b388ef151a021ca9cd99c1e9f3f15ab433d Dynamic Signature Compilation Timestamp:08-21-2026 17:45:46 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:45:46.802 [Cloud] End of cloud request. 2026-08-21T17:45:46.802 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:45:47.304 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:46:08.267 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x46128f8d 2026-08-21T17:46:13.611 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:46:13.611 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:46:13.611 [Cloud] Queued cloud request. 2026-08-21T17:46:13.611 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:46:13.611 [Cloud] Dequeued cloud request. 2026-08-21T17:46:13.611 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:46:13.974 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5f60d006bffabfcba684acc13db43008f054ffab Dynamic Signature Compilation Timestamp:08-21-2026 17:46:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:46:13.974 [Cloud] End of cloud request. 2026-08-21T17:46:13.974 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:46:14.477 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4c00da56 2026-08-21T17:46:19.207 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:46:19.207 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:46:19.207 [Cloud] Queued cloud request. 2026-08-21T17:46:19.207 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:46:19.207 [Cloud] Dequeued cloud request. 2026-08-21T17:46:19.207 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:46:19.411 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f0e3f4ea91b46fd91e62e7906e3b815b928a559 Dynamic Signature Compilation Timestamp:08-21-2026 17:46:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:46:19.411 [Cloud] End of cloud request. 2026-08-21T17:46:19.411 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:46:19.914 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1e8293a3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E8AE2B93D, sigsha=59bec21bd6d326f674dc78ea7762d1786de72569, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x0000157E5908630E, sigsha=72178175221af4b9d01c831d0e796358fdd4a862, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x0000157EAD075680, sigsha=11ae7e5247a29dd6a9b56286bfbd80281a641085, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x0000157E12D3BC6D, sigsha=9639e45cc4469c5e75ab3ee05af548f71bbd1a2a, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x0000157E35B2A684, sigsha=14732c3ccf001af562c4a9dbba495d81cee2a028, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x0000157E1704FE79, sigsha=523194c8904ff85274a284923f4bb0d14a292332, cached=false, source=2, resourceid=0x0bcede75 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb5d00805 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5b7d9848 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbd79b7e3 2026-08-21T17:47:17.809 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:47:17.809 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:47:17.809 [Cloud] Queued cloud request. 2026-08-21T17:47:17.809 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:47:17.809 [Cloud] Dequeued cloud request. 2026-08-21T17:47:17.809 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb1f9b590 2026-08-21T17:47:18.297 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c117100b84c5be52defdc8797c6956f621fdfbb6 Dynamic Signature Compilation Timestamp:08-21-2026 17:47:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T17:47:18.297 [Cloud] End of cloud request. 2026-08-21T17:47:18.297 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:47:18.800 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5f5425dd BEGIN BM telemetry GUID:{73D3848C-63FC-4E37-94A2-1821AC2CAE17} SignatureID:340520518878414 SigSha:e1735ced290d41223a12e50689d7c8ade6f705e0 ThreatLevel:0 ProcessID:2004 ProcessCreationTime:134317859382025316 SessionID:1 CreationTime:08-21-2026 17:47:52 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-21T17:47:54.018 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:47:54.018 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:47:54.018 [Cloud] Queued cloud request. 2026-08-21T17:47:54.018 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:47:54.018 [Cloud] Dequeued cloud request. 2026-08-21T17:47:54.018 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:47:55.103 [Cloud] End of cloud request. 2026-08-21T17:47:55.606 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x65368aa8 2026-08-21T17:48:33.902 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:48:33.902 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:48:33.902 [Cloud] Queued cloud request. 2026-08-21T17:48:33.902 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:48:33.902 [Cloud] Dequeued cloud request. 2026-08-21T17:48:33.902 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:48:34.122 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0b18efa7bf834213e924f4a1751982d2c17d219d Dynamic Signature Compilation Timestamp:08-21-2026 17:48:33 Persistence Type:Duration Time remaining:150196224 2026-08-21T17:48:34.122 [Cloud] End of cloud request. 2026-08-21T17:48:34.122 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T17:48:34.625 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=2, resourceid=0xffae28fa Internal signature match:subtype=Lowfi, sigseq=0x0000157EDDE8A2A7, sigsha=d1dcbc856579ebb11815f29781799a30b23c36e7, cached=false, source=2, resourceid=0x6247b5da Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=2, resourceid=0x6247b5da 2026-08-21T17:48:39.181 FP supression checks:CheckTrusted=true (Sigseq=0x1087f4c9739c), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T17:48:39.181 SDN:Issuing SDN query for \Device\HarddiskVolume9\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe (\Device\HarddiskVolume9\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe) (sha1=493c3b008780b48413e435ae04ad39dde1bf567b, sha2=fd47386e7cebff127da53526768db1e6861e0a8fc9ac18e21fb727549dc33283) 2026-08-21T17:48:39.181 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T17:48:39.181 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:48:39.181 [Cloud] Queued cloud request. 2026-08-21T17:48:39.181 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T17:48:39.181 [Cloud] Dequeued cloud request. 2026-08-21T17:48:39.181 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:48:39.307 SDN:SDN query completed: 00000000 2026-08-21T17:48:39.307 [Cloud] End of cloud request. 2026-08-21T17:48:39.307 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume9\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe. status=0x8070022, statusex=0x200102, threatid=0x8006368b, sigseq=0x1087f4c9739c 2026-08-21T17:48:39.307 [RTP] [Mini-filter] Blocked file(#65): \Device\HarddiskVolume9\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0x0, State: 16, ScanRequest #53620, FileId: 0x20000000010c2, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x100020, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EDDE8A2A7, sigsha=d1dcbc856579ebb11815f29781799a30b23c36e7, cached=false, source=0, resourceid=0x89860dbb Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=0, resourceid=0x89860dbb 2026-08-21T17:48:39.558 FP supression checks:CheckTrusted=true (Sigseq=0x1087f4c9739c), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{A8C572B7-39D5-4822-B770-65FC7D72A38B} Scan Source:3 Start Time:08-21-2026 17:48:39 End Time:08-21-2026 17:48:39 Explicit resource to scan Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Result Count:1 Threat Name:HackTool:Win32/Gendows!pz ID:2147890827 Severity:4 Number of Resources:1 Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Extended Info - SigSeq:00001087f4c9739c Extended Info - SigSha:1a5c2385a66c9c6178fc59bacc533d8bfdae48bb End Scan ************************************************************ 2026-08-21T17:48:39.574 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 2026-08-21T17:48:39.574 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 2026-08-21T17:48:39.589 DETECTIONEVENT MPSOURCE_REALTIME HackTool:Win32/Gendows!pz file:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe; 2026-08-21T17:48:39.589 DETECTION_ADD#1 HackTool:Win32/Gendows!pz file:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe PropBag [length: 0, data: (null)] 2026-08-21T17:48:39.589 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4717 milliseconds. 1 detections to be cleaned. 2026-08-21T17:48:39.809 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4d9b804a 2026-08-21T17:48:44.319 [RoutineClean] Cleaning 1 detections Internal signature match:subtype=Lowfi, sigseq=0x0000157EDDE8A2A7, sigsha=d1dcbc856579ebb11815f29781799a30b23c36e7, cached=false, source=0, resourceid=0x89860dbb Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=0, resourceid=0x89860dbb 2026-08-21T17:48:44.540 FP supression checks:CheckTrusted=true (Sigseq=0x1087f4c9739c), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T17:48:44.586 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 Begin Resource Scan Scan ID:{3AA8B3DD-154E-4923-8D03-1F16F7660E89} Scan Source:6 Start Time:08-21-2026 17:48:44 End Time:08-21-2026 17:48:44 Explicit resource to scan Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Result Count:1 Threat Name:HackTool:Win32/Gendows!pz ID:2147890827 Severity:4 Number of Resources:1 Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Extended Info - SigSeq:00001087f4c9739c Extended Info - SigSha:1a5c2385a66c9c6178fc59bacc533d8bfdae48bb End Scan ************************************************************ 2026-08-21T17:48:44.586 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 2026-08-21T17:48:44.586 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 2026-08-21T17:48:44.586 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 Internal signature match:subtype=Lowfi, sigseq=0x0000157EDDE8A2A7, sigsha=d1dcbc856579ebb11815f29781799a30b23c36e7, cached=false, source=0, resourceid=0x89860dbb Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=0, resourceid=0x89860dbb 2026-08-21T17:48:44.869 FP supression checks:CheckTrusted=true (Sigseq=0x1087f4c9739c), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T17:48:46.613 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T17:48:46.629 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T17:48:46.629 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x49b23ddf Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x3c9400e3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1f7c0cf2 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x1f7c0cf2 2026-08-21T17:49:00.089 QuickScan:ScanID:06FB16D6-4572-43C8-95CF-CB6A3B2C2F71: Quick scan finished with error 0 2026-08-21T17:49:00.105 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 Begin Resource Scan Scan ID:{06FB16D6-4572-43C8-95CF-CB6A3B2C2F71} Scan Source:6 Start Time:08-21-2026 17:48:44 End Time:08-21-2026 17:49:00 Explicit resource to scan Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Result Count:1 Threat Name:HackTool:Win32/Gendows!pz ID:2147890827 Severity:4 Number of Resources:1 Resource Schema:file Resource Path:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Extended Info - SigSeq:00001087f4c9739c Extended Info - SigSha:1a5c2385a66c9c6178fc59bacc533d8bfdae48bb End Scan ************************************************************ FileName:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe SHA1:493c3b008780b48413e435ae04ad39dde1bf567b Internal signature match:subtype=Lowfi, sigseq=0x0000157EDDE8A2A7, sigsha=d1dcbc856579ebb11815f29781799a30b23c36e7, cached=false, source=0, resourceid=0x89860dbb Internal signature match:subtype=Lowfi, sigseq=0x0000157E8D262AFB, sigsha=1848352c7c911d71843d4c7f3a286aac6ba2cc6e, cached=false, source=0, resourceid=0x89860dbb 2026-08-21T17:49:00.451 FP supression checks:CheckTrusted=true (Sigseq=0x1087f4c9739c), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T17:49:00.531 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 HackTool:Win32/Gendows!pz file:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe; 2026-08-21T17:49:00.531 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T17:49:00.531 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:49:00.531 [Cloud] Queued cloud request. 2026-08-21T17:49:00.531 [Cloud] Dequeued cloud request. 2026-08-21T17:49:00.531 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006368b, sev - 4, category - 34). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 17:49:00 Threat Name:HackTool:Win32/Gendows!pz Threat ID:2147890827 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Threat ID:2147890827 Resource refcount:1 Result:0 File to act on SHA1:493C3B008780B48413E435AE04AD39DDE1BF567B File owner:VORDEFINIERT\Administratoren File cleaned/removed successfully File Name:I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Action remove successful on file:\\?\I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Resource action complete:Removal Schema:file Path:\\?\I:\00_WIN7_Back\ADMIN\mini-KMS_Activator_v1.2_Office2010_VL_ENG_FIXED.exe Threat ID:2147890827 Resource refcount:1 Result:0 Finished threat ID:2147890827 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 17:49:00 Result:0 2026-08-21T17:49:00.531 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T17:49:00.531 [RoutineClean] Routine cleaning timer rescheduled to fire in 4699 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T17:49:00.576 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:49:00.702 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T17:49:00.702 [Cloud] End of cloud request. 2026-08-21T17:49:01.206 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:49:02.544 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T17:49:02.544 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T17:49:02.544 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54094, FileId: 0x1f0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54096, FileId: 0x1a0000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54093, FileId: 0x190000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54099, FileId: 0x230000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54097, FileId: 0x1b0000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54102, FileId: 0x240000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54100, FileId: 0x1d0000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.043 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54095, FileId: 0x210000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.058 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54105, FileId: 0x270000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.058 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54107, FileId: 0x280000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.058 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54098, FileId: 0x220000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.058 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54109, FileId: 0x220000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.058 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54106, FileId: 0x200000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.074 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.bin. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54108, FileId: 0x210000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.074 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54111, FileId: 0x230000000ba618, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.074 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54114, FileId: 0x2b0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.074 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54112, FileId: 0x2a0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.231 [RoutineClean] Threat status changed to 0x8 (threatId: 8006368b). Skipping automatic remediation. 2026-08-21T17:49:05.499 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #54145, FileId: 0x2d0000000ba62c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:05.514 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\28124abd-f885-4846-9f92-2a54eec8425a. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc000004b, State: 0, ScanRequest #54147, FileId: 0x10200000000a327, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x2020, ScanAttributes:0x8, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T17:49:30.546 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfefab97ffffffe 2026-08-21T17:49:30.561 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T17:49:30.561 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfefab97ffffffe 2026-08-21T17:49:30.561 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9cfefab97ffffffe 2026-08-21T17:49:30.577 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T17:49:30.577 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T17:49:30.577 [Cloud] Queued cloud request. 2026-08-21T17:49:30.577 [Cloud] Dequeued cloud request. 2026-08-21T17:49:30.592 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T17:49:30.624 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T17:49:30.624 [Cloud] End of cloud request. 2026-08-21T17:49:31.127 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T17:50:26.184 Engine:Setting original file name "mavinject64.exe" for "h:\windows\system32\mavinject.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b 2026-08-21T18:01:13.261 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T18:02:01.955 Engine:Setting original file name "powershell.exe" for "h:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da 2026-08-21T18:16:18.262 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6492371d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x445272c5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2fa20ebe Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbe996f79 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb8f61125 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xde01483c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb4fb11d9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x838a4ff4 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe6f95a55 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3487c12b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xddf8e04f 2026-08-21T18:21:42.971 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:21:42.971 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:21:42.971 [Cloud] Queued cloud request. 2026-08-21T18:21:42.971 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:21:42.971 [Cloud] Dequeued cloud request. 2026-08-21T18:21:42.971 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:21:43.363 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\50a5dd18db945b83ab323fe55aeabffd75fd15af Dynamic Signature Compilation Timestamp:08-21-2026 18:21:42 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:21:43.363 [Cloud] End of cloud request. 2026-08-21T18:21:43.363 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:21:43.867 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0ae196de Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x95beda42 2026-08-21T18:21:54.334 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:21:54.334 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:21:54.334 [Cloud] Queued cloud request. 2026-08-21T18:21:54.334 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:21:54.334 [Cloud] Dequeued cloud request. 2026-08-21T18:21:54.334 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:21:54.785 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7282287b756e1da78b8d97d0e9ff16074d36acb5 Dynamic Signature Compilation Timestamp:08-21-2026 18:21:54 Persistence Type:Duration Time remaining:150196224 2026-08-21T18:21:54.801 [Cloud] End of cloud request. 2026-08-21T18:21:54.801 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:21:55.288 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9ea0acb5 2026-08-21T18:22:17.271 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:17.271 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:17.271 [Cloud] Queued cloud request. 2026-08-21T18:22:17.271 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:17.271 [Cloud] Dequeued cloud request. 2026-08-21T18:22:17.271 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:17.525 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a3163caf1a6e16580954f6a6ba42572903b53930 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:17.525 [Cloud] End of cloud request. 2026-08-21T18:22:17.525 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:22:18.030 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:19.884 Engine:Setting original file name "vssadmin.exe" for "h:\windows\system32\vssadmin.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7203b817 2026-08-21T18:22:41.597 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:41.597 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:41.597 [Cloud] Queued cloud request. 2026-08-21T18:22:41.597 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:41.597 [Cloud] Dequeued cloud request. 2026-08-21T18:22:41.597 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:41.943 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\278bdcfb43a920bd35c5288e2652b8fd7d65225c Dynamic Signature Compilation Timestamp:08-21-2026 18:22:41 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:41.943 [Cloud] End of cloud request. 2026-08-21T18:22:41.943 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:22:42.446 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31c937f9 2026-08-21T18:22:43.766 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:43.766 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:43.766 [Cloud] Queued cloud request. 2026-08-21T18:22:43.766 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:43.766 [Cloud] Dequeued cloud request. 2026-08-21T18:22:43.766 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:43.971 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dfaf355ec3d8b1e65e7b5b4ddeb7ad4faf850708 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:43 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:43.971 [Cloud] End of cloud request. 2026-08-21T18:22:43.971 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x37626aa9 2026-08-21T18:22:44.018 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:44.018 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:44.018 [Cloud] Queued cloud request. 2026-08-21T18:22:44.018 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:44.018 [Cloud] Dequeued cloud request. 2026-08-21T18:22:44.018 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:44.473 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:44.635 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\54718bbcf3d1960fcde965b8e279f9a940f8bb35 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:44 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:44.635 [Cloud] End of cloud request. 2026-08-21T18:22:44.635 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc52dc23b 2026-08-21T18:22:44.677 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:44.677 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:44.677 [Cloud] Queued cloud request. 2026-08-21T18:22:44.677 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:44.677 [Cloud] Dequeued cloud request. 2026-08-21T18:22:44.677 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:44.913 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\92e2e6262f8b23992a307868a6b366a7d204eaf6 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:44 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:44.913 [Cloud] End of cloud request. 2026-08-21T18:22:44.913 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24e13be2 2026-08-21T18:22:45.007 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:45.007 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:45.007 [Cloud] Queued cloud request. 2026-08-21T18:22:45.007 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:45.007 [Cloud] Dequeued cloud request. 2026-08-21T18:22:45.007 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:45.148 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:45.211 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cb455c4827f0f298f33d301af4e7655f65f60c37 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:44 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:45.211 [Cloud] End of cloud request. 2026-08-21T18:22:45.211 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3bae20c9 2026-08-21T18:22:45.258 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:45.258 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:45.258 [Cloud] Queued cloud request. 2026-08-21T18:22:45.258 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:45.258 [Cloud] Dequeued cloud request. 2026-08-21T18:22:45.258 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:45.493 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e28c5e328439c355990e5ef2ccdcd5c63403930f Dynamic Signature Compilation Timestamp:08-21-2026 18:22:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:45.493 [Cloud] End of cloud request. 2026-08-21T18:22:45.493 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4ab3af7e 2026-08-21T18:22:45.572 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:45.572 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:45.572 [Cloud] Queued cloud request. 2026-08-21T18:22:45.572 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:45.572 [Cloud] Dequeued cloud request. 2026-08-21T18:22:45.572 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:45.713 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:45.854 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2eb7e724238012faa858b4315e570ecd7fd20864 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:45.854 [Cloud] End of cloud request. 2026-08-21T18:22:45.854 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x805ad4f9 2026-08-21T18:22:45.901 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:45.901 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:45.901 [Cloud] Queued cloud request. 2026-08-21T18:22:45.901 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:45.901 [Cloud] Dequeued cloud request. 2026-08-21T18:22:45.901 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:46.106 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f230f2510ad963f79410bb8be675b961aecdbdee Dynamic Signature Compilation Timestamp:08-21-2026 18:22:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:46.121 [Cloud] End of cloud request. 2026-08-21T18:22:46.121 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x481fbdaa 2026-08-21T18:22:46.169 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:46.169 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:46.169 [Cloud] Queued cloud request. 2026-08-21T18:22:46.169 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:46.169 [Cloud] Dequeued cloud request. 2026-08-21T18:22:46.169 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:46.357 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:46.373 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0e6f7861c786b9f8f36fa63e08037ffe26212ece Dynamic Signature Compilation Timestamp:08-21-2026 18:22:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:46.373 [Cloud] End of cloud request. 2026-08-21T18:22:46.373 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x16f749fb 2026-08-21T18:22:46.452 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:46.452 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:46.452 [Cloud] Queued cloud request. 2026-08-21T18:22:46.452 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:46.452 [Cloud] Dequeued cloud request. 2026-08-21T18:22:46.452 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:46.671 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\17a3969341ec15d4aace305db9b5f419770e5eff Dynamic Signature Compilation Timestamp:08-21-2026 18:22:46 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:46.671 [Cloud] End of cloud request. 2026-08-21T18:22:46.671 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x09b852d0 2026-08-21T18:22:46.718 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:46.718 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:46.718 [Cloud] Queued cloud request. 2026-08-21T18:22:46.718 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:46.718 [Cloud] Dequeued cloud request. 2026-08-21T18:22:46.718 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:46.876 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:46.985 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6e19915f5ecd28a380c25eb1f7807602386e2548 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:46 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:46.985 [Cloud] End of cloud request. 2026-08-21T18:22:46.985 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x26e32905 2026-08-21T18:22:47.096 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:47.096 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:47.096 [Cloud] Queued cloud request. 2026-08-21T18:22:47.096 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:47.096 [Cloud] Dequeued cloud request. 2026-08-21T18:22:47.096 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:47.284 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b3d1f4a05d70cc49f35af75d46fb5cccb60d71a7 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:46 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:47.284 [Cloud] End of cloud request. 2026-08-21T18:22:47.284 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x877c0c41 2026-08-21T18:22:47.488 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:47.582 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:47.582 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:47.582 [Cloud] Queued cloud request. 2026-08-21T18:22:47.582 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:47.598 [Cloud] Dequeued cloud request. 2026-08-21T18:22:47.598 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\22cc3f5f23ff432e271317ea36719cfc96988f05 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:47.771 Dynamic signature received 2026-08-21T18:22:47.786 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:22:47.786 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe9347ea0 2026-08-21T18:22:47.834 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:47.834 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:47.834 [Cloud] Queued cloud request. 2026-08-21T18:22:47.834 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:47.834 [Cloud] Dequeued cloud request. 2026-08-21T18:22:47.834 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4f11743292cfd9f1299f27825cc5d94d99f23162 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:48.058 Dynamic signature received 2026-08-21T18:22:48.058 [Cloud] End of cloud request. 2026-08-21T18:22:48.058 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x665ca55c 2026-08-21T18:22:48.211 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:48.211 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:48.211 [Cloud] Queued cloud request. 2026-08-21T18:22:48.211 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:48.211 [Cloud] Dequeued cloud request. 2026-08-21T18:22:48.211 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:48.290 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:48.415 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\417db5983684f8b71643e8d9ad8f23075f3e604e Dynamic Signature Compilation Timestamp:08-21-2026 18:22:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:48.415 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:22:48.415 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x324f7b33 2026-08-21T18:22:48.463 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:48.463 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:48.463 [Cloud] Queued cloud request. 2026-08-21T18:22:48.463 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:48.463 [Cloud] Dequeued cloud request. 2026-08-21T18:22:48.463 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:48.667 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\befddf03f5ed853873c062cafddbcc7d8ff8be0b Dynamic Signature Compilation Timestamp:08-21-2026 18:22:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:48.667 [Cloud] End of cloud request. 2026-08-21T18:22:48.667 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x243b2914 2026-08-21T18:22:48.762 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:48.762 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:48.762 [Cloud] Queued cloud request. 2026-08-21T18:22:48.762 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:48.762 [Cloud] Dequeued cloud request. 2026-08-21T18:22:48.762 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:48.918 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:48.934 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bd2fb6af2e508515ba7d26fde498f00f88ceb607 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:48.934 [Cloud] End of cloud request. 2026-08-21T18:22:48.934 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xda88a7ab 2026-08-21T18:22:48.981 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:48.981 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:48.981 [Cloud] Queued cloud request. 2026-08-21T18:22:48.981 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:48.981 [Cloud] Dequeued cloud request. 2026-08-21T18:22:48.981 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:49.281 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d5bf950a57d7c293bb4e94a4fb6a110e7f1d904c Dynamic Signature Compilation Timestamp:08-21-2026 18:22:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:49.281 [Cloud] End of cloud request. 2026-08-21T18:22:49.281 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1df13b58 2026-08-21T18:22:49.375 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:49.375 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:49.375 [Cloud] Queued cloud request. 2026-08-21T18:22:49.375 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:49.375 [Cloud] Dequeued cloud request. 2026-08-21T18:22:49.375 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:49.437 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:49.594 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b24cc6dbb4365ec12a5f29fb925a0819a9a58439 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:49 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:49.594 [Cloud] End of cloud request. 2026-08-21T18:22:49.594 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x113de09b 2026-08-21T18:22:49.689 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:49.689 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:49.689 [Cloud] Queued cloud request. 2026-08-21T18:22:49.689 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:49.689 [Cloud] Dequeued cloud request. 2026-08-21T18:22:49.689 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:50.097 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:22:52.869 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\606d6af5c568d6fd32298cc13adc1f452b3e0dec Dynamic Signature Compilation Timestamp:08-21-2026 18:22:52 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:52.869 [Cloud] End of cloud request. 2026-08-21T18:22:52.869 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x53580355 2026-08-21T18:22:52.924 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:52.924 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:52.924 [Cloud] Queued cloud request. 2026-08-21T18:22:52.924 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:52.924 [Cloud] Dequeued cloud request. 2026-08-21T18:22:52.924 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:53.159 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2fce1c89b680b6ec73d3f33125429d3076b81144 Dynamic Signature Compilation Timestamp:08-21-2026 18:22:52 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:22:53.159 [Cloud] End of cloud request. 2026-08-21T18:22:53.159 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb6d775a0 2026-08-21T18:22:53.238 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:22:53.238 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:22:53.238 [Cloud] Queued cloud request. 2026-08-21T18:22:53.238 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:22:53.238 [Cloud] Dequeued cloud request. 2026-08-21T18:22:53.238 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:22:53.379 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:03.238 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\apache\modules\mod_dumpio.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c 2026-08-21T18:23:03.288 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd31c7f81 2026-08-21T18:23:03.316 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:03.316 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:03.316 [Cloud] Queued cloud request. 2026-08-21T18:23:03.316 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:03.316 [Cloud] Dequeued cloud request. 2026-08-21T18:23:03.316 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:03.803 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:10.767 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\66dc92b6f736d9ccc803982b8340bdcac1679416 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:10 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:10.767 [Cloud] End of cloud request. 2026-08-21T18:23:10.767 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x16d28dfe 2026-08-21T18:23:10.830 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:10.830 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:10.830 [Cloud] Queued cloud request. 2026-08-21T18:23:10.830 [Cloud] Dequeued cloud request. 2026-08-21T18:23:10.830 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:10.830 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:11.006 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ef47441cacdc4a080f8d88049347fd10fc085089 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:10 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:11.006 [Cloud] End of cloud request. 2026-08-21T18:23:11.006 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x94ffcc0e 2026-08-21T18:23:11.051 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:11.051 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:11.051 [Cloud] Queued cloud request. 2026-08-21T18:23:11.051 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:11.051 [Cloud] Dequeued cloud request. 2026-08-21T18:23:11.051 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:11.271 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:11.365 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\69cc5b9dab1662dd5d1a5062741acba16e52b55a Dynamic Signature Compilation Timestamp:08-21-2026 18:23:10 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:11.365 [Cloud] End of cloud request. 2026-08-21T18:23:11.365 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x918ded08 2026-08-21T18:23:11.412 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:11.412 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:11.412 [Cloud] Queued cloud request. 2026-08-21T18:23:11.412 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:11.412 [Cloud] Dequeued cloud request. 2026-08-21T18:23:11.412 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:11.663 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e16ac97e2374d34266d08dcab8fa1546dc359113 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:11 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:11.663 [Cloud] End of cloud request. 2026-08-21T18:23:11.663 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2bc5bc8d 2026-08-21T18:23:11.757 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:11.757 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:11.757 [Cloud] Queued cloud request. 2026-08-21T18:23:11.757 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:11.757 [Cloud] Dequeued cloud request. 2026-08-21T18:23:11.757 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:11.867 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:11.930 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\97521df4cbe677c6c451602036437d88fbcfb0d2 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:11 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:11.930 [Cloud] End of cloud request. 2026-08-21T18:23:11.930 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x99032028 2026-08-21T18:23:11.977 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:11.977 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:11.977 [Cloud] Queued cloud request. 2026-08-21T18:23:11.977 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:11.977 [Cloud] Dequeued cloud request. 2026-08-21T18:23:11.977 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:12.385 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e9938aaec6a3f21efddc937f4134febf0feb6516 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:11 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:12.385 [Cloud] End of cloud request. 2026-08-21T18:23:12.385 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xebb042fc 2026-08-21T18:23:12.434 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:12.449 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:12.449 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:12.449 [Cloud] Queued cloud request. 2026-08-21T18:23:12.449 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:12.449 [Cloud] Dequeued cloud request. 2026-08-21T18:23:12.449 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:13.125 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1f8d150f8f11751b38258a050281971c6b57617b Dynamic Signature Compilation Timestamp:08-21-2026 18:23:12 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:13.125 [Cloud] End of cloud request. 2026-08-21T18:23:13.125 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x624234a3 2026-08-21T18:23:13.172 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:13.172 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:13.172 [Cloud] Queued cloud request. 2026-08-21T18:23:13.172 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:13.172 [Cloud] Dequeued cloud request. 2026-08-21T18:23:13.172 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:13.360 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3e92a9587e8e1224013665f4dec2538cb1509bd8 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:12 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:13.360 [Cloud] End of cloud request. 2026-08-21T18:23:13.360 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x03c110c6 2026-08-21T18:23:13.410 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:13.410 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:13.410 [Cloud] Queued cloud request. 2026-08-21T18:23:13.410 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:13.410 [Cloud] Dequeued cloud request. 2026-08-21T18:23:13.410 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:13.628 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:13.643 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c7147c4cc13ed71233558e23b5ca00ffa16958f4 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:13.643 [Cloud] End of cloud request. 2026-08-21T18:23:13.643 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9996dcb 2026-08-21T18:23:13.800 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:13.800 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:13.800 [Cloud] Queued cloud request. 2026-08-21T18:23:13.800 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:13.800 [Cloud] Dequeued cloud request. 2026-08-21T18:23:13.800 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:14.052 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2849a0fe4a5e5adbe2ffeb75bc7c7ab0b1188696 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:14.067 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:14.067 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5c9f5c6c 2026-08-21T18:23:14.112 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:14.112 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:14.112 [Cloud] Queued cloud request. 2026-08-21T18:23:14.112 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:14.112 [Cloud] Dequeued cloud request. 2026-08-21T18:23:14.112 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:14.146 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:14.287 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\38f61784c0f5d6a53c7175f691b765f4c014b324 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:14.287 [Cloud] End of cloud request. 2026-08-21T18:23:14.287 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x06c0b6b9 2026-08-21T18:23:14.335 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:14.335 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:14.335 [Cloud] Queued cloud request. 2026-08-21T18:23:14.335 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:14.335 [Cloud] Dequeued cloud request. 2026-08-21T18:23:14.335 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:14.790 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:14.813 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6ebc253ef061de53e26c6dd06edc1ead0a60de28 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:14 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:14.813 [Cloud] End of cloud request. 2026-08-21T18:23:14.813 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1d4a04d6 2026-08-21T18:23:14.853 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:14.853 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:14.853 [Cloud] Queued cloud request. 2026-08-21T18:23:14.853 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:14.853 [Cloud] Dequeued cloud request. 2026-08-21T18:23:14.853 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:15.152 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3366da51f895dfb6fb88e3d219431e0973dc569f Dynamic Signature Compilation Timestamp:08-21-2026 18:23:14 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:15.152 [Cloud] End of cloud request. 2026-08-21T18:23:15.152 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00e4b594 2026-08-21T18:23:15.198 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:15.198 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:15.198 [Cloud] Queued cloud request. 2026-08-21T18:23:15.198 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:15.198 [Cloud] Dequeued cloud request. 2026-08-21T18:23:15.213 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:15.324 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:15.450 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7dcc8723772ad13427f2dfd25e74ed43e80b8819 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:15.450 [Cloud] End of cloud request. 2026-08-21T18:23:15.450 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd41d4dd7 2026-08-21T18:23:15.528 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:15.528 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:15.528 [Cloud] Queued cloud request. 2026-08-21T18:23:15.528 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:15.528 [Cloud] Dequeued cloud request. 2026-08-21T18:23:15.528 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:15.717 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d3395a6bca70ecc7bc3a7e4d4e268c48a255b052 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:15.717 [Cloud] End of cloud request. 2026-08-21T18:23:15.717 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfb821569 2026-08-21T18:23:15.764 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:15.764 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:15.764 [Cloud] Queued cloud request. 2026-08-21T18:23:15.764 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:15.764 [Cloud] Dequeued cloud request. 2026-08-21T18:23:15.764 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:15.952 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:15.983 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d2c11343cbcad7216a7efff23333df604fcce313 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:15.983 [Cloud] End of cloud request. 2026-08-21T18:23:15.983 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x78157ac3 2026-08-21T18:23:16.031 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:16.031 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:16.031 [Cloud] Queued cloud request. 2026-08-21T18:23:16.031 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:16.031 [Cloud] Dequeued cloud request. 2026-08-21T18:23:16.031 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:16.488 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:16.534 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\49071a34147be8ce95a5b5cd99ff273934183be0 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:16.534 [Cloud] End of cloud request. 2026-08-21T18:23:16.534 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9aa30290 2026-08-21T18:23:16.596 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:16.596 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:16.596 [Cloud] Queued cloud request. 2026-08-21T18:23:16.596 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:16.596 [Cloud] Dequeued cloud request. 2026-08-21T18:23:16.596 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:16.769 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\292c9cb1c26851c9ea54763327e193fbace62998 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:16.769 [Cloud] End of cloud request. 2026-08-21T18:23:16.769 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc1aeffb2 2026-08-21T18:23:16.816 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:16.816 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:16.816 [Cloud] Queued cloud request. 2026-08-21T18:23:16.816 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:16.816 [Cloud] Dequeued cloud request. 2026-08-21T18:23:16.816 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:17.036 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:17.100 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4843eae99766abde6a1b4d957fe9dbd8684bf6f0 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:17.115 [Cloud] End of cloud request. 2026-08-21T18:23:17.115 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa38a8b2e 2026-08-21T18:23:17.178 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:17.178 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:17.178 [Cloud] Queued cloud request. 2026-08-21T18:23:17.178 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:17.178 [Cloud] Dequeued cloud request. 2026-08-21T18:23:17.178 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:17.367 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a9a43afa2d6e8f325de8fd477426098403a6b436 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:17.367 [Cloud] End of cloud request. 2026-08-21T18:23:17.367 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2e80c7e7 2026-08-21T18:23:17.461 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:17.461 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:17.461 [Cloud] Queued cloud request. 2026-08-21T18:23:17.461 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:17.461 [Cloud] Dequeued cloud request. 2026-08-21T18:23:17.461 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:17.618 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:17.664 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1c1d75a5bc6f926434641467a61ecfff38ec1f1c Dynamic Signature Compilation Timestamp:08-21-2026 18:23:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:17.664 [Cloud] End of cloud request. 2026-08-21T18:23:17.664 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6827b13 2026-08-21T18:23:17.837 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:17.837 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:17.837 [Cloud] Queued cloud request. 2026-08-21T18:23:17.837 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:17.837 [Cloud] Dequeued cloud request. 2026-08-21T18:23:17.837 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:18.027 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\87446a6d8770a5f539ba4750e7626693e56a559e Dynamic Signature Compilation Timestamp:08-21-2026 18:23:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:18.027 [Cloud] End of cloud request. 2026-08-21T18:23:18.027 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfbc97200 2026-08-21T18:23:18.074 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:18.074 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:18.074 [Cloud] Queued cloud request. 2026-08-21T18:23:18.074 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:18.074 [Cloud] Dequeued cloud request. 2026-08-21T18:23:18.074 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:18.168 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:18.372 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a21db9d7e5ca9f0f747a3ea120a171a8172591ee Dynamic Signature Compilation Timestamp:08-21-2026 18:23:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:18.372 [Cloud] End of cloud request. 2026-08-21T18:23:18.372 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x17ee542c 2026-08-21T18:23:18.419 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:18.419 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:18.419 [Cloud] Queued cloud request. 2026-08-21T18:23:18.419 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:18.419 [Cloud] Dequeued cloud request. 2026-08-21T18:23:18.419 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:18.623 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5cfaf207ce5a41cc9c811ffbfd8441ae97867071 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:18.623 [Cloud] End of cloud request. 2026-08-21T18:23:18.623 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5d8dd638 2026-08-21T18:23:18.670 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:18.670 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:18.670 [Cloud] Queued cloud request. 2026-08-21T18:23:18.670 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:18.670 [Cloud] Dequeued cloud request. 2026-08-21T18:23:18.670 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:18.874 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:18.906 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9b633ad338682b27f8a7820a680bd86bd41284fa Dynamic Signature Compilation Timestamp:08-21-2026 18:23:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:18.906 [Cloud] End of cloud request. 2026-08-21T18:23:18.906 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x66c5e5f7 2026-08-21T18:23:18.953 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:18.953 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:18.953 [Cloud] Queued cloud request. 2026-08-21T18:23:18.953 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:18.953 [Cloud] Dequeued cloud request. 2026-08-21T18:23:18.953 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:19.142 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e3adef497bf2241d0e28fc9a1d7b514ac3657116 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:19.142 [Cloud] End of cloud request. 2026-08-21T18:23:19.142 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf62ebe20 2026-08-21T18:23:19.189 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:19.189 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:19.189 [Cloud] Queued cloud request. 2026-08-21T18:23:19.189 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:19.189 [Cloud] Dequeued cloud request. 2026-08-21T18:23:19.189 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:19.377 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4554ee51432f5e404a8a56f824017c537816dcd8 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:19.377 [Cloud] End of cloud request. 2026-08-21T18:23:19.377 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb1541966 2026-08-21T18:23:19.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:19.425 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:19.425 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:19.425 [Cloud] Queued cloud request. 2026-08-21T18:23:19.425 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:19.425 [Cloud] Dequeued cloud request. 2026-08-21T18:23:19.425 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:19.629 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\21a9fd9276fcd09c536e06f70160a65bf14e608b Dynamic Signature Compilation Timestamp:08-21-2026 18:23:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:19.629 [Cloud] End of cloud request. 2026-08-21T18:23:19.629 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x41fb9720 2026-08-21T18:23:19.676 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:19.676 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:19.676 [Cloud] Queued cloud request. 2026-08-21T18:23:19.676 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:19.676 [Cloud] Dequeued cloud request. 2026-08-21T18:23:19.676 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:19.864 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5bc297e4c79c664a5bc63417560089dee7bffb87 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:19.864 [Cloud] End of cloud request. 2026-08-21T18:23:19.864 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9841c3bc 2026-08-21T18:23:19.922 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:19.922 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:19.922 [Cloud] Queued cloud request. 2026-08-21T18:23:19.922 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:19.922 [Cloud] Dequeued cloud request. 2026-08-21T18:23:19.922 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:20.115 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cffd94707850037df5cd0e92f54e25aa41664a54 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:20.115 [Cloud] End of cloud request. 2026-08-21T18:23:20.115 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:20.131 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbf9c8439 2026-08-21T18:23:20.163 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:20.163 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:20.163 [Cloud] Queued cloud request. 2026-08-21T18:23:20.163 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:20.163 [Cloud] Dequeued cloud request. 2026-08-21T18:23:20.163 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:20.791 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7ce9003e996e329cb5b5aa2af83cc86217e523bc Dynamic Signature Compilation Timestamp:08-21-2026 18:23:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:20.806 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:20.806 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb2eb062e 2026-08-21T18:23:20.838 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:20.838 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:20.838 [Cloud] Queued cloud request. 2026-08-21T18:23:20.838 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:20.838 [Cloud] Dequeued cloud request. 2026-08-21T18:23:20.854 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:21.309 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:21.356 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f4da48d148fd5e019b007dfca696ba861d51202e Dynamic Signature Compilation Timestamp:08-21-2026 18:23:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:21.356 [Cloud] End of cloud request. 2026-08-21T18:23:21.356 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc28eb9c1 2026-08-21T18:23:21.403 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:21.403 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:21.403 [Cloud] Queued cloud request. 2026-08-21T18:23:21.403 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:21.403 [Cloud] Dequeued cloud request. 2026-08-21T18:23:21.419 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\11118e4bf75310c597534b232dda8d39d0e5082d Dynamic Signature Compilation Timestamp:08-21-2026 18:23:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:21.595 Dynamic signature received 2026-08-21T18:23:21.595 [Cloud] End of cloud request. 2026-08-21T18:23:21.595 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc82f2171 2026-08-21T18:23:21.650 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:21.650 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:21.650 [Cloud] Queued cloud request. 2026-08-21T18:23:21.650 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:21.650 [Cloud] Dequeued cloud request. 2026-08-21T18:23:21.650 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:21.830 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f4fc268e82df62cb47956d2917dffee0a8733676 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:21.830 [Cloud] End of cloud request. 2026-08-21T18:23:21.830 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13090ddd 2026-08-21T18:23:21.876 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:21.876 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:21.876 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:21.876 [Cloud] Queued cloud request. 2026-08-21T18:23:21.876 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:21.876 [Cloud] Dequeued cloud request. 2026-08-21T18:23:21.876 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:22.379 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dec5e14cc30e4f2d281f29229025548024dd8f99 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:22.379 [Cloud] End of cloud request. 2026-08-21T18:23:22.379 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x365a0a20 2026-08-21T18:23:22.427 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:22.427 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:22.427 [Cloud] Queued cloud request. 2026-08-21T18:23:22.427 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:22.427 [Cloud] Dequeued cloud request. 2026-08-21T18:23:22.427 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:22.631 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a70b7d9e2446ff863bfb4d198cdde6e94ee9778c Dynamic Signature Compilation Timestamp:08-21-2026 18:23:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:22.647 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:22.647 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5252ffda 2026-08-21T18:23:22.678 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:22.678 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:22.678 [Cloud] Queued cloud request. 2026-08-21T18:23:22.678 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:22.678 [Cloud] Dequeued cloud request. 2026-08-21T18:23:22.678 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:22.882 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\460b44100852ccf79f58c5d46d53d69fd5cf7da5 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:22.897 Dynamic signature received 2026-08-21T18:23:22.897 [Cloud] End of cloud request. 2026-08-21T18:23:22.897 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb54c21d1 2026-08-21T18:23:22.960 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:22.960 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:22.960 [Cloud] Queued cloud request. 2026-08-21T18:23:22.960 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:22.960 [Cloud] Dequeued cloud request. 2026-08-21T18:23:22.960 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:23.149 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fa6400d4a691ea4641da9aab5e7c51e0abab7175 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:23.149 [Cloud] End of cloud request. 2026-08-21T18:23:23.149 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b61ff91 2026-08-21T18:23:23.228 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:23.228 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:23.228 [Cloud] Queued cloud request. 2026-08-21T18:23:23.228 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:23.228 [Cloud] Dequeued cloud request. 2026-08-21T18:23:23.228 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:23.400 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:23.714 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0475ca0eb7f47e16928d4ffe1d547e07f8c90011 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:23.714 [Cloud] End of cloud request. 2026-08-21T18:23:23.714 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7aaa7546 2026-08-21T18:23:23.761 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:23.761 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:23.761 [Cloud] Queued cloud request. 2026-08-21T18:23:23.761 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:23.761 [Cloud] Dequeued cloud request. 2026-08-21T18:23:23.761 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:23.965 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d058fc05cbb1ee1016abab3c61291cb2e693c118 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:23.965 [Cloud] End of cloud request. 2026-08-21T18:23:23.965 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x84d37758 2026-08-21T18:23:24.012 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:24.012 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:24.012 [Cloud] Queued cloud request. 2026-08-21T18:23:24.012 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:24.012 [Cloud] Dequeued cloud request. 2026-08-21T18:23:24.012 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:24.216 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:24.311 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9e06d3a18f67c1096c6f3de50144fdbb93c98bbe Dynamic Signature Compilation Timestamp:08-21-2026 18:23:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:24.311 [Cloud] End of cloud request. 2026-08-21T18:23:24.311 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcbd42327 2026-08-21T18:23:24.358 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:24.358 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:24.358 [Cloud] Queued cloud request. 2026-08-21T18:23:24.358 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:24.358 [Cloud] Dequeued cloud request. 2026-08-21T18:23:24.374 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:24.562 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\122c3f11a27299e7944ed9edd761dcba551ac266 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:24.562 [Cloud] End of cloud request. 2026-08-21T18:23:24.562 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52b191ed 2026-08-21T18:23:24.611 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:24.611 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:24.611 [Cloud] Queued cloud request. 2026-08-21T18:23:24.611 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:24.611 [Cloud] Dequeued cloud request. 2026-08-21T18:23:24.611 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:24.813 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:24.832 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c96773e141c0d41897cc92394e4fa8e7a2ee6700 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:24.832 [Cloud] End of cloud request. 2026-08-21T18:23:24.832 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x982c5a0c 2026-08-21T18:23:24.923 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:24.923 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:24.923 [Cloud] Queued cloud request. 2026-08-21T18:23:24.923 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:24.923 [Cloud] Dequeued cloud request. 2026-08-21T18:23:24.923 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:25.132 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8010518cf2770b10680fd49ccb9a49064e497f1b Dynamic Signature Compilation Timestamp:08-21-2026 18:23:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:25.132 [Cloud] End of cloud request. 2026-08-21T18:23:25.132 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4471ecef 2026-08-21T18:23:25.175 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:25.175 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:25.175 [Cloud] Queued cloud request. 2026-08-21T18:23:25.175 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:25.175 [Cloud] Dequeued cloud request. 2026-08-21T18:23:25.175 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:25.332 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:25.364 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\88b08f4b909b7a29312c0ba573ebc32526d83f16 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:25.364 [Cloud] End of cloud request. 2026-08-21T18:23:25.364 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x19b1910e 2026-08-21T18:23:25.410 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:25.410 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:25.410 [Cloud] Queued cloud request. 2026-08-21T18:23:25.410 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:25.410 [Cloud] Dequeued cloud request. 2026-08-21T18:23:25.410 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:25.633 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c8fe36f4f3d356a1cdef306eeef257f3a9bd6396 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:25.633 [Cloud] End of cloud request. 2026-08-21T18:23:25.633 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d827a5d 2026-08-21T18:23:25.678 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:25.678 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:25.678 [Cloud] Queued cloud request. 2026-08-21T18:23:25.678 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:25.678 [Cloud] Dequeued cloud request. 2026-08-21T18:23:25.678 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:25.868 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:25.868 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0fbe80d60199541647bd1932084302cfea9cbb43 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:25.868 [Cloud] End of cloud request. 2026-08-21T18:23:25.868 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xebe4e8ec 2026-08-21T18:23:25.931 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:25.931 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:25.931 [Cloud] Queued cloud request. 2026-08-21T18:23:25.931 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:25.931 [Cloud] Dequeued cloud request. 2026-08-21T18:23:25.931 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:26.135 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1e854befe2a0976f20b48767e5688f2a9dd0bd5d Dynamic Signature Compilation Timestamp:08-21-2026 18:23:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:26.135 [Cloud] End of cloud request. 2026-08-21T18:23:26.135 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc5eee74c 2026-08-21T18:23:26.213 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:26.213 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:26.213 [Cloud] Queued cloud request. 2026-08-21T18:23:26.213 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:26.213 [Cloud] Dequeued cloud request. 2026-08-21T18:23:26.213 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:26.371 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:26.402 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\17a0972d29cad5d44490f9f73cdc8834032f2781 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:26.418 [Cloud] End of cloud request. 2026-08-21T18:23:26.418 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0973a9a 2026-08-21T18:23:26.544 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:26.544 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:26.544 [Cloud] Queued cloud request. 2026-08-21T18:23:26.544 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:26.544 [Cloud] Dequeued cloud request. 2026-08-21T18:23:26.544 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:26.920 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:27.249 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2089a00428c813c103ebd44d6e394fcecabb3bc1 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:26 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:27.249 [Cloud] End of cloud request. 2026-08-21T18:23:27.249 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc331100d 2026-08-21T18:23:27.281 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:27.281 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:27.281 [Cloud] Queued cloud request. 2026-08-21T18:23:27.281 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:27.281 [Cloud] Dequeued cloud request. 2026-08-21T18:23:27.281 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:27.486 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\613e9f3d724f9b4696e8eb17fac5b62f82eb7bbe Dynamic Signature Compilation Timestamp:08-21-2026 18:23:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:27.486 [Cloud] End of cloud request. 2026-08-21T18:23:27.486 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4e4aebcf 2026-08-21T18:23:27.533 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:27.533 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:27.533 [Cloud] Queued cloud request. 2026-08-21T18:23:27.533 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:27.533 [Cloud] Dequeued cloud request. 2026-08-21T18:23:27.533 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:27.722 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\36c895ded239d29174245150e9546488f2d4bb19 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:27.722 [Cloud] End of cloud request. 2026-08-21T18:23:27.722 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3fb10b47 2026-08-21T18:23:27.754 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:27.769 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:27.769 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:27.769 [Cloud] Queued cloud request. 2026-08-21T18:23:27.769 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:27.769 [Cloud] Dequeued cloud request. 2026-08-21T18:23:27.769 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:27.958 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a1ffaaa8dc0361c276ac1d74202458a207cfac07 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:27.958 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:27.958 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xff4834c8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76da9587 2026-08-21T18:23:28.054 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:28.054 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:28.054 [Cloud] Queued cloud request. 2026-08-21T18:23:28.054 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:28.054 [Cloud] Dequeued cloud request. 2026-08-21T18:23:28.054 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:28.256 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a5e9fdb8218ff018bc5d74325b31e1869097da72 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:28.256 [Cloud] End of cloud request. 2026-08-21T18:23:28.256 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xee3e28df 2026-08-21T18:23:28.303 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:28.303 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:28.303 [Cloud] Queued cloud request. 2026-08-21T18:23:28.303 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:28.303 [Cloud] Dequeued cloud request. 2026-08-21T18:23:28.303 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:28.461 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:23:28.508 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8207fb0c4b67b6c54c93a42fead7673684fb0bbc Dynamic Signature Compilation Timestamp:08-21-2026 18:23:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:28.508 [Cloud] End of cloud request. 2026-08-21T18:23:28.508 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9a3f3c7f 2026-08-21T18:23:28.555 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:28.555 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:28.555 [Cloud] Queued cloud request. 2026-08-21T18:23:28.555 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:28.555 [Cloud] Dequeued cloud request. 2026-08-21T18:23:28.555 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:28.792 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1f6019a079a1a20d84bbe39233aaa5733a6f300f Dynamic Signature Compilation Timestamp:08-21-2026 18:23:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:28.792 [Cloud] End of cloud request. 2026-08-21T18:23:28.792 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:29.012 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc2b54150 2026-08-21T18:23:41.536 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:23:41.536 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:23:41.536 [Cloud] Queued cloud request. 2026-08-21T18:23:41.536 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:23:41.536 [Cloud] Dequeued cloud request. 2026-08-21T18:23:41.536 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:23:41.725 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b8a733bec4743c45e08e506c6387ecb8cd238c96 Dynamic Signature Compilation Timestamp:08-21-2026 18:23:41 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:23:41.725 [Cloud] End of cloud request. 2026-08-21T18:23:41.725 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:23:42.238 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd0877ccc 2026-08-21T18:24:12.839 Engine:Setting original file name "tv_x64.exe" for "c:\program files\teamviewer\tv_w32.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000052E72DF804AF, sigsha=bbf09fcebd5c4064c1b3601dead4f4ba6b966f6f, cached=false, source=2, resourceid=0xb6c04848 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24992611 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5579db6b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42357c3b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x50b6cf2f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x411338da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcb8c505f 2026-08-21T18:26:08.098 Engine:Setting original file name "pcalua.exe" for "h:\windows\system32\pcacli.dll", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x93b9c324 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb2d4992d 2026-08-21T18:26:53.992 Engine:Setting original file name "pcalua.exe" for "h:\windows\system32\pcadm.dll", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xeaafb7af 2026-08-21T18:26:57.575 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:26:57.575 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:26:57.575 [Cloud] Queued cloud request. 2026-08-21T18:26:57.575 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:26:57.575 [Cloud] Dequeued cloud request. 2026-08-21T18:26:57.575 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:26:58.031 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\420de1cd56f892f9f1af55f55d180ad3f26853b4 Dynamic Signature Compilation Timestamp:08-21-2026 18:26:57 Persistence Type:Duration Time remaining:150196224 2026-08-21T18:26:58.031 [Cloud] End of cloud request. 2026-08-21T18:26:58.031 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:26:58.534 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:27:38.509 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Windows\Installer\d6f94.msp` is 5015 units Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b0c8c85 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x88499b5b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x306e16d7 Internal signature match:subtype=Lowfi, sigseq=0x0000157E75339128, sigsha=657424af072abcbb34a34c62d8b4c3b06789e95f, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E5908630E, sigsha=72178175221af4b9d01c831d0e796358fdd4a862, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x0000157EAD075680, sigsha=11ae7e5247a29dd6a9b56286bfbd80281a641085, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E12D3BC6D, sigsha=9639e45cc4469c5e75ab3ee05af548f71bbd1a2a, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E35B2A684, sigsha=14732c3ccf001af562c4a9dbba495d81cee2a028, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x0000157E1704FE79, sigsha=523194c8904ff85274a284923f4bb0d14a292332, cached=false, source=2, resourceid=0xa43ffab3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x94d672bf 2026-08-21T18:29:13.359 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:29:13.359 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:29:13.359 [Cloud] Queued cloud request. 2026-08-21T18:29:13.359 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:29:13.359 [Cloud] Dequeued cloud request. 2026-08-21T18:29:13.359 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:29:16.032 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1f2314dd8fd13ff8fb9f85ec44e378a5dd3a3fb5 Dynamic Signature Compilation Timestamp:08-21-2026 18:29:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:29:16.032 [Cloud] End of cloud request. 2026-08-21T18:29:16.032 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4fe005c 2026-08-21T18:29:16.534 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:29:18.075 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:29:18.075 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:29:18.075 [Cloud] Queued cloud request. 2026-08-21T18:29:18.075 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:29:18.075 [Cloud] Dequeued cloud request. 2026-08-21T18:29:18.075 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\334b622601431821da7cc3d63777c103723b7904 Dynamic Signature Compilation Timestamp:08-21-2026 18:29:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:29:19.000 [Cloud] End of cloud request. 2026-08-21T18:29:19.000 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:29:19.000 Dynamic signature received 2026-08-21T18:29:19.503 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x760a69c6 2026-08-21T18:29:24.326 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:29:24.326 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:29:24.326 [Cloud] Queued cloud request. 2026-08-21T18:29:24.326 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:29:24.326 [Cloud] Dequeued cloud request. 2026-08-21T18:29:24.326 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:29:24.530 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ee28b44e727faf72d8a2ba8a978c7c348a539c33 Dynamic Signature Compilation Timestamp:08-21-2026 18:29:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:29:24.530 [Cloud] End of cloud request. 2026-08-21T18:29:24.530 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:29:25.033 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6ec76438 2026-08-21T18:30:14.122 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:30:14.134 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:30:14.134 [Cloud] Queued cloud request. 2026-08-21T18:30:14.134 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:30:14.134 [Cloud] Dequeued cloud request. 2026-08-21T18:30:14.134 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:30:14.338 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4012434b3ef6e393a884fd43ba65494048e3defe Dynamic Signature Compilation Timestamp:08-21-2026 18:30:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T18:30:14.338 [Cloud] End of cloud request. 2026-08-21T18:30:14.338 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:30:14.840 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000108090FCF4C4, sigsha=064f0536ffb97bb72d6c274c080aa4e2ffdf1b46, cached=false, source=2, resourceid=0x7d9fb4f5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9637729e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbfdca678 2026-08-21T18:31:19.574 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:31:19.574 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:31:19.574 [Cloud] Queued cloud request. 2026-08-21T18:31:19.574 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:31:19.574 [Cloud] Dequeued cloud request. 2026-08-21T18:31:19.574 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:31:20.187 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c33353674b5bd7f9c5529c87367c2e30d85c94fc Dynamic Signature Compilation Timestamp:08-21-2026 18:31:19 Persistence Type:Duration Time remaining:150196224 2026-08-21T18:31:20.187 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:31:20.187 [Cloud] End of cloud request. 2026-08-21T18:31:20.690 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:31:23.173 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=true, source=2, resourceid=0xa892ddd6 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbbe8f989 Internal signature match:subtype=Lowfi, sigseq=0x0000157E437254D1, sigsha=1890106486153e15a5f6cf75dc244a4840e483e1, cached=false, source=2, resourceid=0x8e1369c1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb881d8cf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x03e3429d 2026-08-21T18:39:38.801 Bm signature throttled:0x00002db31bed458f 2026-08-21T18:39:38.966 Bm signature throttled:0x00002db31bed458f 2026-08-21T18:40:26.721 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1C4D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #64217, FileId: 0x21a000000002e84, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:42:28.646 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:42:28.664 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:42:28.665 SDN:Issuing SDN query for \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) (sha1=822713aa20db9cf9577a00d7e5387f43d28377d2, sha2=091c335c3b64d9ec35619e67c14ce9370bae28f9b46b0836d5ced112ee3d2e06) 2026-08-21T18:42:28.671 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:42:28.671 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:42:28.671 [Cloud] Queued cloud request. 2026-08-21T18:42:28.671 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:42:28.671 [Cloud] Dequeued cloud request. 2026-08-21T18:42:28.672 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:42:28.941 SDN:SDN query completed: 00000000 2026-08-21T18:42:28.941 [Cloud] End of cloud request. 2026-08-21T18:42:28.943 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:42:28.946 [RTP] [Mini-filter] Blocked file(#86): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #64381, FileId: 0x8000000006991, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:42:28.965 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:42:28.981 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{0EFEC8E5-AE8F-425A-9B05-F99343E4FB58} Scan Source:3 Start Time:08-21-2026 18:42:28 End Time:08-21-2026 18:42:28 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:42:28.987 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:42:28.988 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:42:28.993 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:42:28.995 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:42:28.995 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4949 milliseconds. 1 detections to be cleaned. 2026-08-21T18:42:29.464 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:42:33.946 [RoutineClean] Cleaning 1 detections 2026-08-21T18:42:33.966 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:42:33.983 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:42:33.990 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{3DFA239F-48F8-4148-9CB4-F4C4778C4E4D} Scan Source:6 Start Time:08-21-2026 18:42:33 End Time:08-21-2026 18:42:33 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:42:33.998 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:42:33.999 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:42:34.001 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:42:34.020 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:42:34.036 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:42:36.013 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:42:36.021 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:42:36.023 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:42:49.771 QuickScan:ScanID:1DB10A08-F57B-430E-B7B6-5FB485AE328A: Quick scan finished with error 0 2026-08-21T18:42:49.777 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{1DB10A08-F57B-430E-B7B6-5FB485AE328A} Scan Source:6 Start Time:08-21-2026 18:42:34 End Time:08-21-2026 18:42:49 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T18:42:49.878 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:42:49.895 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:42:49.898 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:42:49.904 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T18:42:49.904 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:42:49.904 [Cloud] Queued cloud request. 2026-08-21T18:42:49.904 [Cloud] Dequeued cloud request. 2026-08-21T18:42:49.905 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 18:42:49 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 18:42:49 Result:0 2026-08-21T18:42:49.907 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:42:49.907 [RoutineClean] Routine cleaning timer rescheduled to fire in 4939 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:42:49.935 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:42:50.059 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:42:50.059 [Cloud] End of cloud request. 2026-08-21T18:42:50.578 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:42:51.923 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:42:51.929 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:42:51.931 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:42:54.848 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:43:19.912 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x682ecf887ffffffe 2026-08-21T18:43:19.922 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T18:43:19.926 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x682ecf887ffffffe 2026-08-21T18:43:19.929 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x682ecf887ffffffe 2026-08-21T18:43:19.945 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T18:43:19.945 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:43:19.945 [Cloud] Queued cloud request. 2026-08-21T18:43:19.945 [Cloud] Dequeued cloud request. 2026-08-21T18:43:19.969 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:43:20.010 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:43:20.010 [Cloud] End of cloud request. 2026-08-21T18:43:20.524 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:46:28.066 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T18:49:56.607 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:49:56.624 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:49:56.627 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:49:56.632 [RTP] [Mini-filter] Blocked file(#87): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #64980, FileId: 0x8000000006992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:49:56.652 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:49:56.672 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{052733D3-EAB9-45A2-8DA7-E1F00CDECA9C} Scan Source:3 Start Time:08-21-2026 18:49:56 End Time:08-21-2026 18:49:56 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:49:56.681 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:49:56.683 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:49:56.689 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:49:56.692 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:49:56.692 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4936 milliseconds. 1 detections to be cleaned. 2026-08-21T18:50:01.631 [RoutineClean] Cleaning 1 detections 2026-08-21T18:50:01.652 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:01.668 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:01.675 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{3C80227E-E1DB-4FA8-9C24-7BE8D9277DA1} Scan Source:6 Start Time:08-21-2026 18:50:01 End Time:08-21-2026 18:50:01 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:50:01.681 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:01.682 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:01.683 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:01.798 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:01.820 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:03.699 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:03.713 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:50:03.714 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:17.190 QuickScan:ScanID:F8313ABF-12A3-4175-A84F-B6ABEA0BFC5D: Quick scan finished with error 0 2026-08-21T18:50:17.195 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{F8313ABF-12A3-4175-A84F-B6ABEA0BFC5D} Scan Source:6 Start Time:08-21-2026 18:50:01 End Time:08-21-2026 18:50:17 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T18:50:17.304 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:17.320 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:17.324 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:17.330 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T18:50:17.330 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:50:17.330 [Cloud] Queued cloud request. 2026-08-21T18:50:17.330 [Cloud] Dequeued cloud request. 2026-08-21T18:50:17.331 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Beginning threat actions Start time:08-21-2026 18:50:17 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 18:50:17 Result:0 2026-08-21T18:50:17.333 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:50:17.334 [RoutineClean] Routine cleaning timer rescheduled to fire in 4940 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:50:17.379 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:50:17.628 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:50:17.628 [Cloud] End of cloud request. 2026-08-21T18:50:18.150 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:50:19.342 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:19.352 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:50:19.354 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:22.288 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:50:25.583 Created on demand scan context for ScanType:1. ScanTrigger:0, ScanId:A5FF4E19-7F95-4B50-9622-5AE943D34701, Source: MPSOURCE_USER(1), EngineSource: MP_SCANSOURCE_ONDEMAND(2) 2026-08-21T18:50:25.584 [SFC] MpCmIsBuildPermissible(1) returns S_OK. Start SFC build. 2026-08-21T18:50:25.584 [SFC] System file cache build is not needed (already completed) 2026-08-21T18:50:30.635 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-21T18:50:30.776 MPCONTROL_ABORT invoked for ScanId:A5FF4E19-7F95-4B50-9622-5AE943D34701. Canceling the scan. reason:1 2026-08-21T18:50:30.836 HandleOnDemandStatusChange: Scan Cancelled, pActiveScan->hScanCancelEvent signaled for ScanID:A5FF4E19-7F95-4B50-9622-5AE943D34701 2026-08-21T18:50:30.837 QuickScan:ScanID:A5FF4E19-7F95-4B50-9622-5AE943D34701: Scan was stopped 2026-08-21T18:50:30.837 HandleOnDemandStatusChange: Scan Cancelled, pActiveScan->hScanCancelEvent signaled for ScanID:A5FF4E19-7F95-4B50-9622-5AE943D34701 2026-08-21T18:50:30.837 QuickScan:ScanID:A5FF4E19-7F95-4B50-9622-5AE943D34701: Quick scan aborted by callback after end stage 2026-08-21T18:50:30.837 HandleOnDemandStatusChange: Scan Cancelled, pActiveScan->hScanCancelEvent signaled for ScanID:A5FF4E19-7F95-4B50-9622-5AE943D34701 2026-08-21T18:50:30.838 OnDemandScanWorker: Scan Cancelled! scanId:A5FF4E19-7F95-4B50-9622-5AE943D34701, hr = 0x80508018 2026-08-21T18:50:34.493 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:34.510 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:34.513 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:50:34.516 [RTP] [Mini-filter] Blocked file(#88): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65093, FileId: 0x9000000006992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:50:34.540 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:34.564 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{FA4BB239-C9A7-4FE3-A862-8AD3C83825BC} Scan Source:3 Start Time:08-21-2026 18:50:34 End Time:08-21-2026 18:50:34 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:50:34.575 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:34.577 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:34.582 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:34.585 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:50:34.585 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4929 milliseconds. 1 detections to be cleaned. 2026-08-21T18:50:39.518 [RoutineClean] Cleaning 1 detections 2026-08-21T18:50:39.538 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:39.554 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:39.560 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{B8B2B6DA-F3B7-46D8-93DA-4D48A5639982} Scan Source:6 Start Time:08-21-2026 18:50:39 End Time:08-21-2026 18:50:39 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:50:39.565 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:39.566 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:39.568 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:39.689 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:39.707 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:41.576 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:41.586 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:50:41.588 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:42.922 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:42.940 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:42.943 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:50:42.948 [RTP] [Mini-filter] Blocked file(#89): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0x0, State: 16, ScanRequest #65174, FileId: 0x9000000006992, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:50:43.052 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:43.092 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{1EA2EB88-08CD-43FC-8F28-F8147DF05744} Scan Source:3 Start Time:08-21-2026 18:50:42 End Time:08-21-2026 18:50:43 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:50:43.097 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:43.100 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:43.109 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:43.113 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:50:47.350 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:47.367 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:47.377 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:47.378 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x563e566b7ffffffe Begin Resource Scan Scan ID:{D128A8B9-DD5E-4ADC-B079-D490FA3E56FC} Scan Source:10 Start Time:08-21-2026 18:50:47 End Time:08-21-2026 18:50:47 Explicit resource to scan Resource Schema:samplefileremediationcheckpoint Resource Path:B9A6C613F12ABBD0518DEA5D22EFA654 Result Count:2 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 Unknown File Identifier:6214499555526836222 Number of Resources:1 Resource Schema:samplefileremediationcheckpoint Resource Path:B9A6C613F12ABBD0518DEA5D22EFA654 Extended Info - SigSeq:0000000000000000 Extended Info - SigSha:da39a3ee5e6b4b0d3255bfef95601890afd80709 End Scan ************************************************************ 2026-08-21T18:50:47.392 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T18:50:47.396 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x563e566b7ffffffe 2026-08-21T18:50:47.399 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x563e566b7ffffffe 2026-08-21T18:50:47.412 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T18:50:47.412 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:50:47.412 [Cloud] Queued cloud request. 2026-08-21T18:50:47.412 [Cloud] Dequeued cloud request. 2026-08-21T18:50:47.437 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:50:47.479 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:50:47.479 [Cloud] End of cloud request. 2026-08-21T18:50:48.000 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:50:55.698 QuickScan:ScanID:F4801C91-3386-4543-9C20-0F68E39350A7: Quick scan finished with error 0 2026-08-21T18:50:55.703 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{F4801C91-3386-4543-9C20-0F68E39350A7} Scan Source:6 Start Time:08-21-2026 18:50:39 End Time:08-21-2026 18:50:55 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T18:50:55.819 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:50:55.842 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:50:55.846 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:55.855 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T18:50:55.856 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:50:55.856 [Cloud] Queued cloud request. 2026-08-21T18:50:55.856 [Cloud] Dequeued cloud request. 2026-08-21T18:50:55.877 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:55.887 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:55.898 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Beginning threat actions Start time:08-21-2026 18:50:55 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 18:50:55 Result:0 2026-08-21T18:50:55.899 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:50:55.899 [RoutineClean] Routine cleaning timer rescheduled to fire in 0 milliseconds. 2 detections remaining to be cleaned. 2026-08-21T18:50:55.912 [RoutineClean] Cleaning 1 detections 2026-08-21T18:50:56.028 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:50:56.028 [Cloud] End of cloud request. 2026-08-21T18:50:56.195 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:56.197 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:50:56.372 [Cloud] SubmitReport(CMpSpyNetReportContext - clean error) 2026-08-21T18:50:56.372 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:50:56.372 [Cloud] Queued cloud request. 2026-08-21T18:50:56.372 [Cloud] Dequeued cloud request. 2026-08-21T18:50:56.373 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:50:56.375 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0x80508032 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:50:56.376 [Remediation] Threat file already quarantined. Marking remediation as success. 2026-08-21T18:50:56.425 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:50:56.426 [RoutineClean] Routine cleaning timer rescheduled to fire in 4359 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:50:56.438 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:50:56.439 [Cloud] End of cloud request. 2026-08-21T18:50:56.556 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:50:57.917 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:57.927 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:50:57.928 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:59.936 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:50:59.946 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:50:59.948 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:00.791 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:51:01.969 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:01.980 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:01.982 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:02.860 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:02.877 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:02.880 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:51:02.883 [RTP] [Mini-filter] Blocked file(#90): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65267, FileId: 0xa000000006992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:51:02.905 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:02.923 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{F1084CA5-5FD5-42EC-A7B7-FEE97F9847AD} Scan Source:3 Start Time:08-21-2026 18:51:02 End Time:08-21-2026 18:51:02 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:02.928 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:02.932 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:02.938 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:02.942 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:51:02.942 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4939 milliseconds. 1 detections to be cleaned. 2026-08-21T18:51:07.895 [RoutineClean] Cleaning 1 detections 2026-08-21T18:51:07.915 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:07.933 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:07.939 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{35BE185B-7C74-43C0-AEDD-F1AE4A7B20CB} Scan Source:6 Start Time:08-21-2026 18:51:07 End Time:08-21-2026 18:51:07 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:07.945 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:07.946 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:07.947 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:08.060 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:08.080 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:09.084 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:09.100 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:09.102 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:51:09.105 [RTP] [Mini-filter] Blocked file(#91): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65282, FileId: 0xa000000006992, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:51:09.125 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:09.146 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{0896287D-CE5A-4231-BD8B-E5DEC9BCBC0D} Scan Source:3 Start Time:08-21-2026 18:51:09 End Time:08-21-2026 18:51:09 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:09.151 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:09.152 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:09.160 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:09.163 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:51:09.956 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:09.964 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:09.966 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:14.856 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\Mup\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:14.878 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:14.882 [RTP] [MpRtp] Engine VFZ block: \Device\Mup\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:51:14.888 [RTP] [Mini-filter] Blocked file(#92): \Device\Mup\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65316, FileId: 0xa000000006992, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x100081, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x901, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:51:14.931 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:14.956 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{BC3BDB25-C91D-4A9C-BE83-D3D2094FF78C} Scan Source:3 Start Time:08-21-2026 18:51:14 End Time:08-21-2026 18:51:14 Explicit resource to scan Resource Schema:file Resource Path:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:14.963 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:14.964 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:14.968 DETECTION_MERGE#2 Trojan:Win32/Kepavll!rfn file:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:51:14.970 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php;file:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:24.004 QuickScan:ScanID:628F8904-DDCE-4ED0-862A-596AE483E154: Quick scan finished with error 0 2026-08-21T18:51:24.009 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{628F8904-DDCE-4ED0-862A-596AE483E154} Scan Source:6 Start Time:08-21-2026 18:51:08 End Time:08-21-2026 18:51:24 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T18:51:24.110 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:24.131 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:24.135 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:24.141 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T18:51:24.141 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:51:24.141 [Cloud] Queued cloud request. 2026-08-21T18:51:24.141 [Cloud] Dequeued cloud request. 2026-08-21T18:51:24.143 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:24.146 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php;file:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; Beginning threat actions Start time:08-21-2026 18:51:24 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 18:51:24 Result:0 2026-08-21T18:51:24.156 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:51:24.156 [RoutineClean] Routine cleaning timer rescheduled to fire in 0 milliseconds. 2 detections remaining to be cleaned. 2026-08-21T18:51:24.166 [RoutineClean] Cleaning 1 detections 2026-08-21T18:51:24.178 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:51:24.335 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:51:24.335 [Cloud] End of cloud request. 2026-08-21T18:51:24.429 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:24.431 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:24.638 [Cloud] SubmitReport(CMpSpyNetReportContext - clean error) 2026-08-21T18:51:24.638 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:51:24.638 [Cloud] Queued cloud request. 2026-08-21T18:51:24.638 [Cloud] Dequeued cloud request. 2026-08-21T18:51:24.639 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:51:24.671 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0x80508032 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php;file:\\localhost\D$\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:24.672 [Remediation] Threat file already quarantined. Marking remediation as success. 2026-08-21T18:51:24.683 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:51:24.683 [RoutineClean] Routine cleaning timer rescheduled to fire in 4395 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:51:24.699 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:51:24.700 [Cloud] End of cloud request. 2026-08-21T18:51:24.917 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:51:26.170 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:26.182 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:26.184 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:28.192 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:28.204 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:28.205 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:29.091 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:51:30.217 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:30.226 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:30.228 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:33.763 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:33.780 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:33.782 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:51:33.786 [RTP] [Mini-filter] Blocked file(#93): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65379, FileId: 0xb000000006992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:51:33.807 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:33.825 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{C6B2EE16-117F-44C9-A481-D456CC2CA5B9} Scan Source:3 Start Time:08-21-2026 18:51:33 End Time:08-21-2026 18:51:33 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:33.835 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:33.836 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:33.841 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:33.845 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:51:33.845 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4938 milliseconds. 1 detections to be cleaned. 2026-08-21T18:51:38.788 [RoutineClean] Cleaning 1 detections 2026-08-21T18:51:38.810 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:38.829 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:38.834 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{E15209DC-970D-4C30-A404-5271F3221B08} Scan Source:6 Start Time:08-21-2026 18:51:38 End Time:08-21-2026 18:51:38 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:38.839 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:38.840 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:38.841 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:38.863 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:38.880 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:40.861 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:40.868 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:40.870 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:48.866 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:48.885 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:48.888 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:51:48.893 [RTP] [Mini-filter] Blocked file(#94): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Program Files\Notepad++\notepad++.exe, Status: 0x0, State: 16, ScanRequest #65424, FileId: 0xb000000006992, Reason: OnOpen, IoStatusBlockForNewFile: 0xffffffff, DesiredAccess:0x120089, FileAttributes:0x20, ScanAttributes:0x0, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:51:48.919 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:48.987 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{B9D103A7-4D14-44AB-8D9E-1F70DD8AF514} Scan Source:3 Start Time:08-21-2026 18:51:48 End Time:08-21-2026 18:51:48 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:51:48.994 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:48.996 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:49.013 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:49.018 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:51:54.163 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:54.179 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:54.191 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:54.192 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9ebbc92a7ffffffe Begin Resource Scan Scan ID:{B8A9F9FD-73DE-4BDE-97D1-09E77E08E143} Scan Source:10 Start Time:08-21-2026 18:51:54 End Time:08-21-2026 18:51:54 Explicit resource to scan Resource Schema:samplefileremediationcheckpoint Resource Path:5366A0EBCA9BD452FFE88A3132801B4E Result Count:2 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 Unknown File Identifier:11437956863010799614 Number of Resources:1 Resource Schema:samplefileremediationcheckpoint Resource Path:5366A0EBCA9BD452FFE88A3132801B4E Extended Info - SigSeq:0000000000000000 Extended Info - SigSha:da39a3ee5e6b4b0d3255bfef95601890afd80709 End Scan ************************************************************ 2026-08-21T18:51:54.205 UnknownTelemetryScan triggered, type: 1 (1 - Unknown, 2- Lofi), flags: 0 (0 - Regular, 1 - MemScan), 1 resources, RtpIoavOnly: FALSE 2026-08-21T18:51:54.209 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9ebbc92a7ffffffe 2026-08-21T18:51:54.212 Using signature default action MP_THREAT_ACTION_ALLOW(6) for special threatID: 0x9ebbc92a7ffffffe 2026-08-21T18:51:54.224 [Cloud] SubmitReport(CMpUnknownSpyNetReportContext) 2026-08-21T18:51:54.224 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:51:54.224 [Cloud] Queued cloud request. 2026-08-21T18:51:54.224 [Cloud] Dequeued cloud request. 2026-08-21T18:51:54.255 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:51:54.296 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:51:54.296 [Cloud] End of cloud request. 2026-08-21T18:51:54.819 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:51:55.904 QuickScan:ScanID:54C1A1F7-82BA-4B2F-A8C0-72BFD280602C: Quick scan finished with error 0 2026-08-21T18:51:55.909 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{54C1A1F7-82BA-4B2F-A8C0-72BFD280602C} Scan Source:6 Start Time:08-21-2026 18:51:38 End Time:08-21-2026 18:51:55 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ FileName:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php SHA1:822713aa20db9cf9577a00d7e5387f43d28377d2 2026-08-21T18:51:56.003 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:51:56.019 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:51:56.023 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:56.029 [Cloud] SubmitReport(CMpSpyNetReportContext - post clean) 2026-08-21T18:51:56.029 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:51:56.029 [Cloud] Queued cloud request. 2026-08-21T18:51:56.029 [Cloud] Dequeued cloud request. 2026-08-21T18:51:56.031 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:56.032 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; Beginning threat actions Start time:08-21-2026 18:51:55 Threat Name:Trojan:Win32/Kepavll!rfn Threat ID:2147939874 Action:quarantine Resource action complete:Quarantine Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 File to act on SHA1:822713AA20DB9CF9577A00D7E5387F43D28377D2 File owner:PC1LAN\ITHAN File cleaned/removed successfully File Name:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Action remove successful on file:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Resource action complete:Removal Schema:file Path:\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Threat ID:2147939874 Resource refcount:1 Result:0 Finished threat ID:2147939874 Threat result:0 Threat status flags:0 Threat Effective RemovalPolicy:128 Finished threat actions End time:08-21-2026 18:51:56 Result:0 2026-08-21T18:51:56.038 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:51:56.038 [RoutineClean] Routine cleaning timer rescheduled to fire in 0 milliseconds. 2 detections remaining to be cleaned. 2026-08-21T18:51:56.050 [RoutineClean] Cleaning 1 detections 2026-08-21T18:51:56.093 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:51:56.221 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:51:56.225 [Cloud] End of cloud request. 2026-08-21T18:51:56.253 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:56.255 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:51:56.358 [Cloud] SubmitReport(CMpSpyNetReportContext - clean error) 2026-08-21T18:51:56.358 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:51:56.358 [Cloud] Queued cloud request. 2026-08-21T18:51:56.358 [Cloud] Dequeued cloud request. 2026-08-21T18:51:56.359 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:51:56.360 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0x80508032 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:51:56.360 [Remediation] Threat file already quarantined. Marking remediation as success. 2026-08-21T18:51:56.364 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:51:56.364 [RoutineClean] Routine cleaning timer rescheduled to fire in 4611 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:51:56.411 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:51:56.411 [Cloud] End of cloud request. 2026-08-21T18:51:56.749 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:51:58.052 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:51:58.060 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:51:58.063 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:00.073 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:00.082 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:52:00.083 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:00.984 [RoutineClean] Threat status changed to 0x8 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:52:02.101 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:02.108 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:52:02.110 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:16.247 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:52:16.265 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:52:16.267 [RTP] [MpRtp] Engine VFZ block: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x8070022, statusex=0x200002, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:52:16.271 [RTP] [Mini-filter] Blocked file(#95): \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. Process: \Device\HarddiskVolume3\Windows\explorer.exe, Status: 0x0, State: 16, ScanRequest #65548, FileId: 0xc000000006992, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T18:52:16.293 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:52:16.316 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) Begin Resource Scan Scan ID:{86A99EE8-F57F-482C-B141-EBF64CADCBBF} Scan Source:3 Start Time:08-21-2026 18:52:16 End Time:08-21-2026 18:52:16 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:52:16.320 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:52:16.322 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:52:16.327 DETECTIONEVENT MPSOURCE_REALTIME Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; 2026-08-21T18:52:16.331 DETECTION_ADD#1 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php PropBag [length: 0, data: (null)] 2026-08-21T18:52:16.331 [RoutineClean] New detection added. Routine cleaning timer scheduled to fire in 4937 milliseconds. 1 detections to be cleaned. 2026-08-21T18:52:21.278 [RoutineClean] Cleaning 1 detections 2026-08-21T18:52:21.299 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:52:21.314 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:52:21.320 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 Begin Resource Scan Scan ID:{12F27A71-0828-4711-9CF0-51203D276806} Scan Source:6 Start Time:08-21-2026 18:52:21 End Time:08-21-2026 18:52:21 Explicit resource to scan Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Result Count:1 Threat Name:Trojan:Win32/Kepavll!rfn ID:2147939874 Severity:5 Number of Resources:1 Resource Schema:file Resource Path:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php Extended Info - SigSeq:000026677737a11f Extended Info - SigSha:28040126fff08e5e87c3e9b1ba3eb080e7df1d54 End Scan ************************************************************ 2026-08-21T18:52:21.325 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:52:21.327 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:52:21.328 Using SDA action MP_THREAT_ACTION_QUARANTINE(2), since failed to get action from PDA/UDA for threat (id - 0x8006f622, sev - 5, category - 8). hr = 0x80070002 2026-08-21T18:52:21.452 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\\?\D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) 2026-08-21T18:52:21.474 FP supression checks:CheckTrusted=true (Sigseq=0x26677737a11f), CheckLimit=true, IsNotRevokedCertSig=true, IsNotFpCheckDisabledSig=true, IsSignedFileCheck=false, IsNotExcludedCertificate=true (FriendlySigSeq=0x0) 2026-08-21T18:52:23.351 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:23.363 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:52:23.364 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:26.723 Job Notification: New process added to job (11620) 2026-08-21T18:52:26.730 Task(GetDeviceTicket -AccessKey 30D3C487-09C2-13FB-BD33-6E3BF1CC2DAF ) launched as network service 2026-08-21T18:52:26.774 Job Notification: Process exited from job (11620) 2026-08-21T18:52:26.958 [Cloud] SubmitReport(CMpHeartbeatSpyNetReportContext - Force), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:52:26.958 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:52:26.958 [Cloud] Queued cloud request. 2026-08-21T18:52:26.959 [Cloud] Dequeued cloud request. 2026-08-21T18:52:26.960 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:52:27.025 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T18:52:27.025 [Cloud] End of cloud request. 2026-08-21T18:52:27.030 [RTP] [RtpConfig] Config change detected, type: 16 2026-08-21T18:52:27.032 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:52:27.903 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:27.914 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:52:27.917 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:29.561 [RTP] Duplicating the current plugin configuration object... 2026-08-21T18:52:29.561 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T18:52:29.561 [RTP] Updating plugin configuration due to recent config changes (0x10) ... 2026-08-21T18:52:29.573 [RTP] Calling GenerateEngineConfigStruct (0x10) ... 2026-08-21T18:52:29.574 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x10, Changed: 0x210 2026-08-21T18:52:37.623 QuickScan:ScanID:BDA32006-9964-44F6-AA16-2410A887CAD1: Quick scan finished with error 0 2026-08-21T18:52:37.641 DETECTION_CLEANEVENT MPSOURCE_REALTIME MP_THREAT_ACTION_QUARANTINE 0x80508023 Trojan:Win32/Kepavll!rfn file:D:\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php; Beginning threat actions Start time:08-21-2026 18:52:37 Finished threat actions End time:08-21-2026 18:52:37 Result:0 2026-08-21T18:52:37.649 [RoutineClean] Routine cleaning completed successfully on 1 detections. 2026-08-21T18:52:37.649 [RoutineClean] Routine cleaning timer rescheduled to fire in 0 milliseconds. 1 detections remaining to be cleaned. 2026-08-21T18:52:37.666 [RoutineClean] Threat status changed to 0x4000 (threatId: 8006f622). Skipping automatic remediation. 2026-08-21T18:52:39.661 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:39.673 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T18:52:39.674 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T18:52:40.463 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) Internal signature match:subtype=Lowfi, sigseq=0x000063E78EA4A718, sigsha=a690228b9916a65ec33ca9267d5d8e67bb239426, cached=false, source=2, resourceid=0x11f9c72b 2026-08-21T18:52:40.535 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T18:52:40.535 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T18:52:40.535 [Cloud] Queued cloud request. 2026-08-21T18:52:40.535 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T18:52:40.535 [Cloud] Dequeued cloud request. 2026-08-21T18:52:40.535 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T18:52:40.926 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c13ac634a02e924f2e3501448fbd2c6a0f73bf48 Dynamic Signature Compilation Timestamp:08-21-2026 18:52:40 Persistence Type:Duration Time remaining:864000000 2026-08-21T18:52:40.927 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T18:52:40.927 [Cloud] End of cloud request. 2026-08-21T18:52:40.941 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php) Internal signature match:subtype=Lowfi, sigseq=0x00000070DE3CA1F0, sigsha=da39a3ee5e6b4b0d3255bfef95601890afd80709, cached=false, source=2, resourceid=0x11f9c72b 2026-08-21T18:52:40.973 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpfm-master\index.php. status=0x40070000, statusex=0x210, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T18:52:41.452 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T18:54:13.773 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 848576, Count: 45582, MaxTime: 5015, MaxTimeFile: \Device\HarddiskVolume3\Windows\Installer\d6f94.msp, EstimatedImpact: 3% 2026-08-21T18:54:13.773 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 33168, Count: 893, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T18:54:13.773 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T18:54:13.773 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T18:54:13.773 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T18:54:13.773 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 2805, Count: 85, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: mysqld.exe, Pid: 240, TotalTime: 2613, Count: 26, MaxTime: 2296, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T18:54:13.773 ProcessImageName: splwow64.exe, Pid: 2044, TotalTime: 2346, Count: 157, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Microsoft\OPC\DDT.a8fehgpc8xglbng52y50urltg.tmp, EstimatedImpact: 4% 2026-08-21T18:54:13.773 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: notepad++.exe, Pid: 6108, TotalTime: 1797, Count: 85, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 5% 2026-08-21T18:54:13.773 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T18:54:13.773 ProcessImageName: notepad++.exe, Pid: 7212, TotalTime: 1293, Count: 61, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: notepad++.exe, Pid: 7820, TotalTime: 1267, Count: 55, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 10% 2026-08-21T18:54:13.773 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: notepad++.exe, Pid: 10968, TotalTime: 1207, Count: 62, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: taskhostw.exe, Pid: 8332, TotalTime: 1093, Count: 2, MaxTime: 1062, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T18:54:13.773 ProcessImageName: PDFXCview.exe, Pid: 9408, TotalTime: 886, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\SearchProviders\Ask.xml, EstimatedImpact: 53% 2026-08-21T18:54:13.773 ProcessImageName: webalizer.exe, Pid: 11200, TotalTime: 844, Count: 66, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\webalizer\hourly_usage_202403.png, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 780, Count: 4, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: perl.exe, Pid: 4816, TotalTime: 779, Count: 4, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T18:54:13.773 ProcessImageName: firefox.exe, Pid: 7256, TotalTime: 631, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13488, EstimatedImpact: 46% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 601, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: perl.exe, Pid: 7836, TotalTime: 576, Count: 4, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: perl.exe, Pid: 10940, TotalTime: 560, Count: 5, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\libstdc++-6.dll, EstimatedImpact: 100% 2026-08-21T18:54:13.773 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T18:54:13.773 ProcessImageName: firefox.exe, Pid: 5356, TotalTime: 451, Count: 39, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa00952, EstimatedImpact: 56% 2026-08-21T18:54:13.773 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 439, Count: 36, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T18:54:13.773 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T18:54:13.773 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T18:54:13.773 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 366, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T18:54:13.773 ProcessImageName: backgroundTaskHost.exe, Pid: 14184, TotalTime: 330, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787324264, EstimatedImpact: 7% 2026-08-21T18:54:13.773 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 316, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: webalizer.exe, Pid: 10172, TotalTime: 287, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\logs\access.log, EstimatedImpact: 17% 2026-08-21T18:54:13.773 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 285, Count: 31, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 2524, TotalTime: 278, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-08-21T18:54:13.773 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 233, Count: 2, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOADF9.tmp, EstimatedImpact: 45% 2026-08-21T18:54:13.773 ProcessImageName: dasHost.exe, Pid: 5204, TotalTime: 212, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: TabTip.exe, Pid: 764, TotalTime: 202, Count: 5, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 98% 2026-08-21T18:54:13.774 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 201, Count: 6, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 196, Count: 17, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T18:54:13.774 ProcessImageName: SDXHelper.exe, Pid: 8808, TotalTime: 181, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 19% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 2940, TotalTime: 170, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer_Service.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T18:54:13.774 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T18:54:13.774 ProcessImageName: dllhost.exe, Pid: 5860, TotalTime: 165, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: SDXHelper.exe, Pid: 7792, TotalTime: 151, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 15% 2026-08-21T18:54:13.774 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T18:54:13.774 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 13892, TotalTime: 137, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 576, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 122, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T18:54:13.774 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T18:54:13.774 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T18:54:13.774 ProcessImageName: dllhost.exe, Pid: 13152, TotalTime: 108, Count: 2, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\contextMenu\NppShell.dll, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: sihost.exe, Pid: 6532, TotalTime: 106, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T18:54:13.774 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 90, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T18:54:13.774 ProcessImageName: notepad++.exe, Pid: 4932, TotalTime: 77, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 3% 2026-08-21T18:54:13.774 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T18:54:13.774 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T18:54:13.774 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T18:54:13.774 ProcessImageName: cmd.exe, Pid: 7796, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp_7.4.1_mit_Programme\xampp\webalizer\webalizer.exe, EstimatedImpact: 55% 2026-08-21T18:54:13.774 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T18:54:13.774 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T18:54:13.774 ProcessImageName: cmd.exe, Pid: 7712, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\webalizer\webalizer.exe, EstimatedImpact: 42% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T18:54:13.774 ProcessImageName: spoolsv.exe, Pid: 3664, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\index.php, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T18:54:13.774 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{91E0771E-FE09-4F47-9C4D-D3E82FEED848}.json, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T18:54:13.774 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 5760, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1745.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 11096, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1743.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T18:54:13.774 ProcessImageName: backgroundTaskHost.exe, Pid: 4016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1787302503->(UTF-16LE), EstimatedImpact: 28% 2026-08-21T18:54:13.774 ProcessImageName: backgroundTaskHost.exe, Pid: 12536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1787317000, EstimatedImpact: 29% 2026-08-21T18:54:13.774 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 7584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1404.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 10748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1344.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 5068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1739.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 12636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1442.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T18:54:13.774 ProcessImageName: backgroundTaskHost.exe, Pid: 4920, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787320631, EstimatedImpact: 1% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 2848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1508.log->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 2312, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1358.log, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1322.log, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: OfficeC2RClient.exe, Pid: 6564, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1516.log, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: StoreDesktopExtension.exe, Pid: 11960, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 9% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 1204, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: SecHealthUI.exe, Pid: 7200, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SecHealthUI_1000.29628.1000.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T18:54:13.774 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T19:01:33.012 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x6ce8411f Internal signature match:subtype=Lowfi, sigseq=0x0000055537F26056, sigsha=c9ab73d1bf881a82f9c1e4548bb90c94d18a6222, cached=false, source=5, resourceid=0x957e9797 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcfe013b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbde0966d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x002f32c3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9d20d3b5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6d0afce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x47bd562a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3775e98d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc88d2ebd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0773e94c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe578f716 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053b9c6d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5af8ee84 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7e779722 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xedf5605b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9f068db 2026-08-21T19:09:08.945 Bm signature throttled:0x00002db31bed458f 2026-08-21T19:13:05.934 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\phpfm-master\phpfm-master\index.php) Internal signature match:subtype=Lowfi, sigseq=0x000063E78EA4A718, sigsha=a690228b9916a65ec33ca9267d5d8e67bb239426, cached=false, source=5, resourceid=0xdc9376e8 2026-08-21T19:13:05.999 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:13:05.999 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:13:05.999 [Cloud] Queued cloud request. 2026-08-21T19:13:05.999 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:13:05.999 [Cloud] Dequeued cloud request. 2026-08-21T19:13:05.999 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:13:06.527 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7aa139a16f9b3cdd02783117288f99c3257e94b3 Dynamic Signature Compilation Timestamp:08-21-2026 19:13:06 Persistence Type:Duration Time remaining:864000000 2026-08-21T19:13:06.529 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:13:06.529 [Cloud] End of cloud request. 2026-08-21T19:13:06.543 Matched bloom filter (standard) (setting MpCloudToVDMBloomFilterSlow) (\Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\phpfm-master\phpfm-master\index.php) Internal signature match:subtype=Lowfi, sigseq=0x00000070DE3CA1F0, sigsha=da39a3ee5e6b4b0d3255bfef95601890afd80709, cached=false, source=5, resourceid=0xdc9376e8 2026-08-21T19:13:06.575 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\phpFileManager-1.8.0\phpfm-master\phpfm-master\index.php. status=0x40070000, statusex=0x210, threatid=0x8006f622, sigseq=0x26677737a11f 2026-08-21T19:13:07.080 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T19:14:46.161 Bm signature throttled:0x000135b39c9104ce BEGIN BM telemetry GUID:{DFC22823-C779-D277-BCCB-BCB8053D7E8C} SignatureID:241562583045193 SigSha:7145aabc8ddde0009e71af5be973eaa5802da41a ThreatLevel:0 ProcessID:2004 ProcessCreationTime:134317859382025316 SessionID:1 CreationTime:08-21-2026 19:14:46 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: ; Parents: Operations:None END BM telemetry 2026-08-21T19:14:46.834 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:14:46.834 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:14:46.834 [Cloud] Queued cloud request. 2026-08-21T19:14:46.834 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:14:46.834 [Cloud] Dequeued cloud request. 2026-08-21T19:14:46.834 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:14:46.846 [Cloud] SubmitReport(CMpBmSpyNetReportContext) 2026-08-21T19:14:46.846 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:14:46.846 [Cloud] Queued cloud request. 2026-08-21T19:14:46.846 [Cloud] Dequeued cloud request. 2026-08-21T19:14:46.847 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:14:47.029 [Cloud] MpEngineParseSpyNetResponse(). hr = 0 2026-08-21T19:14:47.029 [Cloud] End of cloud request. 2026-08-21T19:14:47.119 [Cloud] End of cloud request. 2026-08-21T19:14:47.541 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T19:16:37.957 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe36ef87a 2026-08-21T19:18:12.114 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:18:12.114 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:18:12.114 [Cloud] Queued cloud request. 2026-08-21T19:18:12.114 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:18:12.115 [Cloud] Dequeued cloud request. 2026-08-21T19:18:12.115 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:18:12.576 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\22d07aeb26a7f09d901bca00b46e8ff2152aa9d4 Dynamic Signature Compilation Timestamp:08-21-2026 19:18:12 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:18:12.577 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:18:12.577 [Cloud] End of cloud request. 2026-08-21T19:18:13.098 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1823cda7 2026-08-21T19:18:36.010 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:18:36.010 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:18:36.010 [Cloud] Queued cloud request. 2026-08-21T19:18:36.010 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:18:36.010 [Cloud] Dequeued cloud request. 2026-08-21T19:18:36.011 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0add7ec42b3bad34ff0f41912a41a514f33f2187 Dynamic Signature Compilation Timestamp:08-21-2026 19:18:36 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:18:36.217 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:18:36.218 Dynamic signature received 2026-08-21T19:18:36.218 [Cloud] End of cloud request. 2026-08-21T19:18:36.737 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24992611 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5579db6b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42357c3b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x50b6cf2f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x411338da 2026-08-21T19:20:17.267 Engine:Setting original file name "schtasks.exe" for "h:\windows\system32\schtasks.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xaf487ff1 2026-08-21T19:21:44.954 Engine:Setting original file name "register-cimprovider2.exe" for "h:\windows\system32\register-cimprovider.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7f33e982 2026-08-21T19:22:12.422 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:22:12.423 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:22:12.423 [Cloud] Queued cloud request. 2026-08-21T19:22:12.423 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:22:12.423 [Cloud] Dequeued cloud request. 2026-08-21T19:22:12.423 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:22:12.752 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e50b6aaabf2c00ba18a1a6a97b73774c4e6ff985 Dynamic Signature Compilation Timestamp:08-21-2026 19:22:12 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:22:12.754 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:22:12.755 [Cloud] End of cloud request. 2026-08-21T19:22:13.280 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcb8c505f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4800f287 Internal signature match:subtype=Lowfi, sigseq=0x0000108044F76FB4, sigsha=6a849c9023e5e1ca98e7bb1282e756480f21b470, cached=false, source=2, resourceid=0xc9dd708d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4b6c659b Internal signature match:subtype=Lowfi, sigseq=0x0000157EF4F29ECD, sigsha=e385418083636e38e3395b7b4151db4f804a3577, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E2A478FED, sigsha=8f1ac833a6d48b1eb10ea1c7ec417818567d97a3, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E7FEDC0D5, sigsha=6376cbc7081c62e2b97652c1dd600ccb2e30b834, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E524AFD67, sigsha=74c52e012de48efe9cdfdc6ec776ad63b9e6f4c0, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E37BA5E79, sigsha=663761914a70b779b4d1684cbd87ac31b8665c73, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157EF8F8AFD0, sigsha=b3b1e404201787d14162fcecef21d50526559a19, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E373393FA, sigsha=a9d4ef83efe937cf7cedf02c2c9201186a7fd736, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E2F0F771F, sigsha=50c805bff96bed713a2faddfd5c7ae78e04c6e13, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E90D773D3, sigsha=bb3c78dbcbabc29b108ec0b81b3712b5bd810e62, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E204B19D4, sigsha=1a72eabe9d48022fa12b36c80c171c53808321a8, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157EEA895CFB, sigsha=b35603eb864b7030f5b5bcec5b7182aefa671f43, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x0000157E0F5F5A8E, sigsha=7f0fe713d9813ef8e48dd930d3961e29e641cff3, cached=false, source=2, resourceid=0x1161712a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdd2b2cb8 2026-08-21T19:24:51.043 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:24:51.043 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:24:51.043 [Cloud] Queued cloud request. 2026-08-21T19:24:51.043 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:24:51.043 [Cloud] Dequeued cloud request. 2026-08-21T19:24:51.043 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:24:51.514 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2ec8be288a3008d19893f3a8d34b47e59981d222 Dynamic Signature Compilation Timestamp:08-21-2026 19:24:51 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:24:51.516 [Cloud] End of cloud request. 2026-08-21T19:24:51.516 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:24:52.035 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcd316bb8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0948da9e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2304add2 2026-08-21T19:25:30.932 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:25:30.933 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:25:30.933 [Cloud] Queued cloud request. 2026-08-21T19:25:30.933 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:25:30.933 [Cloud] Dequeued cloud request. 2026-08-21T19:25:30.933 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:25:31.281 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\5fb1a4af6c6afb92d02c52e3e93ab402c1c52a50 Dynamic Signature Compilation Timestamp:08-21-2026 19:25:31 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:25:31.283 [Cloud] End of cloud request. 2026-08-21T19:25:31.283 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:25:31.807 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x55245430 2026-08-21T19:25:34.205 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:25:34.205 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:25:34.205 [Cloud] Queued cloud request. 2026-08-21T19:25:34.205 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:25:34.206 [Cloud] Dequeued cloud request. 2026-08-21T19:25:34.206 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:25:34.402 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c33e454bad7dac09cccdad70470819e6274c4e46 Dynamic Signature Compilation Timestamp:08-21-2026 19:25:34 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:25:34.403 [Cloud] End of cloud request. 2026-08-21T19:25:34.403 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:25:34.913 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T19:25:35.970 Engine:Setting original file name "rundll32.exe" for "h:\windows\system32\rundll32.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9606fc04 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x9606fc04 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7a0acbf6 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x692fe0d9 2026-08-21T19:25:45.473 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:25:45.473 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:25:45.473 [Cloud] Queued cloud request. 2026-08-21T19:25:45.473 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:25:45.473 [Cloud] Dequeued cloud request. 2026-08-21T19:25:45.473 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:25:45.667 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b938e0845e38da27e1886b897414e7585eea1b83 Dynamic Signature Compilation Timestamp:08-21-2026 19:25:45 Persistence Type:Duration Time remaining:150196224 2026-08-21T19:25:45.668 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:25:45.669 [Cloud] End of cloud request. 2026-08-21T19:25:46.180 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3be80d0c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9b3fe0f1 2026-08-21T19:27:00.548 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:27:00.548 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:27:00.548 [Cloud] Queued cloud request. 2026-08-21T19:27:00.548 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:27:00.548 [Cloud] Dequeued cloud request. 2026-08-21T19:27:00.548 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:27:00.886 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\51036205a124ded24ebae9418ae7def01b81f891 Dynamic Signature Compilation Timestamp:08-21-2026 19:27:00 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:27:00.887 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:27:00.888 [Cloud] End of cloud request. 2026-08-21T19:27:01.409 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb8f61125 2026-08-21T19:27:21.397 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Windows\Installer\7443e.msp` is 5390 units Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52f7ba36 2026-08-21T19:27:30.248 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:27:30.248 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:27:30.248 [Cloud] Queued cloud request. 2026-08-21T19:27:30.248 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:27:30.248 [Cloud] Dequeued cloud request. 2026-08-21T19:27:30.248 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:27:30.464 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e55d6e8793bc1edc33b757e635a1e8a5b8f6597c Dynamic Signature Compilation Timestamp:08-21-2026 19:27:30 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:27:30.466 [Cloud] End of cloud request. 2026-08-21T19:27:30.466 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:27:30.984 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T19:27:53.772 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x27b7e2af Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2507f149 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8613995e 2026-08-21T19:28:53.685 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:28:53.685 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:28:53.685 [Cloud] Queued cloud request. 2026-08-21T19:28:53.685 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:28:53.685 [Cloud] Dequeued cloud request. 2026-08-21T19:28:53.743 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:28:54.184 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\859b1d648b50175a0b0fe26de3d2416bcfa01179 Dynamic Signature Compilation Timestamp:08-21-2026 19:28:54 Persistence Type:Duration Time remaining:150196224 2026-08-21T19:28:54.185 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:28:54.185 [Cloud] End of cloud request. 2026-08-21T19:28:54.710 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x5ca953c5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x89d692cd Internal signature match:subtype=Lowfi, sigseq=0x0000157E63AB3170, sigsha=e38cd0eab571423665adf9aa5888e28cacf8b14e, cached=false, source=2, resourceid=0x89d692cd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfd44d446 2026-08-21T19:28:59.371 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:28:59.371 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:28:59.371 [Cloud] Queued cloud request. 2026-08-21T19:28:59.371 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:28:59.371 [Cloud] Dequeued cloud request. 2026-08-21T19:28:59.372 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\383bcca7489897c4a8779cb8b7c22e9ac6e05988 Dynamic Signature Compilation Timestamp:08-21-2026 19:28:59 Persistence Type:Duration Time remaining:150196224 2026-08-21T19:28:59.678 Dynamic signature received 2026-08-21T19:28:59.680 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:28:59.681 [Cloud] End of cloud request. 2026-08-21T19:29:00.200 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3fc1b099 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6a147d78 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb02c8c8b 2026-08-21T19:29:13.603 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:29:13.603 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:29:13.603 [Cloud] Queued cloud request. 2026-08-21T19:29:13.603 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:29:13.603 [Cloud] Dequeued cloud request. 2026-08-21T19:29:13.604 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a2937309ec388fbaf7f44eecc748ca4cb7c4c4c6 Dynamic Signature Compilation Timestamp:08-21-2026 19:29:13 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:29:14.052 Dynamic signature received 2026-08-21T19:29:14.053 [Cloud] End of cloud request. 2026-08-21T19:29:14.053 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:29:14.574 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe967b1ad 2026-08-21T19:29:27.919 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:29:27.919 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:29:27.919 [Cloud] Queued cloud request. 2026-08-21T19:29:27.919 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:29:27.919 [Cloud] Dequeued cloud request. 2026-08-21T19:29:27.920 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:29:28.145 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a9eb1ac3aec176eed9ea929ab92b0ccc01373779 Dynamic Signature Compilation Timestamp:08-21-2026 19:29:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:29:28.146 [Cloud] End of cloud request. 2026-08-21T19:29:28.146 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:29:28.664 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x21927f1a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1dc7847d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0c4c2f76 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x0c4c2f76 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x91de9eea 2026-08-21T19:31:04.331 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:31:04.331 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:31:04.331 [Cloud] Queued cloud request. 2026-08-21T19:31:04.331 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:31:04.331 [Cloud] Dequeued cloud request. 2026-08-21T19:31:04.331 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\634f51648aa3956ab07d170c0f3fc204fa452fa9 Dynamic Signature Compilation Timestamp:08-21-2026 19:31:04 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:31:04.717 Dynamic signature received 2026-08-21T19:31:04.718 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:31:04.718 [Cloud] End of cloud request. 2026-08-21T19:31:05.238 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x843ef6f3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbe996f79 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8b0c8c85 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x88499b5b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x306e16d7 2026-08-21T19:31:42.917 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xef5c1049 2026-08-21T19:35:14.076 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T19:35:14.076 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T19:35:14.076 [Cloud] Queued cloud request. 2026-08-21T19:35:14.076 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T19:35:14.077 [Cloud] Dequeued cloud request. 2026-08-21T19:35:14.077 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T19:35:14.542 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a3dcfd31d190951662854d8d47eaaa8d5ec5dd19 Dynamic Signature Compilation Timestamp:08-21-2026 19:35:14 Persistence Type:Duration Time remaining:50065408 2026-08-21T19:35:14.543 [Cloud] End of cloud request. 2026-08-21T19:35:14.543 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T19:35:15.058 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcfe013b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbde0966d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x002f32c3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9d20d3b5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6d0afce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x47bd562a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3775e98d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc88d2ebd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0773e94c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe578f716 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053b9c6d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5af8ee84 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7e779722 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xedf5605b 2026-08-21T19:37:43.616 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #84424, FileId: 0x1300000001ab35, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB48F7D31, sigsha=53c1b155d493cbab49a5232b334c9852ed0fefd0, cached=false, source=2, resourceid=0x98fdd352 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x7dd5c81b Internal signature match:subtype=Lowfi, sigseq=0x0000055508F3A39A, sigsha=adc296cf14a948811ec4fc94642d047458c25c9d, cached=false, source=2, resourceid=0x5a74683f 2026-08-21T19:43:24.100 Bm signature throttled:0x00002db31bed458f 2026-08-21T19:46:47.886 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T20:01:52.870 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T20:13:24.959 Bm signature throttled:0x00002db31bed458f 2026-08-21T20:16:57.853 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T20:23:04.004 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb)` is 5343 units 2026-08-21T20:23:19.461 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #103901, FileId: 0x10d000000002e67, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T20:23:22.768 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy2\System Volume Information\SPP\snapshot-2 2026-08-21T20:23:22.768 [RTP] 6 newly mounted volumes accumulated, forcing a config update ... 2026-08-21T20:23:22.768 [RTP] Duplicating the current plugin configuration object... 2026-08-21T20:23:22.768 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T20:23:22.768 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-21T20:23:22.768 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-21T20:23:22.768 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-21T20:23:22.863 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy3\System Volume Information\SPP\snapshot-2 2026-08-21T20:23:36.200 ReportLowfi(c:\programdata\package cache\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}\vc_redist.x64.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:36.204 ReportLowfi(c:\programdata\package cache\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}\vc_redist.x64.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:36.210 ReportLowfi(c:\programdata\package cache\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}\vc_redist.x64.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:36.214 ReportLowfi(c:\programdata\package cache\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}\vc_redist.x64.exe, 0x437a0835) from 0x0006b6bd6566d2d9 Internal signature match:subtype=Lowfi, sigseq=0x000005550240CBF2, sigsha=e39a25e9b19899abbd79ec872fd8aeabe27e140d, cached=false, source=0, resourceid=0x568c01cb 2026-08-21T20:23:36.328 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-08-21T20:23:36.328 [RTP] Duplicating the current plugin configuration object... 2026-08-21T20:23:36.328 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\pagefile.sys 2026-08-21T20:23:36.328 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T20:23:36.328 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-21T20:23:36.328 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-21T20:23:36.328 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-21T20:23:37.213 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolumeShadowCopy4\pagefile.sys 2026-08-21T20:23:40.973 ReportLowfi(c:\programdata\package cache\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}\vc_redist.x86.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:40.976 ReportLowfi(c:\programdata\package cache\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}\vc_redist.x86.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:40.982 ReportLowfi(c:\programdata\package cache\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}\vc_redist.x86.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:23:40.985 ReportLowfi(c:\programdata\package cache\{0e4ccf1b-d073-4cfe-8a24-e86185719b56}\vc_redist.x86.exe, 0x437a0835) from 0x0006b6bd6566d2d9 2026-08-21T20:24:30.242 Bm signature throttled:0x00002db31bed458f 2026-08-21T20:25:53.832 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\integrator.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, Status: 0xc0000001, State: 0, ScanRequest #106951, FileId: 0x330000000349cd, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T20:25:53.890 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, Status: 0xc0000001, State: 0, ScanRequest #106955, FileId: 0x70000000bfb1e, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T20:27:04.652 Bm signature throttled:0x00002db31bed458f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6e0fd71e 2026-08-21T20:28:21.153 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T20:28:21.154 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T20:28:21.154 [Cloud] Queued cloud request. 2026-08-21T20:28:21.154 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T20:28:21.154 [Cloud] Dequeued cloud request. 2026-08-21T20:28:21.154 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\154a930e98e6c503d3959a4a092b4371c5cb7af2 Dynamic Signature Compilation Timestamp:08-21-2026 20:28:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T20:28:21.462 Dynamic signature received 2026-08-21T20:28:21.464 [Cloud] End of cloud request. 2026-08-21T20:28:21.464 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T20:28:21.988 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T20:32:02.847 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T20:39:45.587 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #107588, FileId: 0x19000000036b36, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T20:47:07.827 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T20:50:03.752 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpC861.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #107677, FileId: 0x4c000000036909, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T20:54:13.583 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 1164907, Count: 56722, MaxTime: 5484, MaxTimeFile: \Device\HarddiskVolume3\Windows\Installer\7df89.msp, EstimatedImpact: 3% 2026-08-21T20:54:13.583 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 48669, Count: 1139, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: setup.exe, Pid: 2068, TotalTime: 10605, Count: 417, MaxTime: 4187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.101\msedge.dll, EstimatedImpact: 24% 2026-08-21T20:54:13.583 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T20:54:13.583 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 5907, Count: 166, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: splwow64.exe, Pid: 2044, TotalTime: 4657, Count: 304, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Microsoft\OPC\DDT.o2k4yusucxfebl6ht9_2l2oqd.tmp, EstimatedImpact: 3% 2026-08-21T20:54:13.583 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T20:54:13.583 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T20:54:13.583 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T20:54:13.583 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T20:54:13.583 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T20:54:13.583 ProcessImageName: mysqld.exe, Pid: 240, TotalTime: 2613, Count: 26, MaxTime: 2296, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: Integrator.exe, Pid: 7312, TotalTime: 2551, Count: 246, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.Project.Project.x-none.msi.16.x-none.xml, EstimatedImpact: 12% 2026-08-21T20:54:13.583 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T20:54:13.583 ProcessImageName: notepad++.exe, Pid: 6108, TotalTime: 2294, Count: 148, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 1% 2026-08-21T20:54:13.583 ProcessImageName: VSSVC.exe, Pid: 2964, TotalTime: 2234, Count: 2, MaxTime: 1125, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 100% 2026-08-21T20:54:13.583 ProcessImageName: OfficeClickToRun.exe, Pid: 4076, TotalTime: 2225, Count: 129, MaxTime: 734, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.20326.20100\OfficeClickToRun.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: notepad++.exe, Pid: 10180, TotalTime: 2211, Count: 117, MaxTime: 390, MaxTimeFile: \Device\HarddiskVolume5\xampp\xampp-control.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: xampp-control.exe, Pid: 9016, TotalTime: 2182, Count: 10, MaxTime: 1734, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: svchost.exe, Pid: 3492, TotalTime: 1634, Count: 40, MaxTime: 687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\DOB995.tmp, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: mysqld.exe, Pid: 11568, TotalTime: 1359, Count: 115, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 51% 2026-08-21T20:54:13.583 ProcessImageName: geek64.exe, Pid: 7368, TotalTime: 1309, Count: 47, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\StarMicronics\TSP100\Software\20130806\TSP100ControlPanel.exe, EstimatedImpact: 67% 2026-08-21T20:54:13.583 ProcessImageName: svchost.exe, Pid: 2636, TotalTime: 1296, Count: 2, MaxTime: 1265, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 28% 2026-08-21T20:54:13.583 ProcessImageName: notepad++.exe, Pid: 7212, TotalTime: 1293, Count: 61, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T20:54:13.583 ProcessImageName: notepad++.exe, Pid: 7820, TotalTime: 1267, Count: 55, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 10% 2026-08-21T20:54:13.584 ProcessImageName: mysqld.exe, Pid: 13128, TotalTime: 1264, Count: 118, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\vcruntime140_1.dll, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 12836, TotalTime: 1243, Count: 14, MaxTime: 1062, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 984, TotalTime: 1217, Count: 6, MaxTime: 281, MaxTimeFile: \Device\HarddiskVolume3\Program Files\WindowsApps\MicrosoftTeams_26149.701.4759.8860_x64__8wekyb3d8bbwe\msteamsupdate.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: notepad++.exe, Pid: 10968, TotalTime: 1207, Count: 62, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 1412, TotalTime: 1145, Count: 88, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 9224, TotalTime: 1108, Count: 2, MaxTime: 1093, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 25% 2026-08-21T20:54:13.584 ProcessImageName: taskhostw.exe, Pid: 8332, TotalTime: 1093, Count: 2, MaxTime: 1062, MaxTimeFile: \Device\Harddisk0\DR0, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: notepad++.exe, Pid: 5812, TotalTime: 1081, Count: 49, MaxTime: 203, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: httpd.exe, Pid: 9140, TotalTime: 1024, Count: 54, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xampp\htdocs\_0\01_WebApps\Webftp\filemanager\filemanager_10.54\class\FM_Tools.php, EstimatedImpact: 34% 2026-08-21T20:54:13.584 ProcessImageName: wevtutil.exe, Pid: 6500, TotalTime: 921, Count: 2, MaxTime: 890, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Office16\WWLIB.DLL, EstimatedImpact: 60% 2026-08-21T20:54:13.584 ProcessImageName: PDFXCview.exe, Pid: 9408, TotalTime: 886, Count: 76, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Tracker Software\PDF Viewer\SearchProviders\Ask.xml, EstimatedImpact: 53% 2026-08-21T20:54:13.584 ProcessImageName: AddInUtil.exe, Pid: 11500, TotalTime: 884, Count: 14, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\AddInSideAdapters\Microsoft.VisualStudio.Tools.Office.AddInAdapter.v9.0.dll, EstimatedImpact: 53% 2026-08-21T20:54:13.584 ProcessImageName: webalizer.exe, Pid: 11200, TotalTime: 844, Count: 66, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume10\xampp\webalizer\hourly_usage_202403.png, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: Integrator.exe, Pid: 6700, TotalTime: 824, Count: 68, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: WmiPrvSE.exe, Pid: 13256, TotalTime: 803, Count: 16, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\pacer.sys, EstimatedImpact: 82% 2026-08-21T20:54:13.584 ProcessImageName: perl.exe, Pid: 4816, TotalTime: 779, Count: 4, MaxTime: 375, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: mmc.exe, Pid: 8684, TotalTime: 723, Count: 70, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\MMCEx\f97efd414599597cd6c95fdfdc2e714f\MMCEx.ni.dll, EstimatedImpact: 21% 2026-08-21T20:54:13.584 ProcessImageName: wevtutil.exe, Pid: 4588, TotalTime: 655, Count: 2, MaxTime: 640, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSO.DLL, EstimatedImpact: 80% 2026-08-21T20:54:13.584 ProcessImageName: firefox.exe, Pid: 7256, TotalTime: 631, Count: 49, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa13488, EstimatedImpact: 46% 2026-08-21T20:54:13.584 ProcessImageName: perl.exe, Pid: 13024, TotalTime: 576, Count: 5, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\libstdc++-6.dll, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: perl.exe, Pid: 7836, TotalTime: 576, Count: 4, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\perl532.dll, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: perl.exe, Pid: 10940, TotalTime: 560, Count: 5, MaxTime: 234, MaxTimeFile: \Device\HarddiskVolume5\xampp\perl\bin\libstdc++-6.dll, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: OfficeClickToRun.exe, Pid: 6068, TotalTime: 534, Count: 26, MaxTime: 171, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Integrator.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: firefox.exe, Pid: 8516, TotalTime: 526, Count: 38, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\pending_pings\2e0d043b-ad26-4ff7-aa84-8a9e26c7869c, EstimatedImpact: 67% 2026-08-21T20:54:13.584 ProcessImageName: firefox.exe, Pid: 5356, TotalTime: 451, Count: 39, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate.moz_log.tempa00952, EstimatedImpact: 56% 2026-08-21T20:54:13.584 ProcessImageName: AdobeCollabSync.exe, Pid: 7944, TotalTime: 439, Count: 39, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Adobe\GrowthSDK\Production\x64\manifest.db, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: WmiPrvSE.exe, Pid: 3812, TotalTime: 436, Count: 59, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\spool\V4Dirs\1ACA1C2E-2855-473B-9079-B6EDF3508895\d719099c.gpd, EstimatedImpact: 20% 2026-08-21T20:54:13.584 ProcessImageName: firefox.exe, Pid: 6868, TotalTime: 435, Count: 42, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\dependentlibs.list, EstimatedImpact: 29% 2026-08-21T20:54:13.584 ProcessImageName: powershell.exe, Pid: 8276, TotalTime: 414, Count: 31, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\ea3307ee75205324b021498c40f1e767\System.Management.Automation.ni.dll, EstimatedImpact: 19% 2026-08-21T20:54:13.584 ProcessImageName: wacs.exe, Pid: 8740, TotalTime: 366, Count: 19, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\win-acme\acme-v02.api.letsencrypt.org\public_suffix_list.dat, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: updater.exe, Pid: 3212, TotalTime: 361, Count: 30, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\uninstall\helper.exe, EstimatedImpact: 2% 2026-08-21T20:54:13.584 ProcessImageName: backgroundTaskHost.exe, Pid: 14184, TotalTime: 330, Count: 40, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787324264, EstimatedImpact: 7% 2026-08-21T20:54:13.584 ProcessImageName: TeamViewer.exe, Pid: 8052, TotalTime: 316, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\TeamViewer\Database\tvchatfiledownloadhistory.db, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: PhoneExperienceHost.exe, Pid: 10596, TotalTime: 315, Count: 33, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\system32\ctac.json, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: webalizer.exe, Pid: 10172, TotalTime: 287, Count: 21, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\logs\access.log, EstimatedImpact: 17% 2026-08-21T20:54:13.584 ProcessImageName: firefox.exe, Pid: 6400, TotalTime: 285, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp, EstimatedImpact: 20% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 2524, TotalTime: 278, Count: 8, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: SDXHelper.exe, Pid: 1848, TotalTime: 241, Count: 22, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\PlatformCapabilities\ExcelCapabilities.json, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: dllhost.exe, Pid: 5476, TotalTime: 240, Count: 22, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Prefetch\DLLHOST.EXE-87D16202.pf, EstimatedImpact: 58% 2026-08-21T20:54:13.584 ProcessImageName: SDXHelper.exe, Pid: 8508, TotalTime: 226, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 16% 2026-08-21T20:54:13.584 ProcessImageName: dasHost.exe, Pid: 5204, TotalTime: 212, Count: 32, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Dlna\DeviceIcons\aca8d3ad-7139-445f-813a-bd70055483b9_4.bmp, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: dllhost.exe, Pid: 5860, TotalTime: 210, Count: 19, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\WebCache\V01.chk, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: TabTip.exe, Pid: 764, TotalTime: 202, Count: 5, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 98% 2026-08-21T20:54:13.584 ProcessImageName: TabTip.exe, Pid: 5880, TotalTime: 202, Count: 4, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\tabskb.dll, EstimatedImpact: 100% 2026-08-21T20:54:13.584 ProcessImageName: brynhildr.exe, Pid: 4028, TotalTime: 201, Count: 7, MaxTime: 156, MaxTimeFile: \Device\HarddiskVolume3\brynhildr30203\brynhildr.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 2940, TotalTime: 201, Count: 4, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\TeamViewer\TeamViewer_Service.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: spoolsv.exe, Pid: 3664, TotalTime: 198, Count: 12, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Downloads\index.php, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: backgroundTaskHost.exe, Pid: 3436, TotalTime: 195, Count: 21, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\280810\1786913770, EstimatedImpact: 21% 2026-08-21T20:54:13.584 ProcessImageName: dllhost.exe, Pid: 13152, TotalTime: 186, Count: 3, MaxTime: 93, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Notepad++\contextMenu\NppShell.dll, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 2128, TotalTime: 184, Count: 7, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\wbem\WinMgmtR.dll, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: SDXHelper.exe, Pid: 8808, TotalTime: 181, Count: 19, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 19% 2026-08-21T20:54:13.584 ProcessImageName: SDXHelper.exe, Pid: 2632, TotalTime: 168, Count: 10, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\71E12F42-4855-4DEA-9FCD-6BA175559E5D, EstimatedImpact: 6% 2026-08-21T20:54:13.584 ProcessImageName: taskhostw.exe, Pid: 3192, TotalTime: 168, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ink\InkObj.dll, EstimatedImpact: 71% 2026-08-21T20:54:13.584 ProcessImageName: SDXHelper.exe, Pid: 7792, TotalTime: 151, Count: 13, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\F446DABB-0339-48EC-9FD1-7655C1030E7F, EstimatedImpact: 15% 2026-08-21T20:54:13.584 ProcessImageName: backgroundTaskHost.exe, Pid: 5952, TotalTime: 150, Count: 17, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\202914\1639352379, EstimatedImpact: 8% 2026-08-21T20:54:13.584 ProcessImageName: FileSyncHelper.exe, Pid: 4476, TotalTime: 150, Count: 16, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft OneDrive\FileSyncHelper\logs\standaloneUpdaterTelemetryCache.otc-wal, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: RuntimeBroker.exe, Pid: 6528, TotalTime: 150, Count: 12, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3dfddc83-33d3-44cd-9ba6-3d9166cbc52a.down_data, EstimatedImpact: 22% 2026-08-21T20:54:13.584 ProcessImageName: MicrosoftEdge_X64_151.0.4129.101_151.0.4129.93.exe, Pid: 3744, TotalTime: 140, Count: 2, MaxTime: 125, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeUpdate\Install\{C95778E3-96F2-479B-8279-B2A82F4EBEA0}\EDGEMITMP_D0EA5.tmp\setup.exe, EstimatedImpact: 73% 2026-08-21T20:54:13.584 ProcessImageName: OpenWith.exe, Pid: 6580, TotalTime: 139, Count: 3, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\7-Zip\7zG.exe, EstimatedImpact: 64% 2026-08-21T20:54:13.584 ProcessImageName: OfficeC2RClient.exe, Pid: 13892, TotalTime: 137, Count: 9, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T20:54:13.584 ProcessImageName: OfficeClickToRun.exe, Pid: 14624, TotalTime: 136, Count: 10, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 2756, TotalTime: 136, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Fonts\simsun.ttc, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: AggregatorHost.exe, Pid: 5244, TotalTime: 135, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Diagnosis\AggregatorStorage\UpdateHeartbeatScan$, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: svchost.exe, Pid: 576, TotalTime: 124, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\SecurityHealth\10.0.29628.1000-0\SecurityHealthHost.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: VC_redist.x64.exe, Pid: 3312, TotalTime: 123, Count: 6, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\.unverified\cab2C04DDC374BD96EB5C8EB8208F2C7C92, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: VC_redist.x64.exe, Pid: 6732, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{6B51A8A8-B03D-4443-92C2-BE7718678C02}\.ba\1031\thm.wxl, EstimatedImpact: 68% 2026-08-21T20:54:13.584 ProcessImageName: sihost.exe, Pid: 6532, TotalTime: 121, Count: 11, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ollama.lnk, EstimatedImpact: 0% 2026-08-21T20:54:13.584 ProcessImageName: BackgroundTransferHost.exe, Pid: 7256, TotalTime: 121, Count: 6, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\68cbfb25-6a38-4b97-848b-490aae7e8dc0.up_meta_secure, EstimatedImpact: 43% 2026-08-21T20:54:13.585 ProcessImageName: dllhost.exe, Pid: 5044, TotalTime: 120, Count: 14, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\SPP\OnlineMetadataCache\{90879088-966a-4ca7-b663-8464c2e9df95}_OnDiskSnapshotProp, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: taskhostw.exe, Pid: 3124, TotalTime: 120, Count: 13, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\5b4156767e2129db76a3b2f33ac1638165fc8fba.tbres->(UTF-16LE), EstimatedImpact: 18% 2026-08-21T20:54:13.585 ProcessImageName: crashreporter.exe, Pid: 9176, TotalTime: 120, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Mozilla\Firefox\Crash Reports\glean\db\data.safe.bin, EstimatedImpact: 6% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 13012, TotalTime: 107, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: VC_redist.x86.exe, Pid: 12964, TotalTime: 107, Count: 5, MaxTime: 62, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\.unverified\cabB3E1576D1FEFBB979E13B1A5379E0B16, EstimatedImpact: 5% 2026-08-21T20:54:13.585 ProcessImageName: RuntimeBroker.exe, Pid: 9624, TotalTime: 106, Count: 6, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\ScreenClip\{A27A8ED8-1711-4C3C-B4A0-4C6EEBAA6740}.json, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: vc_redist.x64.exe, Pid: 13248, TotalTime: 105, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{32A3BF1B-AEB7-4A9D-B9C4-10484ECF11C0}\.ba\wixstdba.dll, EstimatedImpact: 35% 2026-08-21T20:54:13.585 ProcessImageName: cmd.exe, Pid: 14832, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume5\xampp\apache\bin\htpasswd.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: firefox.exe, Pid: 4172, TotalTime: 93, Count: 2, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\crashreporter.exe, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 7684, TotalTime: 91, Count: 5, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-shm, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: OfficeClickToRun.exe, Pid: 1884, TotalTime: 90, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\83F3AD92-CDE1-4B53-841E-B5337C1E40CE, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 5720, TotalTime: 90, Count: 9, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\9D054AB7-FC66-4419-BF82-7308B854D857, EstimatedImpact: 4% 2026-08-21T20:54:13.585 ProcessImageName: backgroundTaskHost.exe, Pid: 13812, TotalTime: 90, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787338789, EstimatedImpact: 5% 2026-08-21T20:54:13.585 ProcessImageName: , Pid: 4, TotalTime: 90, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolumeShadowCopy4\System Volume Information\{0ed535b3-9d6a-11f1-a194-d850e63fb470}{3808876b-c176-4e48-b7ae-04046e6cc752}, EstimatedImpact: 9% 2026-08-21T20:54:13.585 ProcessImageName: notepad++.exe, Pid: 4932, TotalTime: 77, Count: 28, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: VC_redist.x86.exe, Pid: 14108, TotalTime: 75, Count: 10, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Package Cache\{0b5169e3-39da-4313-808e-1f9c0407f3bf}\state.rsm, EstimatedImpact: 57% 2026-08-21T20:54:13.585 ProcessImageName: vc_redist.x86.exe, Pid: 14588, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\{20E042F2-CA05-4178-95C3-08B5DBE07E3D}\.ba\wixstdba.dll, EstimatedImpact: 47% 2026-08-21T20:54:13.585 ProcessImageName: AcroCEF.exe, Pid: 1200, TotalTime: 75, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State, EstimatedImpact: 46% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 10416, TotalTime: 61, Count: 5, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1058.log, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: Acrobat.exe, Pid: 6112, TotalTime: 61, Count: 4, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\desktop.ini, EstimatedImpact: 7% 2026-08-21T20:54:13.585 ProcessImageName: taskhostw.exe, Pid: 6804, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\drivers\usbport.sys, EstimatedImpact: 2% 2026-08-21T20:54:13.585 ProcessImageName: svchost.exe, Pid: 14608, TotalTime: 61, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\Addons\ActionsServer.msix, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: cmd.exe, Pid: 7796, TotalTime: 61, Count: 3, MaxTime: 46, MaxTimeFile: \Device\HarddiskVolume5\xx_\xampp_7.4.1_mit_Programme\xampp\webalizer\webalizer.exe, EstimatedImpact: 55% 2026-08-21T20:54:13.585 ProcessImageName: SecurityHealthHost.exe, Pid: 10328, TotalTime: 60, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\TokenBroker\Cache\6ec69b01332d9be433081dae9180e1c12d7683f9.tbres->(UTF-16LE), EstimatedImpact: 5% 2026-08-21T20:54:13.585 ProcessImageName: backgroundTaskHost.exe, Pid: 14704, TotalTime: 60, Count: 7, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787335156, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: Acrobat.exe, Pid: 6552, TotalTime: 60, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Adobe\Acrobat\DC\UserCache.bin, EstimatedImpact: 20% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 7552, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1116.log, EstimatedImpact: 2% 2026-08-21T20:54:13.585 ProcessImageName: cmd.exe, Pid: 7712, TotalTime: 46, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume10\xampp\webalizer\webalizer.exe, EstimatedImpact: 42% 2026-08-21T20:54:13.585 ProcessImageName: dllhost.exe, Pid: 13956, TotalTime: 46, Count: 2, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\locale\de_de\Acrobat Elements\ContextMenuShim64.deu, EstimatedImpact: 28% 2026-08-21T20:54:13.585 ProcessImageName: updater.exe, Pid: 12692, TotalTime: 45, Count: 6, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: pingsender.exe, Pid: 1304, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419, EstimatedImpact: 16% 2026-08-21T20:54:13.585 ProcessImageName: AcroCEF.exe, Pid: 1380, TotalTime: 45, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: SDXHelper.exe, Pid: 2340, TotalTime: 45, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\Office\OTele\sdxhelper.exe.db-shm, EstimatedImpact: 11% 2026-08-21T20:54:13.585 ProcessImageName: updater.exe, Pid: 10576, TotalTime: 45, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\0\update.status, EstimatedImpact: 37% 2026-08-21T20:54:13.585 ProcessImageName: OneDriveLauncher.exe, Pid: 10512, TotalTime: 31, Count: 9, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: helper.exe, Pid: 1384, TotalTime: 31, Count: 8, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\default-browser-agent.exe, EstimatedImpact: 4% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 6580, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-2239.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 5760, TotalTime: 31, Count: 3, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1745.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: SDXHelper.exe, Pid: 11216, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Microsoft\OneAuth\accounts\e0926eca9796fcb8, EstimatedImpact: 5% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 11096, TotalTime: 30, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1743.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: StoreDesktopExtension.exe, Pid: 12108, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: backgroundTaskHost.exe, Pid: 12536, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338389\1787317000, EstimatedImpact: 29% 2026-08-21T20:54:13.585 ProcessImageName: backgroundTaskHost.exe, Pid: 4016, TotalTime: 30, Count: 4, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338387\1787302503->(UTF-16LE), EstimatedImpact: 28% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 10748, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1344.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 7584, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1404.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 12636, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1442.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 5068, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1739.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 12896, TotalTime: 30, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1102.log, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: svchost.exe, Pid: 1000, TotalTime: 30, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\System Volume Information\Windows Backup\Catalogs\GlobalCatalog.wbcat, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: ngentask.exe, Pid: 11504, TotalTime: 15, Count: 8, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config, EstimatedImpact: 3% 2026-08-21T20:54:13.585 ProcessImageName: backgroundTaskHost.exe, Pid: 4920, TotalTime: 15, Count: 5, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\LocalState\ContentManagementSDK\Creatives\338388\1787320631, EstimatedImpact: 1% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 2848, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1508.log->(UTF-16LE), EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 6564, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1516.log, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 2312, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1358.log, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: OfficeC2RClient.exe, Pid: 10144, TotalTime: 15, Count: 3, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\Temp\PC1LAN-20260821-1322.log, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: StoreDesktopExtension.exe, Pid: 11960, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\globalization\icu\icudtl.dat, EstimatedImpact: 9% 2026-08-21T20:54:13.585 ProcessImageName: svchost.exe, Pid: 1204, TotalTime: 15, Count: 2, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-20\645e693b46e555ec3e6c34172fc00e85_ff5a7615-1a6f-41c7-bf67-fdc2ec0e3d70, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: SecHealthUI.exe, Pid: 7200, TotalTime: 0, Count: 3, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SecHealthUI_1000.29628.1000.0_x64__8wekyb3d8bbwe\ActivationStore.dat, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: DismHost.exe, Pid: 1400, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Windows\System32\config\components, EstimatedImpact: 0% 2026-08-21T20:54:13.585 ProcessImageName: svchost.exe, Pid: 10760, TotalTime: 0, Count: 2, MaxTime: 0, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Comms\Unistore\data\AggregateCache.uca, EstimatedImpact: 0% 2026-08-21T21:02:12.833 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T21:09:02.994 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php26CC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #108903, FileId: 0x2f000000037286, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:12:16.220 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php1991.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #108976, FileId: 0x2c000000037321, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:12:29.587 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3EDD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #108980, FileId: 0x74000000037289, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:12:39.684 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php73DA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #108982, FileId: 0x34000000037286, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:12:55.311 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB23D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #108984, FileId: 0x2e00000003731f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:16:10.403 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #109092, FileId: 0x3f000000037322, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:16:25.030 UpdateEngine start: Source: 1, szUpdateDirectory: C:\Windows\Temp\E3C8BB54-5F7E-4316-B734-4F5FC188CDCF34f0.1dd31b25122421f 2026-08-21T21:16:25.150 Verifying engine and signature files (source: 0) ... 2026-08-21T21:16:25.150 Skipped verification of [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpengine.dll] due to PPL. 2026-08-21T21:16:25.150 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpasbase.vdm]. File not in cache (0x1) 2026-08-21T21:16:25.928 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpasbase.vdm] 2026-08-21T21:16:25.928 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpasdlta.vdm]. File not in cache (0x1) 2026-08-21T21:16:25.947 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpasdlta.vdm] 2026-08-21T21:16:25.947 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpavbase.vdm]. File not in cache (0x1) 2026-08-21T21:16:26.301 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpavbase.vdm] 2026-08-21T21:16:26.301 MpCacheManagerIsTrustedFile [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpavdlta.vdm]. File not in cache (0x1) 2026-08-21T21:16:26.320 Verified [C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D}\mpavdlta.vdm] 2026-08-21T21:16:26.487 [Engine] IsHybridMode: 0 2026-08-21T21:16:26.488 [KSL]KSL(1.1.26051.3007) Is available via CAMP. KslDevice : KslD 2026-08-21T21:16:26.499 Database:Can't find offline cache cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1DEF9495DE388C7FBAB7457ABDC4799ACE89DF4.bin): 0x00000002 2026-08-21T21:16:26.504 Database:Creating offline cache (C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-A1DEF9495DE388C7FBAB7457ABDC4799ACE89DF4.bin) 2026-08-21T21:16:26.504 Database:Product:1, ProductVersion:5, Platform:6, PlatformVersion:19, IsBeta:0, IsAdvancedAtLoad:1, IsParanoid: 0, IsOffline: 0 2026-08-21T21:16:26.504 Database:IsEmbedded: 0, IsIEVEnabled: 1, IsServerSku: 0, IsRsdhSku: 0, IsEnterpriseProduct: 0, IsMsft: 0, IsSeville: 0, IsMsSense: 0, IsImmune: 0, IsMba: 0, IsPus: 1, IsManaged: 0, IsSmode: 0 2026-08-21T21:16:26.504 Database:IsAutoSubmit:1, IsPusRem:0, LoadedAS:1, LoadedAV:1, LoadedInternal: 0, PassiveMode: 0, SxsPassiveMode:0, IsDevMode:0, IsTestSigning:0, IsWCOS: 0, IsInsideContainer: 0, IsHybridMode: 0 2026-08-21T21:16:26.504 Database:kLCID:1031, kOsVersion:655360, kProcessorArch:9, dwIsTest:0, kOOsVersion:655360, kOsSP:0, kOsBld:22000, dwPvpRing=0xffffffff IDynamicConfig::ReportError value=BruteForceProtectionIPExclusion hr=0x8007007b IDynamicConfig::ReportError value=BruteForceProtectionStatus hr=0x8007007b IDynamicConfig::ReportError value=DisableGradualRelease hr=0x8007007b IDynamicConfig::ReportError value=EnableFileHashComputation hr=0x8007007b IDynamicConfig::ReportError value=MpBafsExtendedTimeout hr=0x8007000d IDynamicConfig::ReportError value=MpCampRing hr=0x8007007b IDynamicConfig::ReportError value=MpCampRingThrottled hr=0x8007007b IDynamicConfig::ReportError value=MpCloudBlockLevel hr=0x8007000d IDynamicConfig::ReportError value=MpEngineRing hr=0x8007007b IDynamicConfig::ReportError value=MpEngineRingThrottled hr=0x8007007b 2026-08-21T21:16:37.289 Geo ID not found using standard default set: :SOAP:https://wdcp.microsoft.com/WdCpSrvc.asmx 2026-08-21T21:16:37.289 [AutoExclusion] Skipped Non-Windows 10+ Server SKUs. IDynamicConfig::ReportError ECS value=EnableAdsSymlinkMitigation_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableCIWorkaroundOnCFAEnabled_MpRamp hr=0x8007007b IDynamicConfig::ReportError ECS value=MdTimerInitalDelay hr=0x800700d4 IDynamicConfig::ReportError ECS value=MdTimerMonitorInterval hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpCopyAcceleratorCancellableCopyState hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisablePropBagNotification hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnablePurgeHipsCache hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpForceDllHostScanExeOnOpen hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpDisableResourceMonitoring hr=0x8007007b IDynamicConfig::ReportError ECS value=MdDisableResController hr=0x800700d4 IDynamicConfig::ReportError ECS value=EnableBmProcessInfoMetastoreMaintenance_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpEnableNoMetaStoreProcessInfoContainer hr=0x800700d4 IDynamicConfig::ReportError ECS value=NIS_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=EnableThreatIdKeyForSigExpiry_MpRamp hr=0x800700d4 IDynamicConfig::ReportError ECS value=MpFC_DisableTransportCallouts hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDlpClipboardSettings hr=0x8007007b IDynamicConfig::ReportError ECS value=NIS_EnableUsoSupport hr=0x8007007b IDynamicConfig::ReportError ECS value=MpDisablePerProcessLoopbackTraffic hr=0x800700d4 IDynamicConfig::ReportChange ECS value=EnableSmsEmsOnArm64_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableWDClipHelper new=1 old0 IDynamicConfig::ReportChange ECS value=EnableGetCmdComponentsV2_MpRamp new=True oldFalse IDynamicConfig::ReportChange ECS value=MpFC_EnableNetPromptMemscan new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_CoreSvcEnableUpdateLogging new=1 old0 IDynamicConfig::ReportChange ECS value=MpFC_EnforceMpUxAgentHostParentCheck new=1 old0 IDynamicConfig::ReportChange ECS value=MpDisableBmHealthOneDsEvent new=True oldFalse 2026-08-21T21:16:37.349 [Engine] RSIG_ENGINE_PRE_SHUTDOWN, 0x00007FFB7F3055E0, lRefCount: 6, hr=0 2026-08-21T21:16:37.349 [Engine] New active engine 00007FFB70DF55E0 replacing engine 00007FFB7F3055E0. Number of active engines: 2 2026-08-21T21:16:37.356 EngineInit:Global ASOC is enabled 2026-08-21T21:16:37.356 EngineInit:ASOO is enabled for developer volumes 2026-08-21T21:16:37.425 Engine-HIPS:Loaded ASR vdm rule "Block use of copied or impersonated system tools", State=5, Action=0, Type=9, Duplicates(Interval=288000000000, scope=0x100) 2026-08-21T21:16:37.425 Engine-HIPS:Loaded ASR vdm rule "Block executable files from running unless they meet a prevalence, age, or trusted list criteria", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block credential stealing from the Windows local security authority subsystem (lsass.exe)", State=5, Action=7, Type=1, Duplicates(Interval=288000000000, scope=0x380) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from injecting code into other processes", State=5, Action=2, Type=24, Duplicates(Interval=144000000000, scope=0x380) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Controlled folder access", State=0, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block untrusted and unsigned processes that run from USB", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Adobe Reader from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Office applications from creating executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Webshell creation for Servers", State=5, Action=0, Type=1, Duplicates(Interval=0, scope=0x0) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Office communication application from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block Win32 API calls from Office macro", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.426 Engine-HIPS:Loaded ASR vdm rule "Block abuse of in-the-wild exploited vulnerable signed drivers", State=5, Action=0, Type=1, Duplicates(Interval=36000000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block all Office applications from creating child processes", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Use advanced protection against ransomware", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block Process Creations originating from PSExec & WMI commands", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block Launching of executable content from email attachment", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block JavaScript or VBScript from launching downloaded executable content", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block persistence through WMI event subscription", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block rebooting machine in Safe Mode", State=5, Action=1, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.427 Engine-HIPS:Loaded ASR vdm rule "Block execution of potentially obfuscated scripts", State=5, Action=0, Type=1, Duplicates(Interval=1200000000, scope=0x100) 2026-08-21T21:16:37.434 Dynamic signature dropped Dynamic Signature has been dropped Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\048573091599a2271128b5c8ca1582612463e035 Dynamic Signature Compilation Timestamp:08-21-2026 09:12:45 Persistence Type:Duration Time remaining:288000000 2026-08-21T21:16:37.465 MpWriteUupSignatureVersion 1.457.275.0, hr = 0 2026-08-21T21:16:37.467 ForceSyncMoacInsertion config from engine is 0, hr = 0x0 2026-08-21T21:16:37.492 [RTP] [Mini-filter] MpFC: MpFC_Kernel_HardenUxProcesses=0;MpFC_Kernel_SystemIoRequestWorkOnBehalfOf=0x1;MpFC_Kernel_PreventBindfltAbuse=0x1;MpFC_Kernel_ParentProcessObHardeningAllow=0;MpFC_Kernel_ReduceOfficeInjectRuleFP=0x1;MPC_Kernel_CheckValidityOfProcessFilterFlagsInASR=0x1;MpFc_Kernel_UseLowPrioThreadsForAsyncScans=0x1;MpFc_Kernel_DisableFileDirtyLogic=0;MpFC_Kernel_DisableDLPPort=0x1;MpFC_Kernel_DlpFeatures=0;MpFC_Kernel_EnableFolderGuardOnPostCreate=0x1;MpFC_Kernel_StrictTiChildrenMatch=0;MpFC_Kernel_PPLReduxMitigationFlags=0x3;MpFc_Kernel_UseLowPriAsyncScansDevDrvOnly=0x1;MpFc_Kernel_DisableOfficeInjectUevSuppression=0x1;MpFc_Kernel_CopyChunkFileHintMask=0;MpFc_Kernel_DisableScanOnCloseForNetworkFiles=0x1;MpFc_Kernel_MaxAsyncWorkQueue=0x400;MpFc_Kernel_DlpIgnoreSystemFolder=0x1;MpFc_Kernel_DlpPassThroughMode=0;MpFc_Kernel_L2StateCache_DefaultStreamsOnly=0x1;MpFc_Kernel_L2StateCache_SupportGenericFileState=0x1;MpFc_Kernel_CryptSvcPreScanFilter=0x1;MpFc_Kernel_SystemPreScanFilter=0x1;MpFC_Kernel_CheckValidit 2026-08-21T21:16:37.493 [HybridMode] HybridMode change notification isHybridModePolicyEnabled: 0, isVerifiedAndReputableTrustModeEnabled: 0 2026-08-21T21:16:37.493 Hybrid mode change notification called, no change detected in verified and reputable trust mode (0 -> 0)! 2026-08-21T21:16:37.493 Hybrid mode change notification called, no change detected in Hybrid mode (0 -> 0)! 2026-08-21T21:16:37.493 ReinforceServiceAcls: will NOT be adding Truster Installed SID to Defender service SD.ApplyDefenderProcessTokenTrustLableAce succeeded to set. 2026-08-21T21:16:37.522 MpUpdateUpdateResiliencyConfiguration updated to 0 2026-08-21T21:16:37.522 [Plugin] Initializing RTP plugin state... 2026-08-21T21:16:37.522 [Plugin] Normal mode, or passive mode with shadow protection enabled. Will not force RTP off. 2026-08-21T21:16:37.522 [RTP] ****************************RTP Perf Log*************************** RTP Start:‎08‎-‎21‎-‎2026 10:54:14 Last Perf:‎08‎-‎21‎-‎2026 10:54:14 First RTP Scan:‎08‎-‎21‎-‎2026 10:54:14 Plugin States: AV:1 AS:1 RTP:1 OA:1 BM:1 Process Exclusions: Path Exclusions: Ext Exclusions: Temp Exclusions: Worker Threads: AM:18 Async:4 Cache Flushes: RTP:4 System File Cache: Hits:18873 Misses:81604 BM Queue:0,580,0 Proc:0,181,0 File:0,447,0 NamedPipe:0,0,0 Plugin Queue:0,2,0 Threat:0,1,0 Susp:0,1,0 Unknown:0,0,0 Error:0,0,0 Request Queue:1,3,0 SetEngine:1,1,0 SetState:0,1,0 SetUser:0,0,0 Config:0,2,0 ProcExcl:0,1,0 FilterReload:0,0,0 FilterUnload:0,0,0 MpFilter: Scans:109204 Pending:0 RegSize:309948 AsyncQNotif:0 AsyncQMissed:0 AsyncQTotalSent:429638392 AsyncQCurrent:0 BMFlags:56543 ServiceMaj:0 ServiceMin:0 NumInstance:14 TotalStreamCon:36210 NTFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:226934 TotalHits:605768 InstanceCacheInserts:14856 InstanceCacheUpdates:0 InstanceCacheDeletes:4421 InstanceCacheHits:1015 InstanceCacheMisses:118654 InstanceCacheOverflows:0 CSVFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 REFS Cache Statistics (Instance Cache Type:GenericTable): TotalMisses:0 TotalHits:0 InstanceCacheInserts:0 InstanceCacheUpdates:0 InstanceCacheDeletes:0 InstanceCacheHits:0 InstanceCacheMisses:0 InstanceCacheOverflows:0 SyncProcessCreateDuration:3ms (6226/1978) Success: 1978, failures: 0 (last code: 0x0), timeouts: 0, baddata: 0 **************************END RTP Perf Log************************* 2026-08-21T21:16:37.523 [Engine] Loaded C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{ACF48B0E-751B-46E5-8501-F295351DCD1D} 2026-08-21T21:16:37.525 [RTP] Setting TrustedInstallerHardeningExcludeFlags to 3 (hr=0). 2026-08-21T21:16:37.525 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4BD27298-9E55-4A0F-8642-8781F938FE1E} removed 2026-08-21T21:16:37.525 [Engine] Skip removing C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}, C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7}\mpasbase.vdm in use, hr=0x80070020 2026-08-21T21:16:37.526 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.526 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.527 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.527 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.527 MdCoreSvc is supported in this platform and OS Beginning quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Target: Flags:131074 Start time:08-21-2026 21:16:37 Finished quarantine recovery Quarantine ID:{00000000-0000-0000-0000-000000000000} Result:0 End time:08-21-2026 21:16:37 2026-08-21T21:16:37.532 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T21:16:37.533 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). BmLoggingDisabled:MpDisableBmLogging not set. 2026-08-21T21:16:37.533 MpPlatformKillbitsFromEngine (0x4000000) written, hr = 0 2026-08-21T21:16:37.533 MpPlatformKillbitsFromEngineEx (0x0) (0x0) written, hr = 0 2026-08-21T21:16:37.536 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T21:16:37.537 Failed to retrieve config value from engine or configurations for config key (MdCpuSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.537 Failed to retrieve config value from engine or configurations for config key (MdCrashSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.537 Failed to retrieve config value from engine or configurations for config key (MdDiskSensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.537 Failed to retrieve config value from engine or configurations for config key (MdMemorySensorCollectionLag) hr = 0x8050800f 2026-08-21T21:16:37.538 MdCoreSvc is supported in this platform and OS 2026-08-21T21:16:37.540 [ManagedAgent] IFEO: process mitigations enforced for DefenderAgentScan.exe (options=0x0050101000000000) 2026-08-21T21:16:37.540 [ManagedAgent] Removing hooks (FC=0, state=0, dlp=0) Signature updated on 08-21-2026 21:16:37 Product Version: 4.18.26070.9 Service Version: 4.18.26070.9 Engine Version: 1.1.26070.7 AS Signature Version: 1.457.275.0 AV Signature Version: 1.457.275.0 ************************************************************ 2026-08-21T21:16:37.542 [Update] Performing ScanOnUpdate, GetConfigHr: 0x0, dwDisableScanOnUpdate: 0, passiveMode: 0, killbit: 0 2026-08-21T21:16:37.542 UpdateEngine finished with 0: Source: 1, szUpdateDirectory: C:\Windows\Temp\E3C8BB54-5F7E-4316-B734-4F5FC188CDCF34f0.1dd31b25122421f 2026-08-21T21:16:37.558 Process scan (postsignatureupdatescan) started. 2026-08-21T21:16:37.648 [TP] State change. FeatureAvialable: True, NewState: 0x1, OldState: 0x1, Scenario: Consumer, Source: Signatures, ConfigChange: True 2026-08-21T21:16:37.650 [TP] TP Enabled: 1, SecureConfigEnabled: 0, DisableTPExclusionBypass: 0, EnableTPExclusion via FC: 1, IsIntuneManagedDefender: 0, IsSCCMManagedDefender: 0, IsMDEAttachManagedDefender: 0, IsSCCMOnlyManagedDefender: 0, IsStrictPolicyModeEnabled: 0 (from snapshot: 0), Effective EnableTPExclusions: 0, Previous EnableTPExclusions: 0, Delayed call: 0 2026-08-21T21:16:37.991 [KSL] Entering CKSLEngine::EnableKSL. State: [3] 2026-08-21T21:16:37.991 [KSL] CKSLEngine::EnableKSL feature is already enabled. 2026-08-21T21:16:37.991 [KSL] Leaving CKSLEngine::EnableKsl(0). 2026-08-21T21:16:38.062 [RTP] Setting RegLinkHardeningMode to 1 (hr=0). 2026-08-21T21:16:38.062 [RTP] Setting EfsHardeningFlags to 1 (hr=0). 2026-08-21T21:16:38.062 [RTP] Setting DisableDynamicFsHardening to 1 (hr=0). 2026-08-21T21:16:38.062 [RTP] PreventPagingFileAbuseKillbit[0]. 2026-08-21T21:16:38.062 [RTP] Setting PreventPagingFileAbuse to 1 (hr=0). 2026-08-21T21:16:38.079 [Engine] Engine 00007FFB7F3055E0 no longer in use. Number of active engines: 1 2026-08-21T21:16:38.079 [RTP] OS Copy Accelerator feature is: 1 (0:Disabled, 1:Enabled) 2026-08-21T21:16:38.079 [RTP] Setting SetEnablePurgeHipsCache to 1 (hr=0). 2026-08-21T21:16:38.337 ProcessImageName: httpd.exe, Pid: 2004, TotalTime: 1166131, Count: 56817, MaxTime: 5484, MaxTimeFile: \Device\HarddiskVolume3\Windows\Installer\7df89.msp, EstimatedImpact: 3% 2026-08-21T21:16:38.337 ProcessImageName: explorer.exe, Pid: 7428, TotalTime: 48989, Count: 1160, MaxTime: 5687, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\Cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T21:16:38.337 ProcessImageName: Everything.exe, Pid: 1916, TotalTime: 23921, Count: 38, MaxTime: 5437, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb), EstimatedImpact: 0% 2026-08-21T21:16:38.337 ProcessImageName: setup.exe, Pid: 2068, TotalTime: 10605, Count: 417, MaxTime: 4187, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\Microsoft\EdgeCore\151.0.4129.101\msedge.dll, EstimatedImpact: 24% 2026-08-21T21:16:38.337 ProcessImageName: CCC.exe, Pid: 12612, TotalTime: 7610, Count: 93, MaxTime: 593, MaxTimeFile: \Device\HarddiskVolume3\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll, EstimatedImpact: 79% 2026-08-21T21:16:38.337 ProcessImageName: dllhost.exe, Pid: 9972, TotalTime: 5907, Count: 166, MaxTime: 218, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\CacheStorage\Files4\QHCL356W_503\LUF39ZLN_504\I418CELYD4_114, EstimatedImpact: 0% 2026-08-21T21:16:38.337 ProcessImageName: splwow64.exe, Pid: 2044, TotalTime: 4657, Count: 304, MaxTime: 78, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\LocalLow\Temp\Microsoft\OPC\DDT.o2k4yusucxfebl6ht9_2l2oqd.tmp, EstimatedImpact: 3% 2026-08-21T21:16:38.337 ProcessImageName: AcroCEF.exe, Pid: 10976, TotalTime: 3979, Count: 175, MaxTime: 343, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\static\js\rna-main.js, EstimatedImpact: 32% 2026-08-21T21:16:38.337 ProcessImageName: svchost.exe, Pid: 6908, TotalTime: 3836, Count: 51, MaxTime: 703, MaxTimeFile: \Device\HarddiskVolume5\xx_\WindowsZertifikaterstellen\win-acme.v2.2.9.1701.x64.pluggable\wacs.exe, EstimatedImpact: 100% 2026-08-21T21:16:38.337 ProcessImageName: helper.exe, Pid: 12224, TotalTime: 3381, Count: 77, MaxTime: 2078, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Mozilla Firefox\xul.dll, EstimatedImpact: 86% 2026-08-21T21:16:38.337 ProcessImageName: DesktopOK.exe, Pid: 11808, TotalTime: 3240, Count: 375, MaxTime: 15, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\DesktopOK\DesktopOK.ini->(UTF-16LE), EstimatedImpact: 43% 2026-08-21T21:16:38.337 ProcessImageName: httpd.exe, Pid: 7692, TotalTime: 2862, Count: 78, MaxTime: 250, MaxTimeFile: \Device\HarddiskVolume5\xampp\php\ext\php_gd.dll, EstimatedImpact: 52% 2026-08-21T21:16:38.337 ProcessImageName: mysqld.exe, Pid: 240, TotalTime: 2613, Count: 26, MaxTime: 2296, MaxTimeFile: \Device\HarddiskVolume5\xampp\mysql\bin\mysqld.exe, EstimatedImpact: 0% 2026-08-21T21:16:38.337 ProcessImageName: Integrator.exe, Pid: 7312, TotalTime: 2551, Count: 246, MaxTime: 31, MaxTimeFile: \Device\HarddiskVolume3\Program Files\Microsoft Office\root\Integration\C2RManifest.Project.Project.x-none.msi.16.x-none.xml, EstimatedImpact: 12% 2026-08-21T21:16:38.337 ProcessImageName: DeviceCensus.exe, Pid: 8048, TotalTime: 2450, Count: 6, MaxTime: 1218, MaxTimeFile: \Device\Harddisk2\DR2, EstimatedImpact: 41% 2026-08-21T21:16:38.337 ProcessImageName: notepad++.exe, Pid: 6108, TotalTime: 2294, Count: 148, MaxTime: 187, MaxTimeFile: \Device\HarddiskVolume3\Users\ITHAN\AppData\Roaming\Notepad++\langs.xml, EstimatedImpact: 1% 2026-08-21T21:16:38.450 [Engine] RSIG_UNLOADENGINE, 00007FFB7F3055E0, err=0x0 2026-08-21T21:16:38.470 [Engine] C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8E8BD9F9-3D12-43B9-B94A-2DF744B2AFE7} removed 2026-08-21T21:16:39.558 IWscAVStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T21:16:39.569 IWscAVStatus4: 1, 1, 1. hr = 0x0 2026-08-21T21:16:39.571 IWscASStatus::UpdateStatus() succceeded writing instance with state (0), snooze state (0), and up-to-date state(1) 2026-08-21T21:16:41.498 Engine:Setting original file name "tv_x64.exe" for "\\?\c:\program files\teamviewer\tv_w32.exe", hr=0x800710da 2026-08-21T21:17:02.442 Process scan (postsignatureupdatescan) completed. 2026-08-21T21:17:17.823 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T21:21:37.422 [RbM] Setting Last known good engine candidate. hr = 0 2026-08-21T21:22:19.509 [RTP] [Mini-filter] Unsuccessful scan status(#1): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #109326, FileId: 0x820000000150d1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:24:40.114 [RTP] [Mini-filter] Unsuccessful scan status(#2): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php736B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110502, FileId: 0x42000000037322, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:24:51.205 [RTP] [Mini-filter] Unsuccessful scan status(#3): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9EC3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110504, FileId: 0x44000000037322, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:25:40.528 [RTP] [Mini-filter] Unsuccessful scan status(#4): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php633F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110522, FileId: 0x49000000037322, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:25:46.010 [RTP] [Mini-filter] Unsuccessful scan status(#5): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php78BC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110525, FileId: 0x4a000000037322, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:25:53.962 [RTP] [Mini-filter] Unsuccessful scan status(#6): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php97BE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110528, FileId: 0x6600000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:25:55.410 [RTP] [Mini-filter] Unsuccessful scan status(#7): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9D7C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110530, FileId: 0x6700000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:25:56.813 [RTP] [Mini-filter] Unsuccessful scan status(#8): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA2EC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110532, FileId: 0x6800000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:04.915 [RTP] [Mini-filter] Unsuccessful scan status(#9): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpACFA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110557, FileId: 0x6a00000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:13.214 [RTP] [Mini-filter] Unsuccessful scan status(#10): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpCD64.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110559, FileId: 0x6b00000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:37.181 [RTP] [Mini-filter] Unsuccessful scan status(#11): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2B06.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110561, FileId: 0x6c00000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:43.321 [RTP] [Mini-filter] Unsuccessful scan status(#12): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php42F6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110564, FileId: 0x6f00000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:46.798 [RTP] [Mini-filter] Unsuccessful scan status(#13): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5095.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110567, FileId: 0x7200000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:50.645 [RTP] [Mini-filter] Unsuccessful scan status(#14): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5F9C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110570, FileId: 0x7500000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:55.395 [RTP] [Mini-filter] Unsuccessful scan status(#15): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php722D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110573, FileId: 0x260000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:27:58.047 [RTP] [Mini-filter] Unsuccessful scan status(#16): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7C8E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110575, FileId: 0x270000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:28:42.521 [RTP] [Mini-filter] Unsuccessful scan status(#17): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2A44.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110577, FileId: 0x280000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:28:42.820 [RTP] [Mini-filter] Unsuccessful scan status(#18): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2B6E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110579, FileId: 0x290000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:28:45.462 [RTP] [Mini-filter] Unsuccessful scan status(#19): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php35BF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110580, FileId: 0x2a0000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:29:28.106 [RTP] [Mini-filter] Unsuccessful scan status(#20): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDC61.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110582, FileId: 0x2b0000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:29:28.470 [RTP] [Mini-filter] Unsuccessful scan status(#21): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDDD9.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110584, FileId: 0x2c0000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:29:32.203 [RTP] [Mini-filter] Unsuccessful scan status(#22): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEC60.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110586, FileId: 0x2d0000000358a2, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:29:51.649 [RTP] [Mini-filter] Unsuccessful scan status(#23): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php385E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #110588, FileId: 0x4f00000003732d, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:31:05.280 [RTP] [Mini-filter] Unsuccessful scan status(#24): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php57F8.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111268, FileId: 0x3600000003742b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:08.574 [RTP] [Mini-filter] Unsuccessful scan status(#25): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4F3A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111281, FileId: 0x58000000037284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:16.529 [RTP] [Mini-filter] Unsuccessful scan status(#26): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php6E4C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111283, FileId: 0x1de000000001c1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:19.299 [RTP] [Mini-filter] Unsuccessful scan status(#27): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php791B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111285, FileId: 0x1df000000001c1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:21.845 [RTP] [Mini-filter] Unsuccessful scan status(#28): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php830F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111287, FileId: 0x1e0000000001c1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:22.816 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T21:32:22.870 [RTP] [Mini-filter] Unsuccessful scan status(#29): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8708.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111289, FileId: 0x1e1000000001c1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:32:28.323 [RTP] [Mini-filter] Unsuccessful scan status(#30): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9C65.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111291, FileId: 0x1e2000000001c1a, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:38:00.669 [RTP] [Mini-filter] Unsuccessful scan status(#31): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpAEAE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111565, FileId: 0x18000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:38:09.310 [RTP] [Mini-filter] Unsuccessful scan status(#32): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD060.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111571, FileId: 0x19000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:38:11.627 [RTP] [Mini-filter] Unsuccessful scan status(#33): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD979.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111573, FileId: 0x1a000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:38:59.444 [RTP] [Mini-filter] Unsuccessful scan status(#34): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9450.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111593, FileId: 0x4700000000310c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:39:47.540 [RTP] [Mini-filter] Unsuccessful scan status(#35): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php500F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111596, FileId: 0xc8000000004c03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:39:50.214 [RTP] [Mini-filter] Unsuccessful scan status(#36): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5A90.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111598, FileId: 0xc9000000004c03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:39:56.228 [RTP] [Mini-filter] Unsuccessful scan status(#37): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7211.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111601, FileId: 0xca000000004c03, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:42:01.968 [RTP] [Mini-filter] Unsuccessful scan status(#38): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5D38.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111667, FileId: 0x1c000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:42:07.623 [RTP] [Mini-filter] Unsuccessful scan status(#39): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7342.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111669, FileId: 0x7800000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:42:09.845 [RTP] [Mini-filter] Unsuccessful scan status(#40): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7C0D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111671, FileId: 0x7900000000a7c3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:47:27.812 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T21:51:42.436 [RTP] [Mini-filter] Unsuccessful scan status(#41): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php38BF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111779, FileId: 0x2a0000000358aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:51:50.121 [RTP] [Mini-filter] Unsuccessful scan status(#42): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php56CA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111782, FileId: 0x2d0000000358aa, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x148a175b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x394a5565 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8e6f0da8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa776049a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xed029a49 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x59f7bdc7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x73b50a7e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf0e3e0cc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdcccaacf Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa14cd24a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x52c686ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa5641ecc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x30dc5cf7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x62252621 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15d7d7e9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd8cead3a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053cb68f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x31b9a2ed Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc727532c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1889d781 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x08f2eca2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4946dce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x530923c0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae3a7a2c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfa02ab69 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4a37fceb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29370b66 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbce20cd1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe25bc992 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x72ba87b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x406004f0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2d238acd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb7971c0b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9cec7f26 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2b3abd23 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd4d785b8 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x76b6716e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc8ec92cb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7234158b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x891744e2 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x13addf41 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe8475d1d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0abbccb9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x00304122 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbab6af74 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0dbb21ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xba0a924d 2026-08-21T21:52:40.623 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T21:52:40.623 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T21:52:40.623 [Cloud] Queued cloud request. 2026-08-21T21:52:40.623 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T21:52:40.623 [Cloud] Dequeued cloud request. 2026-08-21T21:52:40.623 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T21:52:41.229 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e523fb027f06e77d831645c4459266928b4c5ac6 Dynamic Signature Compilation Timestamp:08-21-2026 21:52:41 Persistence Type:Duration Time remaining:288000000 2026-08-21T21:52:41.230 [Cloud] End of cloud request. 2026-08-21T21:52:41.230 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T21:52:41.749 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T21:52:42.364 [RTP] [Mini-filter] Unsuccessful scan status(#43): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php226B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111926, FileId: 0x2e00000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:52:44.403 [RTP] [Mini-filter] Unsuccessful scan status(#44): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2A5B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111928, FileId: 0x2f00000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:52:52.895 [RTP] [Mini-filter] Unsuccessful scan status(#45): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4B92.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #111997, FileId: 0x3200000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:52:57.495 [RTP] [Mini-filter] Unsuccessful scan status(#46): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5D87.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112000, FileId: 0x3500000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:52:59.250 [RTP] [Mini-filter] Unsuccessful scan status(#47): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php647D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112002, FileId: 0x3600000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:53:02.252 [RTP] [Mini-filter] Unsuccessful scan status(#48): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7008.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112008, FileId: 0x3700000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:53:05.942 [RTP] [Mini-filter] Unsuccessful scan status(#49): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7E8F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112010, FileId: 0x3800000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:53:09.286 [RTP] [Mini-filter] Unsuccessful scan status(#50): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php8BA0.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112012, FileId: 0x3900000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:53:11.520 [RTP] [Mini-filter] Unsuccessful scan status(#51): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php946B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112014, FileId: 0x3a00000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:53:14.131 [RTP] [Mini-filter] Unsuccessful scan status(#52): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php9E8E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112016, FileId: 0x3b00000003749b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:54:25.341 [RTP] [Mini-filter] Unsuccessful scan status(#53): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpB4CA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112041, FileId: 0x46000000036cd3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:56:23.292 [RTP] [Mini-filter] Unsuccessful scan status(#54): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php816C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112120, FileId: 0x1f000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:09.658 [RTP] [Mini-filter] Unsuccessful scan status(#55): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3694.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112122, FileId: 0x20000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:10.018 [RTP] [Mini-filter] Unsuccessful scan status(#56): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php380C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112124, FileId: 0x21000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.259 [RTP] [Mini-filter] Unsuccessful scan status(#57): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4888.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112125, FileId: 0x22000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.448 [RTP] [Mini-filter] Unsuccessful scan status(#58): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4954.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112127, FileId: 0x23000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.651 [RTP] [Mini-filter] Unsuccessful scan status(#59): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A30.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112128, FileId: 0x24000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.744 [RTP] [Mini-filter] Unsuccessful scan status(#60): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A8F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112129, FileId: 0x25000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.862 [RTP] [Mini-filter] Unsuccessful scan status(#61): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4AFD.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112130, FileId: 0x26000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:14.955 [RTP] [Mini-filter] Unsuccessful scan status(#62): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4B5C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112131, FileId: 0x27000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.043 [RTP] [Mini-filter] Unsuccessful scan status(#63): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4BBB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112132, FileId: 0x28000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.151 [RTP] [Mini-filter] Unsuccessful scan status(#64): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4C19.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112133, FileId: 0x29000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.293 [RTP] [Mini-filter] Unsuccessful scan status(#65): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4C97.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112135, FileId: 0x2a000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.399 [RTP] [Mini-filter] Unsuccessful scan status(#66): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4D25.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112136, FileId: 0x2b000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.495 [RTP] [Mini-filter] Unsuccessful scan status(#67): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4D84.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112137, FileId: 0x2c000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.583 [RTP] [Mini-filter] Unsuccessful scan status(#68): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4DC3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112138, FileId: 0x2d000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.673 [RTP] [Mini-filter] Unsuccessful scan status(#69): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4E32.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112139, FileId: 0x2e000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.783 [RTP] [Mini-filter] Unsuccessful scan status(#70): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4E90.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112140, FileId: 0x2f000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:15.898 [RTP] [Mini-filter] Unsuccessful scan status(#71): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4EFF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112141, FileId: 0x30000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:16.005 [RTP] [Mini-filter] Unsuccessful scan status(#72): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4F8C.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112142, FileId: 0x31000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:16.109 [RTP] [Mini-filter] Unsuccessful scan status(#73): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4FDC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112143, FileId: 0x32000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:16.191 [RTP] [Mini-filter] Unsuccessful scan status(#74): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php504A.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112145, FileId: 0x33000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:16.298 [RTP] [Mini-filter] Unsuccessful scan status(#75): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5099.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112146, FileId: 0x34000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:17.752 [RTP] [Mini-filter] Unsuccessful scan status(#76): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5647.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112147, FileId: 0x35000000032ede, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T21:57:58.691 [RTP] [Mini-filter] First scan on a volume: \Device\HarddiskVolume6\System Volume Information\WPSettings.dat 2026-08-21T21:57:58.691 [RTP] 2 newly mounted volumes accumulated, forcing a config update ... 2026-08-21T21:57:58.691 [RTP] Duplicating the current plugin configuration object... 2026-08-21T21:57:58.691 [RTP] CCMPluginConfiguration::Duplicate() - no GenerateEngineEngineConfigStruct ... 2026-08-21T21:57:58.691 [RTP] Updating plugin configuration due to recent config changes (0x1) ... 2026-08-21T21:57:58.691 [RTP] Calling GenerateEngineConfigStruct (0) ... 2026-08-21T21:57:58.691 [RTP] RefreshPluginConfiguration completed successfully. Requested: 0x1, Changed: 0x200 2026-08-21T21:58:01.790 [RTP] [Mini-filter] Unsuccessful scan status(#77): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php257.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #112170, FileId: 0x48000000037497, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:02:32.819 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T22:03:12.650 [RTP] [Mini-filter] Unsuccessful scan status(#78): \Device\HarddiskVolume3\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db-wal. Process: \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, Status: 0xc0000001, State: 0, ScanRequest #113179, FileId: 0x15000000036bc4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2507f149 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xae06ad55 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0c4c2f76 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x0c4c2f76 2026-08-21T22:04:25.667 [RTP] [Mini-filter] Unsuccessful scan status(#79): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDDEB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113427, FileId: 0x3400000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:25.959 [RTP] [Mini-filter] Unsuccessful scan status(#80): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDF05.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113432, FileId: 0x3500000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.087 [RTP] [Mini-filter] Unsuccessful scan status(#81): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDF83.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113435, FileId: 0x3600000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.182 [RTP] [Mini-filter] Unsuccessful scan status(#82): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpDFF1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113437, FileId: 0x3700000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.265 [RTP] [Mini-filter] Unsuccessful scan status(#83): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE031.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113439, FileId: 0x3800000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.357 [RTP] [Mini-filter] Unsuccessful scan status(#84): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE090.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113440, FileId: 0x3900000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.449 [RTP] [Mini-filter] Unsuccessful scan status(#85): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE0FE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113443, FileId: 0x3a00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.527 [RTP] [Mini-filter] Unsuccessful scan status(#86): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE14D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113444, FileId: 0x3b00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.652 [RTP] [Mini-filter] Unsuccessful scan status(#87): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE1AC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113446, FileId: 0x3c00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.872 [RTP] [Mini-filter] Unsuccessful scan status(#88): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE268.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113449, FileId: 0x3d00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:26.997 [RTP] [Mini-filter] Unsuccessful scan status(#89): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE325.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113454, FileId: 0x3e00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.123 [RTP] [Mini-filter] Unsuccessful scan status(#90): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE3A3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113459, FileId: 0x3f00000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.230 [RTP] [Mini-filter] Unsuccessful scan status(#91): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE402.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113461, FileId: 0x4000000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.369 [RTP] [Mini-filter] Unsuccessful scan status(#92): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE480.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113462, FileId: 0x4100000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.503 [RTP] [Mini-filter] Unsuccessful scan status(#93): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE51D.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113467, FileId: 0x4200000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.619 [RTP] [Mini-filter] Unsuccessful scan status(#94): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE58B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113472, FileId: 0x4300000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.808 [RTP] [Mini-filter] Unsuccessful scan status(#95): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE628.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113476, FileId: 0x4400000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:27.937 [RTP] [Mini-filter] Unsuccessful scan status(#96): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE6C6.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113483, FileId: 0x4500000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:28.040 [RTP] [Mini-filter] Unsuccessful scan status(#97): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE734.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113490, FileId: 0x4600000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:04:28.808 [RTP] [Mini-filter] Unsuccessful scan status(#98): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpEA33.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #113514, FileId: 0x4700000003749f, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9637729e 2026-08-21T22:05:04.892 [RTP] [Mini-filter] Unsuccessful scan status(#99): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php7731.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #114174, FileId: 0x5c0000000374a3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:05:08.849 [RTP] [Mini-filter] Unsuccessful scan status(#100): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php86B3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #114319, FileId: 0x5d0000000374a3, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x0000157E437254D1, sigsha=1890106486153e15a5f6cf75dc244a4840e483e1, cached=false, source=2, resourceid=0x8e1369c1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x03bda170 Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0x5bfbd454 2026-08-21T22:05:41.661 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:05:41.661 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:05:41.661 [Cloud] Queued cloud request. 2026-08-21T22:05:41.661 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:05:41.661 [Cloud] Dequeued cloud request. 2026-08-21T22:05:41.661 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:05:41.846 [Cloud] End of cloud request. 2026-08-21T22:05:41.846 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3\webinterface\benutzerBearbeiten\benutzerAendernDurchfuehren.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df Internal signature match:subtype=Lowfi, sigseq=0x00001B29DE1959DF, sigsha=69447b0b4ef658b9400ed851202a64ef6290469c, cached=false, source=2, resourceid=0xcd225076 2026-08-21T22:05:42.137 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:05:42.138 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:05:42.138 [Cloud] Queued cloud request. 2026-08-21T22:05:42.138 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:05:42.138 [Cloud] Dequeued cloud request. 2026-08-21T22:05:42.138 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:05:42.181 [Cloud] End of cloud request. 2026-08-21T22:05:42.181 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\rezervi3\webinterface\benutzerBearbeiten\benutzerEintragen.php. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x1b29de1959df 2026-08-21T22:05:42.370 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:17:37.807 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x0000157E3AD2FCEB, sigsha=3770decc51672ac33595d86ef32b29601703be6e, cached=false, source=2, resourceid=0x947711e0 Internal signature match:subtype=Lowfi, sigseq=0x0000157E602E328E, sigsha=39d1b12b926bc36ca502bb9a629356b2fea736cd, cached=false, source=2, resourceid=0x947711e0 2026-08-21T22:18:40.879 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:18:40.879 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:18:40.879 [Cloud] Queued cloud request. 2026-08-21T22:18:40.879 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:18:40.879 [Cloud] Dequeued cloud request. 2026-08-21T22:18:40.879 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:18:41.485 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e459c5b181065a160002af341abf4f31f4072389 Dynamic Signature Compilation Timestamp:08-21-2026 22:18:41 Persistence Type:Duration Time remaining:288000000 2026-08-21T22:18:41.486 [Cloud] End of cloud request. 2026-08-21T22:18:41.486 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:18:41.998 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcfe013b9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbde0966d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x002f32c3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9d20d3b5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6d0afce Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x47bd562a Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3775e98d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc88d2ebd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0773e94c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe578f716 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x053b9c6d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5af8ee84 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7e779722 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xedf5605b 2026-08-21T22:21:08.719 [RTP] [Mini-filter] Unsuccessful scan status(#110): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php2C31.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117464, FileId: 0x25000000038bc6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:21:09.856 [RTP] [Mini-filter] Unsuccessful scan status(#120): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php30BF.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117477, FileId: 0x2f000000038bc6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:27:06.683 [RTP] [Mini-filter] Unsuccessful scan status(#130): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA286.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117753, FileId: 0x4f00000000310c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:27:08.352 [RTP] [Mini-filter] Unsuccessful scan status(#140): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA918.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117784, FileId: 0x5900000000310c, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:28:07.624 [RTP] [Mini-filter] Unsuccessful scan status(#150): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php90B3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117831, FileId: 0x60000000037284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:28:50.418 [RTP] [Mini-filter] Unsuccessful scan status(#160): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php37DA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117884, FileId: 0x6a000000037284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:28:51.543 [RTP] [Mini-filter] Unsuccessful scan status(#170): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php3C59.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #117905, FileId: 0x74000000037284, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:30:20.500 [RTP] [Mini-filter] Unsuccessful scan status(#180): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php97CC.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #118003, FileId: 0x4200000000d825, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:32:30.897 [RTP] [Mini-filter] Unsuccessful scan status(#190): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php954B.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #118485, FileId: 0x320000000372f6, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:32:42.815 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T22:39:53.503 [RTP] [Mini-filter] Unsuccessful scan status(#200): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5627.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #119275, FileId: 0x32000000038142, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:47:47.814 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8890ce2e 2026-08-21T22:51:30.156 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:51:30.156 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:51:30.156 [Cloud] Queued cloud request. 2026-08-21T22:51:30.157 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:51:30.157 [Cloud] Dequeued cloud request. 2026-08-21T22:51:30.157 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:51:30.556 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\59bb867a75336a0d2a3a668a67e7df16cd39ee3a Dynamic Signature Compilation Timestamp:08-21-2026 22:51:30 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:51:30.557 [Cloud] End of cloud request. 2026-08-21T22:51:30.557 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:51:31.081 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x133955c7 2026-08-21T22:52:18.386 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:18.386 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:18.386 [Cloud] Queued cloud request. 2026-08-21T22:52:18.386 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:18.386 [Cloud] Dequeued cloud request. 2026-08-21T22:52:18.387 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:18.757 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\61fac8819dcac3eae46c54686f87114f03667e68 Dynamic Signature Compilation Timestamp:08-21-2026 22:52:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:18.758 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:18.758 [Cloud] End of cloud request. 2026-08-21T22:52:19.274 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcc7eafc9 2026-08-21T22:52:21.830 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:21.830 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:21.830 [Cloud] Queued cloud request. 2026-08-21T22:52:21.830 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:21.830 [Cloud] Dequeued cloud request. 2026-08-21T22:52:21.830 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:22.323 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\18114ac20df68eca8cab4728f21eaca2e584991b Dynamic Signature Compilation Timestamp:08-21-2026 22:52:22 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:22.324 [Cloud] End of cloud request. 2026-08-21T22:52:22.324 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:22.846 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x612bd000 2026-08-21T22:52:23.374 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:23.374 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:23.374 [Cloud] Queued cloud request. 2026-08-21T22:52:23.374 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:23.374 [Cloud] Dequeued cloud request. 2026-08-21T22:52:23.375 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:23.606 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae9183bcc3247d11cd11937a2c0d0df0ff99cfe9 Dynamic Signature Compilation Timestamp:08-21-2026 22:52:23 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:23.607 [Cloud] End of cloud request. 2026-08-21T22:52:23.607 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:24.132 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x290aa726 2026-08-21T22:52:30.270 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:30.270 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:30.270 [Cloud] Queued cloud request. 2026-08-21T22:52:30.270 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:30.270 [Cloud] Dequeued cloud request. 2026-08-21T22:52:30.270 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:30.973 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\00f61c4655d833e7a66bac56daacf1ed13d47802 Dynamic Signature Compilation Timestamp:08-21-2026 22:52:31 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:30.974 [Cloud] End of cloud request. 2026-08-21T22:52:30.974 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:31.487 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3fffbe02 2026-08-21T22:52:41.272 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:41.272 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:41.273 [Cloud] Queued cloud request. 2026-08-21T22:52:41.273 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:41.273 [Cloud] Dequeued cloud request. 2026-08-21T22:52:41.273 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:41.696 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7f29540e3d001355f2c7aa78acdbf39dfab99c1a Dynamic Signature Compilation Timestamp:08-21-2026 22:52:41 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:41.697 [Cloud] End of cloud request. 2026-08-21T22:52:41.697 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:42.209 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xeab99d94 2026-08-21T22:52:44.119 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:52:44.120 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:52:44.120 [Cloud] Queued cloud request. 2026-08-21T22:52:44.120 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:52:44.120 [Cloud] Dequeued cloud request. 2026-08-21T22:52:44.120 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:52:44.435 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\271730915362f4beb6e1c9893d1e31cd9d56253d Dynamic Signature Compilation Timestamp:08-21-2026 22:52:44 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:52:44.436 [Cloud] End of cloud request. 2026-08-21T22:52:44.436 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:52:44.951 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x849e23fb 2026-08-21T22:53:06.876 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:06.876 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:06.876 [Cloud] Queued cloud request. 2026-08-21T22:53:06.876 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:06.876 [Cloud] Dequeued cloud request. 2026-08-21T22:53:06.877 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:53:07.166 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1784790e505e05d8af7739411b1531ccc1db115d Dynamic Signature Compilation Timestamp:08-21-2026 22:53:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:53:07.167 [Cloud] End of cloud request. 2026-08-21T22:53:07.167 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:53:07.684 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9de1bcd2 2026-08-21T22:53:10.323 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:10.323 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:10.323 [Cloud] Queued cloud request. 2026-08-21T22:53:10.323 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:10.323 [Cloud] Dequeued cloud request. 2026-08-21T22:53:10.324 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd56390a6 2026-08-21T22:53:14.621 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:14.621 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:14.621 [Cloud] Queued cloud request. 2026-08-21T22:53:14.621 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:14.622 [Cloud] Dequeued cloud request. 2026-08-21T22:53:14.622 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f0acca1ddd460ed3b7137f4000c879bc925d9654 Dynamic Signature Compilation Timestamp:08-21-2026 22:53:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:53:15.036 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:53:15.042 [Cloud] End of cloud request. 2026-08-21T22:53:15.042 Dynamic signature received 2026-08-21T22:53:15.519 Bm signature throttled:0x00002db31bed458f 2026-08-21T22:53:15.572 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb29e5870 2026-08-21T22:53:16.365 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:16.365 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:16.365 [Cloud] Queued cloud request. 2026-08-21T22:53:16.365 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:16.369 [Cloud] Dequeued cloud request. 2026-08-21T22:53:16.397 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e0215bcf296153546938257f14242eb98a43ce11 Dynamic Signature Compilation Timestamp:08-21-2026 22:53:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:53:16.698 Dynamic signature received 2026-08-21T22:53:16.698 [Cloud] End of cloud request. 2026-08-21T22:53:16.698 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:53:17.230 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:53:20.338 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\apache\modules\mod_alias.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:53:20.361 [Cloud] End of cloud request. 2026-08-21T22:53:20.875 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:53:34.298 Engine:Setting original file name "powershell.exe" for "h:\windows\system32\windowspowershell\v1.0\powershell.exe", hr=0x800710da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xff3fbf50 2026-08-21T22:53:38.470 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:38.470 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:38.470 [Cloud] Queued cloud request. 2026-08-21T22:53:38.470 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:38.470 [Cloud] Dequeued cloud request. 2026-08-21T22:53:38.471 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:53:38.687 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f3d90e85dcb390c07e488957073dce677180e179 Dynamic Signature Compilation Timestamp:08-21-2026 22:53:38 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:53:38.689 [Cloud] End of cloud request. 2026-08-21T22:53:38.689 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdfd7c733 2026-08-21T22:53:39.011 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:53:39.011 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:53:39.011 [Cloud] Queued cloud request. 2026-08-21T22:53:39.011 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:53:39.011 [Cloud] Dequeued cloud request. 2026-08-21T22:53:39.012 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:53:39.212 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:53:39.289 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cef133aaf679e33e335d069315f06f8d5a3bbf88 Dynamic Signature Compilation Timestamp:08-21-2026 22:53:39 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:53:39.290 [Cloud] End of cloud request. 2026-08-21T22:53:39.290 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:53:39.812 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x63b0d5e2 2026-08-21T22:54:10.870 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:10.871 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:10.871 [Cloud] Queued cloud request. 2026-08-21T22:54:10.871 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:10.872 [Cloud] Dequeued cloud request. 2026-08-21T22:54:10.872 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:11.070 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a2d6d1338a020238f899ec56ef3e86e635ad9401 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:11 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:11.071 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:11.071 [Cloud] End of cloud request. 2026-08-21T22:54:11.588 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x383b60a1 2026-08-21T22:54:32.225 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:32.225 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:32.225 [Cloud] Queued cloud request. 2026-08-21T22:54:32.225 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:32.225 [Cloud] Dequeued cloud request. 2026-08-21T22:54:32.225 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:32.589 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\49646114ed7ea4fd31e933a482c2ec9dd6b60d50 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:32 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:32.591 [Cloud] End of cloud request. 2026-08-21T22:54:32.591 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3cd1218f 2026-08-21T22:54:32.981 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:32.981 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:32.981 [Cloud] Queued cloud request. 2026-08-21T22:54:32.981 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:32.982 [Cloud] Dequeued cloud request. 2026-08-21T22:54:32.982 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:33.111 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:54:33.237 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b611e616e662abd431ba11108e9c6be5df4a1206 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:33 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:33.238 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:33.238 [Cloud] End of cloud request. 2026-08-21T22:54:33.752 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xda5660a5 2026-08-21T22:54:34.210 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:34.210 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:34.210 [Cloud] Queued cloud request. 2026-08-21T22:54:34.210 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:34.210 [Cloud] Dequeued cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6c97c217 2026-08-21T22:54:34.210 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:34.240 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:34.240 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:34.240 [Cloud] Queued cloud request. 2026-08-21T22:54:34.240 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:34.240 [Cloud] Dequeued cloud request. 2026-08-21T22:54:34.241 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:34.436 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a3a15f9e199bd33c6b9415eeee928a643a2019ef Dynamic Signature Compilation Timestamp:08-21-2026 22:54:34 Persistence Type:Duration Time remaining:50065408 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ebd04039be4f556cf30ea7ef6d2e55699ad4281c Dynamic Signature Compilation Timestamp:08-21-2026 22:54:34 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:34.437 Dynamic signature received 2026-08-21T22:54:34.437 [Cloud] End of cloud request. 2026-08-21T22:54:34.437 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:34.438 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:34.438 [Cloud] End of cloud request. 2026-08-21T22:54:34.955 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:54:40.812 [RTP] [Mini-filter] Unsuccessful scan status(#210): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #122373, FileId: 0x23000000039fa4, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:54:41.395 [RTP] [Mini-filter] Unsuccessful scan status(#220): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #122420, FileId: 0x2f000000039f9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:54:42.051 [RTP] [Mini-filter] Unsuccessful scan status(#230): \Device\HarddiskVolume3\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\CA9422711AE1A81C\backgroundupdate\datareporting\glean\db\data.safe.tmp. Process: \Device\HarddiskVolume3\Program Files\Firefox Developer Edition\firefox.exe, Status: 0xc0000001, State: 0, ScanRequest #122491, FileId: 0x3e000000039f9b, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x2020, ScanAttributes:0x10, AccessStateFlags:0x801, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x838a4ff4 Internal signature match:subtype=Lowfi, sigseq=0x0000157EB1025588, sigsha=9018bbb70a44f45fc8d654e776a41d5e4c19de15, cached=false, source=2, resourceid=0x94814b90 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1768a4c2 2026-08-21T22:54:44.957 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:44.957 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:44.957 [Cloud] Queued cloud request. 2026-08-21T22:54:44.957 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:44.957 [Cloud] Dequeued cloud request. 2026-08-21T22:54:44.957 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:45.179 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a1f1a4a215316f8c7e590b8348d51999173c8c8d Dynamic Signature Compilation Timestamp:08-21-2026 22:54:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:45.180 [Cloud] End of cloud request. 2026-08-21T22:54:45.180 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9942ce4 2026-08-21T22:54:45.322 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:45.322 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:45.322 [Cloud] Queued cloud request. 2026-08-21T22:54:45.322 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:45.322 [Cloud] Dequeued cloud request. 2026-08-21T22:54:45.322 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:45.694 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:54:45.697 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82452d0ab1de4e5633428830f1bf71c644b2c726 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:45 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:45.699 [Cloud] End of cloud request. 2026-08-21T22:54:45.699 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:46.216 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfaffd6de 2026-08-21T22:54:47.319 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:47.319 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:47.319 [Cloud] Queued cloud request. 2026-08-21T22:54:47.319 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:47.319 [Cloud] Dequeued cloud request. 2026-08-21T22:54:47.319 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:47.698 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b4ed2aefd55f3ea30f4f17ca6b96f8bbe7162489 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:47.699 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:47.699 [Cloud] End of cloud request. 2026-08-21T22:54:48.211 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd11e8782 2026-08-21T22:54:48.492 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:48.492 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:48.492 [Cloud] Queued cloud request. 2026-08-21T22:54:48.492 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:48.492 [Cloud] Dequeued cloud request. 2026-08-21T22:54:48.492 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:48.747 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\180c5a1e2187a232ac82d5657060b20105815e71 Dynamic Signature Compilation Timestamp:08-21-2026 22:54:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:48.748 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:48.748 [Cloud] End of cloud request. 2026-08-21T22:54:49.260 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe1830e2f 2026-08-21T22:54:58.444 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:54:58.444 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:54:58.444 [Cloud] Queued cloud request. 2026-08-21T22:54:58.444 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:54:58.444 [Cloud] Dequeued cloud request. 2026-08-21T22:54:58.444 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:54:58.873 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3fe630aa96efb946576c2165d6f23083bd6366de Dynamic Signature Compilation Timestamp:08-21-2026 22:54:58 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:54:58.874 [Cloud] End of cloud request. 2026-08-21T22:54:58.874 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:54:59.393 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000157EAFC2B838, sigsha=ef600f76a8e9dcce34454b1e4fda122185095fe4, cached=false, source=2, resourceid=0xb785cb3e Internal signature match:subtype=Lowfi, sigseq=0x0000157ED01FA601, sigsha=fdc6b8d4215e1e59a08ee3f4793e98a74459e01f, cached=false, source=2, resourceid=0xb785cb3e Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd008eed1 2026-08-21T22:55:34.997 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:34.997 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:34.997 [Cloud] Queued cloud request. 2026-08-21T22:55:34.997 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:34.997 [Cloud] Dequeued cloud request. 2026-08-21T22:55:34.998 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:55:35.282 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\8009a9528118c0a2ee408adfa343c26716092ff6 Dynamic Signature Compilation Timestamp:08-21-2026 22:55:35 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:55:35.283 [Cloud] End of cloud request. 2026-08-21T22:55:35.283 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:55:35.796 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb1849d19 2026-08-21T22:55:47.500 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:47.500 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:47.500 [Cloud] Queued cloud request. 2026-08-21T22:55:47.500 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:47.500 [Cloud] Dequeued cloud request. 2026-08-21T22:55:47.501 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\39acd0826c50a9b0417e35add15fe9767ca067a7 Dynamic Signature Compilation Timestamp:08-21-2026 22:55:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:55:47.739 [Cloud] End of cloud request. 2026-08-21T22:55:47.739 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:55:47.742 Dynamic signature received 2026-08-21T22:55:48.269 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0de07c78 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5a2ec9ff 2026-08-21T22:55:54.509 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:54.509 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:54.509 [Cloud] Queued cloud request. 2026-08-21T22:55:54.509 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:54.509 [Cloud] Dequeued cloud request. 2026-08-21T22:55:54.509 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x84cb536f 2026-08-21T22:55:54.613 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:54.613 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:54.613 [Cloud] Queued cloud request. 2026-08-21T22:55:54.613 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:54.613 [Cloud] Dequeued cloud request. 2026-08-21T22:55:54.613 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\52c53647be64e6a376ef57dfa6a2e8da5ac50378 Dynamic Signature Compilation Timestamp:08-21-2026 22:55:54 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:55:54.764 Dynamic signature received 2026-08-21T22:55:54.765 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:55:54.765 [Cloud] End of cloud request. 2026-08-21T22:55:55.276 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe5d46892 2026-08-21T22:55:55.915 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:55.915 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:55.915 [Cloud] Queued cloud request. 2026-08-21T22:55:55.915 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:55.915 [Cloud] Dequeued cloud request. 2026-08-21T22:55:55.915 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cc955a5643db8a71df2d74848788b945e30921ca Dynamic Signature Compilation Timestamp:08-21-2026 22:55:56 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:55:56.258 Dynamic signature received 2026-08-21T22:55:56.259 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:55:56.260 [Cloud] End of cloud request. 2026-08-21T22:55:56.780 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x39da0735 2026-08-21T22:55:57.681 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:55:57.681 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:55:57.681 [Cloud] Queued cloud request. 2026-08-21T22:55:57.681 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:55:57.681 [Cloud] Dequeued cloud request. 2026-08-21T22:55:57.681 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:55:58.137 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3ba3b4bd9c9b1289d71d7341017ad9d3a5919962 Dynamic Signature Compilation Timestamp:08-21-2026 22:55:58 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:55:58.137 [Cloud] End of cloud request. 2026-08-21T22:55:58.137 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:55:58.660 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf69a5f24 2026-08-21T22:56:00.396 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:00.396 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:00.396 [Cloud] Queued cloud request. 2026-08-21T22:56:00.396 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:00.396 [Cloud] Dequeued cloud request. 2026-08-21T22:56:00.396 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x68b905d7 2026-08-21T22:56:02.232 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:02.232 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:02.232 [Cloud] Queued cloud request. 2026-08-21T22:56:02.232 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:02.232 [Cloud] Dequeued cloud request. 2026-08-21T22:56:02.233 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:02.547 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fa0b51bb1fb2f4ffcfcd1c1808af25b866e07e95 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:02 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:02.548 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:02.549 [Cloud] End of cloud request. 2026-08-21T22:56:03.071 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:03.831 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f18d6bc4f2fd31f271dead06c4ffc7fd782003db Dynamic Signature Compilation Timestamp:08-21-2026 22:56:03 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:03.832 [Cloud] End of cloud request. 2026-08-21T22:56:03.832 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:04.356 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:04.625 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\apache\modules\mod_session_cookie.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:56:04.655 [Cloud] End of cloud request. 2026-08-21T22:56:05.177 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcf5c0135 2026-08-21T22:56:05.718 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:05.718 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:05.718 [Cloud] Queued cloud request. 2026-08-21T22:56:05.718 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:05.718 [Cloud] Dequeued cloud request. 2026-08-21T22:56:05.719 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:05.954 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e315cfba3a801d0d48c6d05dd53714f4758f6591 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:06 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:05.955 [Cloud] End of cloud request. 2026-08-21T22:56:05.955 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:06.466 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0d1d5f35 2026-08-21T22:56:08.408 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:08.408 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:08.408 [Cloud] Queued cloud request. 2026-08-21T22:56:08.408 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:08.408 [Cloud] Dequeued cloud request. 2026-08-21T22:56:08.408 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:08.760 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2ab46ead3997831ebaf39eadeb300e414826721f Dynamic Signature Compilation Timestamp:08-21-2026 22:56:08 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:56:08.761 [Cloud] End of cloud request. 2026-08-21T22:56:08.761 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:09.276 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:13.103 [RTP] [Mini-filter] Unsuccessful scan status(#240): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php48DA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123230, FileId: 0x1600000003a8c1, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:56:16.717 [RTP] [Mini-filter] Unsuccessful scan status(#250): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php56FE.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123253, FileId: 0xc1000000002f32, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:56:17.899 [RTP] [Mini-filter] Unsuccessful scan status(#260): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php5BAB.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123274, FileId: 0xa50000000075cc, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x24992611 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5579db6b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x42357c3b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x50b6cf2f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x411338da Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x933d95e8 2026-08-21T22:56:32.490 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:32.490 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:32.490 [Cloud] Queued cloud request. 2026-08-21T22:56:32.490 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:32.490 [Cloud] Dequeued cloud request. 2026-08-21T22:56:32.490 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:32.690 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\dd689c2e9c05a074cfe8a38d5ed7cabca58faf8a Dynamic Signature Compilation Timestamp:08-21-2026 22:56:32 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:32.691 [Cloud] End of cloud request. 2026-08-21T22:56:32.691 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:33.207 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x8de11cfd 2026-08-21T22:56:36.032 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:36.032 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:36.032 [Cloud] Queued cloud request. 2026-08-21T22:56:36.032 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:36.032 [Cloud] Dequeued cloud request. 2026-08-21T22:56:36.032 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:36.384 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\266d217caa47da9e51918acf175d20da274338e8 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:36 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:56:36.385 [Cloud] End of cloud request. 2026-08-21T22:56:36.385 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:36.906 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:37.178 [RTP] [Mini-filter] Unsuccessful scan status(#270): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA6F7.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123420, FileId: 0x1500000003a8d7, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4b0f1695 2026-08-21T22:56:39.946 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:39.946 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:39.946 [Cloud] Queued cloud request. 2026-08-21T22:56:39.946 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:39.946 [Cloud] Dequeued cloud request. 2026-08-21T22:56:39.946 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5a6901ab 2026-08-21T22:56:40.336 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:40.336 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:40.336 [Cloud] Queued cloud request. 2026-08-21T22:56:40.336 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:40.336 [Cloud] Dequeued cloud request. 2026-08-21T22:56:40.336 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:40.519 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9acef86db53486bf18d240f19afbe290aa0c3a6c Dynamic Signature Compilation Timestamp:08-21-2026 22:56:40 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:56:40.520 [Cloud] End of cloud request. 2026-08-21T22:56:40.520 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:40.670 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\029616d6bafc4f4ae4444747e89f9b27d484b0c7 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:40 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:40.671 [Cloud] End of cloud request. 2026-08-21T22:56:40.671 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5bd40fe8 2026-08-21T22:56:40.868 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:40.869 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:40.869 [Cloud] Queued cloud request. 2026-08-21T22:56:40.869 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:40.869 [Cloud] Dequeued cloud request. 2026-08-21T22:56:40.869 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:41.039 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c4b1ff9bd6b0971a3e35b24e5561c6dffa4a2189 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:41 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:41.090 Dynamic signature received 2026-08-21T22:56:41.090 [Cloud] End of cloud request. 2026-08-21T22:56:41.090 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:41.611 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1c818288 2026-08-21T22:56:42.707 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:42.707 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:42.707 [Cloud] Queued cloud request. 2026-08-21T22:56:42.707 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:42.707 [Cloud] Dequeued cloud request. 2026-08-21T22:56:42.707 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:43.029 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\602c81f52a20fdbeacca0e5f79c1e4a8b8e17210 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:43 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:43.030 [Cloud] End of cloud request. 2026-08-21T22:56:43.030 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:43.547 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe0c57da9 2026-08-21T22:56:45.897 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:45.897 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:45.897 [Cloud] Queued cloud request. 2026-08-21T22:56:45.897 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:45.898 [Cloud] Dequeued cloud request. 2026-08-21T22:56:45.898 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:46.125 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c39f6789376b09bd9072d2cac6e91148e216840f Dynamic Signature Compilation Timestamp:08-21-2026 22:56:46 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:46.125 [Cloud] End of cloud request. 2026-08-21T22:56:46.125 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x162b573c 2026-08-21T22:56:46.631 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:46.631 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:46.631 [Cloud] Queued cloud request. 2026-08-21T22:56:46.631 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:46.631 [Cloud] Dequeued cloud request. 2026-08-21T22:56:46.631 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:46.640 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:47.799 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f4a002e3f6ddc80e223c1a97ea30475254c6c24b Dynamic Signature Compilation Timestamp:08-21-2026 22:56:47 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:47.800 [Cloud] End of cloud request. 2026-08-21T22:56:47.800 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfba2715c 2026-08-21T22:56:48.088 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:48.088 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:48.088 [Cloud] Queued cloud request. 2026-08-21T22:56:48.088 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:48.089 [Cloud] Dequeued cloud request. 2026-08-21T22:56:48.089 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:48.289 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\121a1470c5998a23067a42709c36df9cb974bd32 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:48.290 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:48.291 [Cloud] End of cloud request. 2026-08-21T22:56:48.320 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe3ffc57d 2026-08-21T22:56:48.716 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:48.716 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:48.716 [Cloud] Queued cloud request. 2026-08-21T22:56:48.716 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:48.716 [Cloud] Dequeued cloud request. 2026-08-21T22:56:48.716 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:48.900 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4870e9cc7bffc9c00b6776f3c5c04c75f8a33763 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:48.901 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:48.901 [Cloud] End of cloud request. 2026-08-21T22:56:49.168 [RTP] [Mini-filter] Unsuccessful scan status(#280): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpD5D1.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123538, FileId: 0x1a00000003aa14, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:56:49.426 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9140556 2026-08-21T22:56:49.683 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:49.683 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:49.683 [Cloud] Queued cloud request. 2026-08-21T22:56:49.683 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:49.683 [Cloud] Dequeued cloud request. 2026-08-21T22:56:49.683 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x055e921d 2026-08-21T22:56:51.634 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:51.634 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:51.634 [Cloud] Queued cloud request. 2026-08-21T22:56:51.634 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:51.634 [Cloud] Dequeued cloud request. 2026-08-21T22:56:51.634 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x14197fae 2026-08-21T22:56:53.048 [RTP] [Mini-filter] Unsuccessful scan status(#290): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE50E.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123591, FileId: 0x2400000003aa14, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 2026-08-21T22:56:53.074 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:53.075 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:53.075 [Cloud] Queued cloud request. 2026-08-21T22:56:53.075 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:53.075 [Cloud] Dequeued cloud request. 2026-08-21T22:56:53.075 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:53.255 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\779a241ea418ee67855dd7c94dcb40b8d4150132 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:53 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:53.257 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:53.257 [Cloud] End of cloud request. 2026-08-21T22:56:53.304 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e253b72c15e1c4da74db3991b6664ef95a0612d8 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:53 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:53.305 [Cloud] End of cloud request. 2026-08-21T22:56:53.305 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf11c2271 2026-08-21T22:56:53.570 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:53.570 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:53.570 [Cloud] Queued cloud request. 2026-08-21T22:56:53.570 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:53.570 [Cloud] Dequeued cloud request. 2026-08-21T22:56:53.571 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d69f99613bb60a3d278d32ef245ddc02cdc24ff5 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:53 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:53.771 Dynamic signature received 2026-08-21T22:56:53.771 [Cloud] End of cloud request. 2026-08-21T22:56:53.771 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:53.781 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:56:54.250 [RTP] [Mini-filter] Unsuccessful scan status(#300): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpE9DA.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #123621, FileId: 0x2500000003abee, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x15557b90 2026-08-21T22:56:56.924 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:56.924 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:56.924 [Cloud] Queued cloud request. 2026-08-21T22:56:56.924 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:56.924 [Cloud] Dequeued cloud request. 2026-08-21T22:56:56.925 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x100bbf9d 2026-08-21T22:56:57.538 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:57.538 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:57.539 [Cloud] Queued cloud request. 2026-08-21T22:56:57.539 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:57.539 [Cloud] Dequeued cloud request. 2026-08-21T22:56:57.539 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:57.754 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3459f5e45297c47ee39345b738159014bd58b78c Dynamic Signature Compilation Timestamp:08-21-2026 22:56:57 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:57.755 [Cloud] End of cloud request. 2026-08-21T22:56:57.755 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:58.271 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcb52be35 2026-08-21T22:56:58.539 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:58.539 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:58.539 [Cloud] Queued cloud request. 2026-08-21T22:56:58.539 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:58.539 [Cloud] Dequeued cloud request. 2026-08-21T22:56:58.539 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x236f22be 2026-08-21T22:56:58.714 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:58.714 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:58.714 [Cloud] Queued cloud request. 2026-08-21T22:56:58.714 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:58.714 [Cloud] Dequeued cloud request. 2026-08-21T22:56:58.714 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc9225445 2026-08-21T22:56:58.905 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:56:58.905 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:56:58.905 [Cloud] Queued cloud request. 2026-08-21T22:56:58.905 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:56:58.905 [Cloud] Dequeued cloud request. 2026-08-21T22:56:58.905 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:56:59.004 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c51a3999ae3d909405c7354b2f9c0f3715112e4c Dynamic Signature Compilation Timestamp:08-21-2026 22:56:59 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:59.005 [Cloud] End of cloud request. 2026-08-21T22:56:59.005 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:59.159 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\cb16aede4ebd093a5280dbc78bb2228922f078dc Dynamic Signature Compilation Timestamp:08-21-2026 22:56:59 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:59.160 [Cloud] End of cloud request. 2026-08-21T22:56:59.160 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:59.472 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\97b5e4169931187cd3a62fcd0cf46ad64a317236 Dynamic Signature Compilation Timestamp:08-21-2026 22:56:59 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:56:59.473 [Cloud] End of cloud request. 2026-08-21T22:56:59.473 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:56:59.526 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:01.640 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\apache\modules\mod_setenvif.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:57:01.677 [Cloud] End of cloud request. 2026-08-21T22:57:02.189 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:02.690 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e26b8b0e852d3e43551d751a4ef0e32dd7efa492 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:02 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:02.691 [Cloud] End of cloud request. 2026-08-21T22:57:02.691 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:03.201 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x93e3d568 2026-08-21T22:57:04.748 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:04.748 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:04.748 [Cloud] Queued cloud request. 2026-08-21T22:57:04.748 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:04.748 [Cloud] Dequeued cloud request. 2026-08-21T22:57:04.748 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:04.964 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9a4752d403446ca512d1534350847a0adb4e307e Dynamic Signature Compilation Timestamp:08-21-2026 22:57:05 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:04.965 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:04.965 [Cloud] End of cloud request. 2026-08-21T22:57:05.485 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcfa5edca Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2486ace4 2026-08-21T22:57:15.569 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:15.569 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:15.569 [Cloud] Queued cloud request. 2026-08-21T22:57:15.569 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:15.569 [Cloud] Dequeued cloud request. 2026-08-21T22:57:15.569 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbc3c9a04 2026-08-21T22:57:15.721 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:15.721 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:15.721 [Cloud] Queued cloud request. 2026-08-21T22:57:15.721 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:15.722 [Cloud] Dequeued cloud request. 2026-08-21T22:57:15.722 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:15.913 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\6e21533259887741f52d3d64ae6a204357011d43 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:15.914 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:15.915 [Cloud] End of cloud request. 2026-08-21T22:57:15.942 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f7e006f64c02dd9d14c17ca2bec30d0e78201c1f Dynamic Signature Compilation Timestamp:08-21-2026 22:57:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:15.943 [Cloud] End of cloud request. 2026-08-21T22:57:15.943 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:16.436 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x32dafddb 2026-08-21T22:57:17.455 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:17.455 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:17.455 [Cloud] Queued cloud request. 2026-08-21T22:57:17.455 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:17.455 [Cloud] Dequeued cloud request. 2026-08-21T22:57:17.455 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:17.757 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b83457377a1b8c7f36c5ef38224cac7bb94ecf93 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:17 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:17.758 [Cloud] End of cloud request. 2026-08-21T22:57:17.758 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf8da7320 2026-08-21T22:57:18.276 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:18.330 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:18.330 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:18.330 [Cloud] Queued cloud request. 2026-08-21T22:57:18.330 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:18.330 [Cloud] Dequeued cloud request. 2026-08-21T22:57:18.330 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:18.554 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d323a26590b4da83f84e34a18e8097df56035400 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:18.555 [Cloud] End of cloud request. 2026-08-21T22:57:18.555 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:19.079 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa6f33c1c 2026-08-21T22:57:19.366 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:19.367 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:19.367 [Cloud] Queued cloud request. 2026-08-21T22:57:19.367 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:19.367 [Cloud] Dequeued cloud request. 2026-08-21T22:57:19.367 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x909672fe 2026-08-21T22:57:19.478 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:19.478 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:19.478 [Cloud] Queued cloud request. 2026-08-21T22:57:19.478 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:19.478 [Cloud] Dequeued cloud request. 2026-08-21T22:57:19.478 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9ddd00607c03d4872eeb375bf9699ec6e93ba4e8 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:19.708 Dynamic signature received 2026-08-21T22:57:19.709 [Cloud] End of cloud request. 2026-08-21T22:57:19.709 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:19.861 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\c70c4ded6aa678ca365c67dda6dad20f803d0054 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:19 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:19.862 [Cloud] End of cloud request. 2026-08-21T22:57:19.862 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5ec79c25 2026-08-21T22:57:20.176 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:20.176 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:20.176 [Cloud] Queued cloud request. 2026-08-21T22:57:20.176 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:20.176 [Cloud] Dequeued cloud request. 2026-08-21T22:57:20.177 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:20.223 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:20.370 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\763e51ca8f0adf6f7bbd3d3a270bb233419153ba Dynamic Signature Compilation Timestamp:08-21-2026 22:57:20 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:20.371 [Cloud] End of cloud request. 2026-08-21T22:57:20.371 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:20.890 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x102961b5 2026-08-21T22:57:23.046 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:23.046 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:23.046 [Cloud] Queued cloud request. 2026-08-21T22:57:23.046 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:23.047 [Cloud] Dequeued cloud request. 2026-08-21T22:57:23.047 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x77115ba8 2026-08-21T22:57:23.356 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:23.356 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:23.356 [Cloud] Queued cloud request. 2026-08-21T22:57:23.356 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:23.356 [Cloud] Dequeued cloud request. 2026-08-21T22:57:23.356 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7561b1d8 2026-08-21T22:57:24.159 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:24.159 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:24.159 [Cloud] Queued cloud request. 2026-08-21T22:57:24.159 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:24.159 [Cloud] Dequeued cloud request. 2026-08-21T22:57:24.159 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:24.406 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b07efa86bd4b570b37cd762240969816ef76be67 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:24.407 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:24.408 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x537410d7 2026-08-21T22:57:24.932 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:24.932 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:24.932 [Cloud] Queued cloud request. 2026-08-21T22:57:24.932 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:24.932 [Cloud] Dequeued cloud request. 2026-08-21T22:57:24.932 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:24.935 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4836a28944e5c60a00ad59ebe9ea9379188806ab Dynamic Signature Compilation Timestamp:08-21-2026 22:57:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:25.269 Dynamic signature received 2026-08-21T22:57:25.270 [Cloud] End of cloud request. 2026-08-21T22:57:25.270 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:25.789 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x39386cde 2026-08-21T22:57:25.959 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:25.959 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:25.959 [Cloud] Queued cloud request. 2026-08-21T22:57:25.959 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:25.959 [Cloud] Dequeued cloud request. 2026-08-21T22:57:25.960 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:26.159 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d587f6fd99d9029d4d32bda38a0cb8464a5249b6 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:26 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:26.160 [Cloud] End of cloud request. 2026-08-21T22:57:26.160 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xaf703c60 2026-08-21T22:57:26.637 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:26.637 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:26.637 [Cloud] Queued cloud request. 2026-08-21T22:57:26.637 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:26.637 [Cloud] Dequeued cloud request. 2026-08-21T22:57:26.637 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:26.670 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:26.957 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\07afad000a32e5f4f752595ba558001eb560b5bb Dynamic Signature Compilation Timestamp:08-21-2026 22:57:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:26.957 [Cloud] End of cloud request. 2026-08-21T22:57:26.957 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb55086ed 2026-08-21T22:57:27.027 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:27.027 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:27.028 [Cloud] Queued cloud request. 2026-08-21T22:57:27.028 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:27.028 [Cloud] Dequeued cloud request. 2026-08-21T22:57:27.028 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:27.261 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\40ff1e65eda2147daf25435e3f9f27fc9aab14dd Dynamic Signature Compilation Timestamp:08-21-2026 22:57:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:27.262 [Cloud] End of cloud request. 2026-08-21T22:57:27.262 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:27.475 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd767ca2f 2026-08-21T22:57:28.052 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:28.052 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:28.052 [Cloud] Queued cloud request. 2026-08-21T22:57:28.052 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:28.052 [Cloud] Dequeued cloud request. 2026-08-21T22:57:28.053 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\09d3d4decde20460ec2e90376cacb75506d9e6a4 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:28.258 Dynamic signature received 2026-08-21T22:57:28.259 [Cloud] End of cloud request. 2026-08-21T22:57:28.259 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:28.773 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x88b98e66 2026-08-21T22:57:30.378 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:30.378 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:30.379 [Cloud] Queued cloud request. 2026-08-21T22:57:30.379 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:30.379 [Cloud] Dequeued cloud request. 2026-08-21T22:57:30.379 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9852ef00 2026-08-21T22:57:30.464 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:30.464 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:30.464 [Cloud] Queued cloud request. 2026-08-21T22:57:30.464 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:30.464 [Cloud] Dequeued cloud request. 2026-08-21T22:57:30.464 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:30.587 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\967cb8e7d13234a841bcae847fe82222accc3c47 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:30 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:30.588 [Cloud] End of cloud request. 2026-08-21T22:57:30.588 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:30.697 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1c95d4643bd76a14d4995f6cbc3af294c5ef6daf Dynamic Signature Compilation Timestamp:08-21-2026 22:57:30 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:30.698 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:30.698 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5c567000 2026-08-21T22:57:31.032 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:31.032 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:31.032 [Cloud] Queued cloud request. 2026-08-21T22:57:31.032 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:31.032 [Cloud] Dequeued cloud request. 2026-08-21T22:57:31.032 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:31.100 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:31.546 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\12284e4099ddce706b119d97868e5231cb574019 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:31 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:57:31.547 [Cloud] End of cloud request. 2026-08-21T22:57:31.547 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:32.060 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:57:33.056 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\apache\modules\mod_negotiation.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:57:33.083 [Cloud] End of cloud request. 2026-08-21T22:57:33.364 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\php\ext\php_snmp.dll. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:57:33.398 [Cloud] End of cloud request. 2026-08-21T22:57:33.604 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb3c65f13 2026-08-21T22:57:47.713 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:47.713 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:47.713 [Cloud] Queued cloud request. 2026-08-21T22:57:47.713 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:47.713 [Cloud] Dequeued cloud request. 2026-08-21T22:57:47.713 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:48.016 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\14e56d7ef1ac319b91c20c483ac6c60665b018d8 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:48 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:48.017 [Cloud] End of cloud request. 2026-08-21T22:57:48.018 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:48.534 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x413cc667 2026-08-21T22:57:49.570 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:49.571 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:49.571 [Cloud] Queued cloud request. 2026-08-21T22:57:49.571 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:49.571 [Cloud] Dequeued cloud request. 2026-08-21T22:57:49.571 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:49.939 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3338ff663bb058de008a3381ed0f2f4fbba98827 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:50 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:57:49.940 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:49.940 [Cloud] End of cloud request. 2026-08-21T22:57:50.455 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1e671863 2026-08-21T22:57:57.776 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:57.776 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:57.776 [Cloud] Queued cloud request. 2026-08-21T22:57:57.776 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:57.776 [Cloud] Dequeued cloud request. 2026-08-21T22:57:57.777 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:58.003 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d64702c1d960d1b3ee9a2d356c0e86cbc53300cc Dynamic Signature Compilation Timestamp:08-21-2026 22:57:58 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:58.004 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:58.004 [Cloud] End of cloud request. 2026-08-21T22:57:58.521 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x19f0d1fd 2026-08-21T22:57:58.731 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:58.731 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:58.731 [Cloud] Queued cloud request. 2026-08-21T22:57:58.731 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:58.731 [Cloud] Dequeued cloud request. 2026-08-21T22:57:58.731 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:58.994 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\e552b36f044f8afc90ab91e12403183671ed9f01 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:59 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:58.995 [Cloud] End of cloud request. 2026-08-21T22:57:58.995 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:57:59.508 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x94605516 2026-08-21T22:57:59.552 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:57:59.552 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:57:59.552 [Cloud] Queued cloud request. 2026-08-21T22:57:59.552 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:57:59.552 [Cloud] Dequeued cloud request. 2026-08-21T22:57:59.553 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:57:59.786 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\7a3d3abb747083b4aa98e34313c411343ead4151 Dynamic Signature Compilation Timestamp:08-21-2026 22:57:59 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:57:59.786 [Cloud] End of cloud request. 2026-08-21T22:57:59.787 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:00.299 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x773a99d1 2026-08-21T22:58:00.481 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:00.481 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:00.481 [Cloud] Queued cloud request. 2026-08-21T22:58:00.481 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:00.481 [Cloud] Dequeued cloud request. 2026-08-21T22:58:00.482 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:58:00.804 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\f69817cf28ebcee41a871bdd2f2e085945398763 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:00 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:00.805 [Cloud] End of cloud request. 2026-08-21T22:58:00.805 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb733bf21 2026-08-21T22:58:00.951 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:00.951 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:00.951 [Cloud] Queued cloud request. 2026-08-21T22:58:00.951 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:00.951 [Cloud] Dequeued cloud request. 2026-08-21T22:58:00.951 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:58:01.202 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b07b17cc3c8374844916ba7ac7767f2c1fefd801 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:01 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:01.203 [Cloud] End of cloud request. 2026-08-21T22:58:01.203 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:01.327 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x906afdc3 2026-08-21T22:58:04.266 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:04.266 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:04.266 [Cloud] Queued cloud request. 2026-08-21T22:58:04.266 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:04.266 [Cloud] Dequeued cloud request. 2026-08-21T22:58:04.266 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc4937e34 2026-08-21T22:58:04.843 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:04.844 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:04.844 [Cloud] Queued cloud request. 2026-08-21T22:58:04.844 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:04.844 [Cloud] Dequeued cloud request. 2026-08-21T22:58:04.844 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\641f2050c87a7e1406a63bc723a0fa83c3d29285 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:05 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:05.080 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:05.083 Dynamic signature received 2026-08-21T22:58:05.084 [Cloud] End of cloud request. 2026-08-21T22:58:05.188 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4c69e9c7d0726f0b54f65c5150c22338faa825c1 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:05 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:58:05.189 [Cloud] End of cloud request. 2026-08-21T22:58:05.189 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:05.598 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x0e62217b 2026-08-21T22:58:06.436 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:06.436 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:06.436 [Cloud] Queued cloud request. 2026-08-21T22:58:06.436 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:06.436 [Cloud] Dequeued cloud request. 2026-08-21T22:58:06.436 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:58:06.755 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\593356d623bfe3efcc5825a999298b846231c6b5 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:06 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:06.756 [Cloud] End of cloud request. 2026-08-21T22:58:06.756 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:07.275 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1649a338 2026-08-21T22:58:15.713 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:15.713 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:15.713 [Cloud] Queued cloud request. 2026-08-21T22:58:15.713 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:15.713 [Cloud] Dequeued cloud request. 2026-08-21T22:58:15.714 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\381d5ffaa8d5ecd6be1bda73aa6c11aeeba043b1 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:16 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:16.108 Dynamic signature received 2026-08-21T22:58:16.109 [Cloud] End of cloud request. 2026-08-21T22:58:16.109 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:16.622 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5dbf71a4 2026-08-21T22:58:17.424 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:17.424 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:17.424 [Cloud] Queued cloud request. 2026-08-21T22:58:17.424 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:17.424 [Cloud] Dequeued cloud request. 2026-08-21T22:58:17.424 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xecd4fd0e 2026-08-21T22:58:18.175 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:18.175 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:18.175 [Cloud] Queued cloud request. 2026-08-21T22:58:18.175 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:18.175 [Cloud] Dequeued cloud request. 2026-08-21T22:58:18.176 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:58:18.511 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\4b49cb98e22da92b576e6559f78a2672cb871424 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:18 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:18.512 [Cloud] End of cloud request. 2026-08-21T22:58:18.512 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:19.025 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd9a7b3cc 2026-08-21T22:58:20.557 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:58:20.557 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:58:20.557 [Cloud] Queued cloud request. 2026-08-21T22:58:20.557 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:58:20.557 [Cloud] Dequeued cloud request. 2026-08-21T22:58:20.558 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:58:20.916 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\ae00ab1dc16cd3968c5bea476a55ba9975a367d2 Dynamic Signature Compilation Timestamp:08-21-2026 22:58:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:58:20.917 [Cloud] End of cloud request. 2026-08-21T22:58:20.917 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:58:21.428 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:58:27.431 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume8\xampp\apache\modules\mod_lbmethod_bytraffic.so. status=0x40070000, statusex=0x200110, threatid=0x80000000, sigseq=0x294bdc606b459 2026-08-21T22:58:27.463 [Cloud] End of cloud request. 2026-08-21T22:58:27.981 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x16d45692 2026-08-21T22:59:26.864 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:59:26.864 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:59:26.864 [Cloud] Queued cloud request. 2026-08-21T22:59:26.864 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:59:26.864 [Cloud] Dequeued cloud request. 2026-08-21T22:59:26.864 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:59:27.102 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\1464dbcb8ac68ef779831f84d33c27f506c60348 Dynamic Signature Compilation Timestamp:08-21-2026 22:59:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:59:27.104 [Cloud] End of cloud request. 2026-08-21T22:59:27.104 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x27a55753 2026-08-21T22:59:27.620 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T22:59:28.569 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:59:28.569 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:59:28.569 [Cloud] Queued cloud request. 2026-08-21T22:59:28.569 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:59:28.570 [Cloud] Dequeued cloud request. 2026-08-21T22:59:28.570 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:59:28.764 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a8bb2df081da007821064f1f5826391ca4575f5c Dynamic Signature Compilation Timestamp:08-21-2026 22:59:28 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:59:28.765 [Cloud] End of cloud request. 2026-08-21T22:59:28.765 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:59:29.277 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa3b877a4 2026-08-21T22:59:33.599 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:59:33.600 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:59:33.600 [Cloud] Queued cloud request. 2026-08-21T22:59:33.600 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:59:33.600 [Cloud] Dequeued cloud request. 2026-08-21T22:59:33.600 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:59:33.787 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\d7841f7a70b22cc11fc76add21f1e83d20b45db7 Dynamic Signature Compilation Timestamp:08-21-2026 22:59:33 Persistence Type:Duration Time remaining:50065408 2026-08-21T22:59:33.788 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:59:33.788 [Cloud] End of cloud request. 2026-08-21T22:59:34.310 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3d47aa81 2026-08-21T22:59:43.317 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T22:59:43.317 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T22:59:43.317 [Cloud] Queued cloud request. 2026-08-21T22:59:43.317 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T22:59:43.317 [Cloud] Dequeued cloud request. 2026-08-21T22:59:43.317 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T22:59:43.514 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\2209f739f4b485c39a2d553218ec4810c25944a0 Dynamic Signature Compilation Timestamp:08-21-2026 22:59:43 Persistence Type:Duration Time remaining:150196224 2026-08-21T22:59:43.515 [Cloud] End of cloud request. 2026-08-21T22:59:43.515 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T22:59:44.026 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9e63f576 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6492371d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd95d93b3 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x445272c5 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2fa20ebe Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbe996f79 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb8f61125 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xde01483c Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb4fb11d9 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe6f95a55 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3487c12b Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x61afc6fe 2026-08-21T23:00:25.668 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:00:25.668 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:00:25.668 [Cloud] Queued cloud request. 2026-08-21T23:00:25.668 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:00:25.668 [Cloud] Dequeued cloud request. 2026-08-21T23:00:25.668 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:00:25.960 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bc86c51753c1074a50da4f6baf31a1f66d2a7674 Dynamic Signature Compilation Timestamp:08-21-2026 23:00:26 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:00:25.961 [Cloud] End of cloud request. 2026-08-21T23:00:25.961 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:00:26.473 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xe45f0e70 2026-08-21T23:00:43.384 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:00:43.384 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:00:43.384 [Cloud] Queued cloud request. 2026-08-21T23:00:43.384 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:00:43.384 [Cloud] Dequeued cloud request. 2026-08-21T23:00:43.384 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:00:43.678 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\9603b1436cfc4f077627e13ce16473f6cc5ab79b Dynamic Signature Compilation Timestamp:08-21-2026 23:00:43 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:00:43.679 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:00:43.679 [Cloud] End of cloud request. 2026-08-21T23:00:44.203 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x5cbaa74c 2026-08-21T23:00:47.806 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:00:47.807 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:00:47.807 [Cloud] Queued cloud request. 2026-08-21T23:00:47.807 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:00:47.807 [Cloud] Dequeued cloud request. 2026-08-21T23:00:47.807 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:00:48.304 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b7f6760d66b828f4f3b89fa41e0b7fc3482c99c6 Dynamic Signature Compilation Timestamp:08-21-2026 23:00:48 Persistence Type:Duration Time remaining:150196224 2026-08-21T23:00:48.305 [Cloud] End of cloud request. 2026-08-21T23:00:48.305 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:00:48.818 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6b4f5754 2026-08-21T23:00:59.297 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:00:59.297 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:00:59.297 [Cloud] Queued cloud request. 2026-08-21T23:00:59.297 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:00:59.297 [Cloud] Dequeued cloud request. 2026-08-21T23:00:59.297 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:00.729 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\0f1e0fe079234f5f7fc91ce94e7193d37724f0f4 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:00 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:00.730 [Cloud] End of cloud request. 2026-08-21T23:01:00.730 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:01.251 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x07bda34e 2026-08-21T23:01:09.200 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:09.201 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:09.201 [Cloud] Queued cloud request. 2026-08-21T23:01:09.201 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:09.201 [Cloud] Dequeued cloud request. 2026-08-21T23:01:09.201 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:09.427 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\67a4e2840cf6d9ca1038b218c291e6f5ff9a958f Dynamic Signature Compilation Timestamp:08-21-2026 23:01:09 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:09.428 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:09.428 [Cloud] End of cloud request. 2026-08-21T23:01:09.950 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6a653b20 2026-08-21T23:01:10.665 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:10.665 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:10.665 [Cloud] Queued cloud request. 2026-08-21T23:01:10.665 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:10.666 [Cloud] Dequeued cloud request. 2026-08-21T23:01:10.666 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:10.881 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a694f99e34e8d68094ecf9383cf9b366da31da28 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:10 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:10.882 [Cloud] End of cloud request. 2026-08-21T23:01:10.882 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:11.393 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x0000108044F76FB4, sigsha=6a849c9023e5e1ca98e7bb1282e756480f21b470, cached=false, source=2, resourceid=0xc9dd708d Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3df96426 2026-08-21T23:01:15.619 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:15.619 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:15.619 [Cloud] Queued cloud request. 2026-08-21T23:01:15.619 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:15.619 [Cloud] Dequeued cloud request. 2026-08-21T23:01:15.620 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:15.865 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\adb6c5d0795cefa96fef397319ca74e30b70b598 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:15.865 [Cloud] End of cloud request. 2026-08-21T23:01:15.866 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:16.389 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x84a32acb Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xbaaab625 2026-08-21T23:01:22.852 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:22.852 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:22.852 [Cloud] Queued cloud request. 2026-08-21T23:01:22.852 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:22.853 [Cloud] Dequeued cloud request. 2026-08-21T23:01:22.853 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:23.088 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\98927cca2e2ca51bd7299015d597edc1495a86be Dynamic Signature Compilation Timestamp:08-21-2026 23:01:23 Persistence Type:Duration Time remaining:150196224 2026-08-21T23:01:23.089 [Cloud] End of cloud request. 2026-08-21T23:01:23.089 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:23.607 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb02694c2 2026-08-21T23:01:24.324 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:24.324 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:24.324 [Cloud] Queued cloud request. 2026-08-21T23:01:24.324 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:24.325 [Cloud] Dequeued cloud request. 2026-08-21T23:01:24.325 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:24.960 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\bf7386badc2859d8a445e196fa78c21066c25e67 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:25 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:24.961 [Cloud] End of cloud request. 2026-08-21T23:01:24.961 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:25.484 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x1488e641 2026-08-21T23:01:43.489 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:43.489 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:43.489 [Cloud] Queued cloud request. 2026-08-21T23:01:43.489 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:43.489 [Cloud] Dequeued cloud request. 2026-08-21T23:01:43.489 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:43.812 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\90ed5f37174cfc39a7020b1d3e23777816e3ee3e Dynamic Signature Compilation Timestamp:08-21-2026 23:01:43 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:43.813 [Cloud] End of cloud request. 2026-08-21T23:01:43.813 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:44.327 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2930b459 2026-08-21T23:01:54.405 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:54.405 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:54.405 [Cloud] Queued cloud request. 2026-08-21T23:01:54.405 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:54.405 [Cloud] Dequeued cloud request. 2026-08-21T23:01:54.405 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:01:54.643 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\77c6296b212fa712d0a793eee3e3c6d9832f08d8 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:54 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:54.644 [Cloud] End of cloud request. 2026-08-21T23:01:54.644 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:55.154 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x00001727EB7DE8C7, sigsha=115083f33e9b3434e10dc3900db3aa2bba53de1c, cached=false, source=2, resourceid=0xf2c9f97b 2026-08-21T23:01:55.318 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:55.319 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:55.319 [Cloud] Queued cloud request. 2026-08-21T23:01:55.319 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:55.319 [Cloud] Dequeued cloud request. 2026-08-21T23:01:55.319 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\82d3509ecf180ba06aec89b4a81f3adb574a1f74 Dynamic Signature Compilation Timestamp:08-21-2026 23:01:55 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:55.610 Dynamic signature received 2026-08-21T23:01:55.611 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:55.614 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x00000070DE3CA1F0, sigsha=da39a3ee5e6b4b0d3255bfef95601890afd80709, cached=false, source=2, resourceid=0xf2c9f97b 2026-08-21T23:01:55.666 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume3\Windows\SysWOW64\Printing_Admin_Scripts\el-GR\prnjobs.vbs. status=0x40030000, statusex=0x200, threatid=0x80000000, sigseq=0x1727eb7de8c7 2026-08-21T23:01:56.136 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x6015008a 2026-08-21T23:01:57.614 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:01:57.614 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:01:57.614 [Cloud] Queued cloud request. 2026-08-21T23:01:57.614 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:01:57.614 [Cloud] Dequeued cloud request. 2026-08-21T23:01:57.743 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\748863c71632bf0d4089c74eaf3f4a69a7d92e7d Dynamic Signature Compilation Timestamp:08-21-2026 23:01:58 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:01:57.949 Dynamic signature received 2026-08-21T23:01:57.950 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:01:57.950 [Cloud] End of cloud request. 2026-08-21T23:01:58.465 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x4b803821 2026-08-21T23:02:01.519 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:01.519 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:01.519 [Cloud] Queued cloud request. 2026-08-21T23:02:01.519 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:01.519 [Cloud] Dequeued cloud request. 2026-08-21T23:02:01.519 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\216f868234c98c691855c95c08c98ffc64db21fc Dynamic Signature Compilation Timestamp:08-21-2026 23:02:01 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:01.904 Dynamic signature received 2026-08-21T23:02:01.905 [Cloud] End of cloud request. 2026-08-21T23:02:01.905 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:02.425 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x577fe1d8 2026-08-21T23:02:03.017 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:03.017 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:03.017 [Cloud] Queued cloud request. 2026-08-21T23:02:03.017 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:03.017 [Cloud] Dequeued cloud request. 2026-08-21T23:02:03.017 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\29d3417fb8c2b98c2c9b8cd857276f58d09d2b70 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:03 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:03.325 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:03.324 Dynamic signature received 2026-08-21T23:02:03.327 [Cloud] End of cloud request. 2026-08-21T23:02:03.851 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x3a10c374 2026-08-21T23:02:04.349 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:04.350 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:04.350 [Cloud] Queued cloud request. 2026-08-21T23:02:04.350 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:04.350 [Cloud] Dequeued cloud request. 2026-08-21T23:02:04.350 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:04.561 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\da447443217cef6007099eb92a4224827112df34 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:04 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:04.562 [Cloud] End of cloud request. 2026-08-21T23:02:04.562 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:05.078 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xa28fd930 2026-08-21T23:02:07.716 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:07.716 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:07.716 [Cloud] Queued cloud request. 2026-08-21T23:02:07.716 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:07.716 [Cloud] Dequeued cloud request. 2026-08-21T23:02:07.717 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:07.983 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\867a251bcfb2d17a215ef2652160e27044dda18f Dynamic Signature Compilation Timestamp:08-21-2026 23:02:08 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:07.984 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:07.984 [Cloud] End of cloud request. 2026-08-21T23:02:08.504 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xdbf68e26 2026-08-21T23:02:15.187 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:15.187 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:15.187 [Cloud] Queued cloud request. 2026-08-21T23:02:15.187 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:15.187 [Cloud] Dequeued cloud request. 2026-08-21T23:02:15.187 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:15.419 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\398fd5efd7978951e506ed48bd38889e8d79c964 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:15 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:15.420 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:15.420 [Cloud] End of cloud request. 2026-08-21T23:02:15.940 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb9b36adc 2026-08-21T23:02:21.003 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:21.003 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:21.003 [Cloud] Queued cloud request. 2026-08-21T23:02:21.003 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:21.003 [Cloud] Dequeued cloud request. 2026-08-21T23:02:21.003 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:21.239 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\a47781baefefb63387286589776eb747c608c11c Dynamic Signature Compilation Timestamp:08-21-2026 23:02:21 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:21.241 [Cloud] End of cloud request. 2026-08-21T23:02:21.241 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:21.753 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xd648a7df 2026-08-21T23:02:23.803 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:23.803 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:23.803 [Cloud] Queued cloud request. 2026-08-21T23:02:23.803 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:23.803 [Cloud] Dequeued cloud request. 2026-08-21T23:02:23.803 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:24.010 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\20eb1f27668f56c0f5931d546a3aa101d2cb706c Dynamic Signature Compilation Timestamp:08-21-2026 23:02:24 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:24.011 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:24.011 [Cloud] End of cloud request. 2026-08-21T23:02:24.534 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x427d3848 2026-08-21T23:02:26.885 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:26.885 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:26.885 [Cloud] Queued cloud request. 2026-08-21T23:02:26.885 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:26.885 [Cloud] Dequeued cloud request. 2026-08-21T23:02:26.886 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:27.099 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\100f2d9a963797c5baa8d025814f2afed5329a00 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:27.100 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:27.100 [Cloud] End of cloud request. Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xc63736b2 2026-08-21T23:02:27.620 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T23:02:27.630 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:27.630 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:27.630 [Cloud] Queued cloud request. 2026-08-21T23:02:27.630 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:27.630 [Cloud] Dequeued cloud request. 2026-08-21T23:02:27.630 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\906e2225c9547a95fa8af093fee4c5b5d9790ecc Dynamic Signature Compilation Timestamp:08-21-2026 23:02:27 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:27.839 Dynamic signature received 2026-08-21T23:02:27.840 [Cloud] End of cloud request. 2026-08-21T23:02:27.840 RTSD:RTSD recieved, rescanning impacted resources Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x175c8eb8 2026-08-21T23:02:28.000 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:28.000 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:28.000 [Cloud] Queued cloud request. 2026-08-21T23:02:28.000 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:28.000 [Cloud] Dequeued cloud request. 2026-08-21T23:02:28.001 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf6ae3ca2 2026-08-21T23:02:28.292 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:28.292 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:28.292 [Cloud] Queued cloud request. 2026-08-21T23:02:28.292 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:28.292 [Cloud] Dequeued cloud request. 2026-08-21T23:02:28.293 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:28.354 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T23:02:28.434 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\963f1a95f23ef8bd778bfacf4fc2471b7aa03cef Dynamic Signature Compilation Timestamp:08-21-2026 23:02:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:28.435 [Cloud] End of cloud request. 2026-08-21T23:02:28.435 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:28.897 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\50f507d8e42a527e490f644ef6d23b3faaaf8ac5 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:28 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:28.897 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:28.898 [Cloud] End of cloud request. 2026-08-21T23:02:28.952 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000048E714E8BBC2, sigsha=01095c124be8a58fbcba40b6599f01f794ba012d, cached=false, source=2, resourceid=0xa892ddd6 2026-08-21T23:02:36.560 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:36.560 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:36.560 [Cloud] Queued cloud request. 2026-08-21T23:02:36.560 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:36.560 [Cloud] Dequeued cloud request. 2026-08-21T23:02:36.560 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:37.109 [Cloud] End of cloud request. 2026-08-21T23:02:37.109 [RTP] [MpRtp] Engine VFZ lofi/sample/expensive: \Device\HarddiskVolume5\xampp\htdocs\_0\06_Hotel\mobile_reservation_application\Mobile Reservation Application\Objects\MobileReservation.apk. status=0x40070000, statusex=0x200200, threatid=0x80000000, sigseq=0x48e714e8bbc2 2026-08-21T23:02:37.629 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T23:02:39.576 Engine:Setting original file name "rasautou.exe" for "h:\windows\winsxs\backup\x86_microsoft-windows-rasautodial_31bf3856ad364e35_10.0.19041.546_none_91b4aa330bc4f8a4_rasautou.exe_477abe34", hr=0x800710da 2026-08-21T23:02:52.808 [ESU] ESU heartbeat: ESU disabled (explicit EnableEmergencySigs config) 2026-08-21T23:02:54.605 ExpensiveFile:Scan time for `\Device\HarddiskVolume3\Users\ITHAN\Desktop\KSoft\Microsoft_Visual-Basic_Professional_Edition_Deutsch.cameyo.exe->(EXEEmb)` is 5671 units Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x75d50b65 2026-08-21T23:02:55.636 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:55.636 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:55.636 [Cloud] Queued cloud request. 2026-08-21T23:02:55.636 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:55.636 [Cloud] Dequeued cloud request. 2026-08-21T23:02:55.637 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\3f40587ec310a5015e8d984cd9dfd25ecb0fafab Dynamic Signature Compilation Timestamp:08-21-2026 23:02:55 Persistence Type:Duration Time remaining:150196224 2026-08-21T23:02:55.851 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:55.854 Dynamic signature received 2026-08-21T23:02:55.856 [Cloud] End of cloud request. 2026-08-21T23:02:56.376 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x2deb1e10 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7a814a35 2026-08-21T23:02:58.521 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:02:58.521 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:02:58.521 [Cloud] Queued cloud request. 2026-08-21T23:02:58.521 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:02:58.521 [Cloud] Dequeued cloud request. 2026-08-21T23:02:58.522 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:02:58.792 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\75e280aa90ae8e59665618dac5fc2277497bff24 Dynamic Signature Compilation Timestamp:08-21-2026 23:02:58 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:02:58.793 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:02:58.794 [Cloud] End of cloud request. 2026-08-21T23:02:59.309 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7687b823 2026-08-21T23:03:06.854 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:03:06.854 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:03:06.854 [Cloud] Queued cloud request. 2026-08-21T23:03:06.854 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:03:06.854 [Cloud] Dequeued cloud request. 2026-08-21T23:03:06.854 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:03:07.184 Engine:Setting original file name "MpCmdRun.exe" for "h:\windows\winsxs\backup\x86_windows-defender-service_31bf3856ad364e35_10.0.19041.746_none_4780d216fd3e6781_mpcmdrun.exe_1d1038c2", hr=0x800710da Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\27ae9c505d530c574109fc05f48b1d613980bf50 Dynamic Signature Compilation Timestamp:08-21-2026 23:03:07 Persistence Type:Duration Time remaining:150196224 2026-08-21T23:03:07.255 [Cloud] End of cloud request. 2026-08-21T23:03:07.255 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:03:07.256 Dynamic signature received Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x303c19b6 2026-08-21T23:03:07.447 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:03:07.447 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:03:07.447 [Cloud] Queued cloud request. 2026-08-21T23:03:07.447 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:03:07.447 [Cloud] Dequeued cloud request. 2026-08-21T23:03:07.447 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:03:07.646 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\b9295e2337b62243a6f872c18e0f9730dde72195 Dynamic Signature Compilation Timestamp:08-21-2026 23:03:07 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:03:07.647 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:03:07.647 [Cloud] End of cloud request. 2026-08-21T23:03:07.781 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x81bc0457 2026-08-21T23:03:08.124 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:03:08.124 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:03:08.124 [Cloud] Queued cloud request. 2026-08-21T23:03:08.124 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:03:08.124 [Cloud] Dequeued cloud request. 2026-08-21T23:03:08.124 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:03:08.399 Engine:Setting original file name "msmpeng.exe" for "h:\windows\winsxs\backup\x86_windows-defender-service_31bf3856ad364e35_10.0.19041.746_none_4780d216fd3e6781_msmpeng.exe_2f1c6923", hr=0x800710da Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\fb6678efc9e082211ac0b28fbdd39aa353794ebb Dynamic Signature Compilation Timestamp:08-21-2026 23:03:08 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:03:08.471 Dynamic signature received 2026-08-21T23:03:08.472 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:03:08.472 [Cloud] End of cloud request. 2026-08-21T23:03:08.991 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x29192183 2026-08-21T23:03:09.825 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:03:09.825 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:03:09.825 [Cloud] Queued cloud request. 2026-08-21T23:03:09.825 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:03:09.825 [Cloud] Dequeued cloud request. 2026-08-21T23:03:09.825 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:03:10.012 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\315e1e179c4a2ba654b25cac55c1a1d9303f39fc Dynamic Signature Compilation Timestamp:08-21-2026 23:03:10 Persistence Type:Duration Time remaining:50065408 2026-08-21T23:03:10.013 [Cloud] End of cloud request. 2026-08-21T23:03:10.013 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:03:10.536 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x97f3542f 2026-08-21T23:03:18.342 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:03:18.342 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:03:18.342 [Cloud] Queued cloud request. 2026-08-21T23:03:18.342 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:03:18.342 [Cloud] Dequeued cloud request. 2026-08-21T23:03:18.343 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:03:18.587 Dynamic signature received Dynamic Signature has been received Dynamic Signature Type:Signature Update Signature Path:C:\ProgramData\Microsoft\Windows Defender\Scans\\RtSigs\Data\df022c441fe6b2bca7deeca15452eb3ef6dfaffd Dynamic Signature Compilation Timestamp:08-21-2026 23:03:18 Persistence Type:Duration Time remaining:150196224 2026-08-21T23:03:18.589 [Cloud] End of cloud request. 2026-08-21T23:03:18.589 RTSD:RTSD recieved, rescanning impacted resources 2026-08-21T23:03:19.111 [NRI] Successfully updated NIS service with platform settings for enforcement level Log Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf3df1850 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0xf3df1850 2026-08-21T23:06:25.686 [RTP] [Mini-filter] Unsuccessful scan status(#310): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\phpA1F3.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #128950, FileId: 0x21000000046379, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x9606fc04 Internal signature match:subtype=Lowfi, sigseq=0x0000157E7D1F4EFF, sigsha=a18aa2b8c11271ac6057c63b2f2463a76cd3d6f0, cached=false, source=2, resourceid=0x9606fc04 BEGIN BM telemetry GUID:{BD472DB5-59D0-BBFB-80CA-498B1969DBEA} SignatureID:55746285003867 SigSha:053433b4a1fafc4ab1360d4cde5d44f8ae7ac8df ThreatLevel:0 ProcessID:15616 ProcessCreationTime:134318227570548052 SessionID:1 CreationTime:08-21-2026 23:14:24 ImagePath:D:\xampp\apache\bin\httpd.exe Taint Info:Friendly: N; Reason: ; Modules: D:\xampp\apache\bin\libapr-1.dll:25,D:\xampp\apache\bin\libaprutil-1.dll:25,D:\xampp\apache\bin\libhttpd.dll:25,D:\xampp\apache\bin\libapriconv-1.dll:25,D:\xampp\apache\bin\pcre2-8.dll:25,D:\xampp\apache\modules\mod_access_compat.so:25,D:\xampp\apache\modules\mod_actions.so:25,D:\xampp\apache\modules\mod_alias.so:25,D:\xampp\apache\modules\mod_allowmethods.so:25,D:\xampp\apache\modules\mod_asis.so:25,D:\xampp\apache\modules\mod_auth_basic.so:25,D:\xampp\apache\modules\mod_authn_core.so:25,D:\xampp\apache\modules\mod_authn_file.so:25,D:\xampp\apache\modules\mod_authz_core.so:25,D:\xampp\apache\modules\mod_authz_groupfile.so:25,D:\xampp\apache\modules\mod_authz_host.so:25,D:\xampp\apache\modules\mod_authz_user.so:25,D:\xampp\apache\modules\mod_autoindex.so:25,D:\xampp\apache\modules\mod_cgi.so:25,D:\xampp\apache\modules\mod_dav_lock.so:25,; Parents: Operations:None END BM telemetry 2026-08-21T23:14:25.860 [Cloud] SubmitReport(CMpSpyDssContext), ShouldSendEvenOnPaidNetworks: 1 2026-08-21T23:14:25.860 [Cloud] Start of cloud request. Passive mode: 0 2026-08-21T23:14:25.860 [Cloud] Queued cloud request. 2026-08-21T23:14:25.860 [Cloud] MpEngineCloudRequest(). hr = 0 2026-08-21T23:14:25.861 [Cloud] Dequeued cloud request. 2026-08-21T23:14:25.861 [Cloud] RpcSpynetQueueGenerateReport(). hr = 0 2026-08-21T23:14:26.200 [Cloud] End of cloud request. 2026-08-21T23:14:26.715 [NRI] Successfully updated NIS service with platform settings for enforcement level Log 2026-08-21T23:14:47.566 [RTP] [Mini-filter] Unsuccessful scan status(#320): \Device\HarddiskVolume3\Users\ITHAN\AppData\Local\Temp\php4A7F.tmp. Process: \Device\HarddiskVolume5\xampp\apache\bin\httpd.exe, Status: 0xc0000001, State: 0, ScanRequest #130061, FileId: 0x8500000000fb48, Reason: OnClose, IoStatusBlockForNewFile: 0x2, DesiredAccess:0x0, FileAttributes:0x20, ScanAttributes:0x10, AccessStateFlags:0x1, BackingFileInfo: 0x0, 0x0, 0x0:0\0x0:0 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xcad6cbdd Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xfed8e46f Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x431740c1 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xde18a1b7 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xb5e8ddcc Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xeb61f335 Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0xf9dd88ab Internal signature match:subtype=Lowfi, sigseq=0x000294BDC606B459, sigsha=425fe00cff03a4c1f56b5218212a01b292c0dbf5, cached=false, source=2, resourceid=0x7b9538c3